Data Breach & Privacy
Blog > Data Breach & Privacy
Elara Caring Data Breach: What Home Health Patients Need to Know
Elara Caring has disclosed a data breach involving a third-party vendor that may have exposed the personal and protected health information of thousands of home health patients. If you received a notice, here is what was involved and what you can do next.

What Happened in the Elara Caring Data Breach
How a vendor incident affected home health patients
Elara Caring is a home health care provider that serves patients across the Northeast, Midwest, and Southwest. According to the company’s disclosures, the incident originated with a third-party vendor that helps manage and sign documents related to home health care services. The vendor notified Elara Caring of a security incident on December 12, 2025, reporting that an unauthorized party accessed and/or downloaded documents from its system during windows in November 2025.
Elara Caring conducted an investigation and, by March 12, 2026, determined that patient personal information was among the documents involved. The company began notifying affected individuals, mailing notification letters on or around May 12, 2026. The incident was reported to the U.S. Department of Health and Human Services’ Office for Civil Rights, which maintains a public portal of large healthcare breaches.
What Information Was Exposed in the Elara Caring Breach
The sensitive patient data involved
According to reporting on the incident, the information involved may have included medical records and Social Security numbers, among other personal details contained in the vendor’s documents. For patients, the combination of health information and Social Security numbers is especially sensitive, because it can enable both financial identity theft and medical identity theft.
Elara Caring stated it is offering 24 months of complimentary credit monitoring and remediation services through Cyberscout, a TransUnion company, at no cost to affected individuals, with a unique enrollment code provided in each notification letter. The company also established a dedicated call center for individuals with questions about the incident or assistance enrolling.
Who Is Affected and Why It Matters
Understanding the scope for patients
Reporting to HHS indicated that the protected health information of thousands of individuals was involved. Because Elara Caring’s own systems were reportedly not the point of intrusion — the incident occurred at a third-party vendor — affected individuals are primarily patients whose documents were handled through that vendor’s platform.
Vendor-related breaches are increasingly common in healthcare, and they underscore that your data can be exposed through companies you may never have interacted with directly. If you are a current or former Elara Caring patient, it is reasonable to treat a notification letter as a signal to take protective action promptly.
Steps to Take If You Were Notified
Protecting yourself after a healthcare data breach
Enroll in the complimentary credit monitoring offered within the enrollment period specified in your letter, and monitor your bank, credit card, and online accounts for unauthorized activity. Because medical information may be involved, it is also wise to review Explanations of Benefits from your health insurer for services you did not receive, which can be a sign of medical identity theft.
Be cautious of phishing attempts that reference Elara Caring or the data breach by name, as scammers sometimes use breach notifications to craft convincing messages. You may also wish to place a fraud alert or credit freeze. Beyond these steps, a legal professional can help you understand whether you may have a claim.
You can also read our overview of the MBE CPAs data breach lawsuit.
FAQs
The underlying vendor incident occurred in November 2025. Elara Caring was notified by the vendor on December 12, 2025, determined that patient data was involved by March 12, 2026, and mailed notification letters on or around May 12, 2026.
Reporting on the incident indicated that involved information may have included medical records and Social Security numbers, among other personal details.
According to the company, its own systems were reportedly not the point of the intrusion. The incident occurred at a third-party vendor that provided document management and signing services.
Yes. Elara Caring stated it is offering 24 months of complimentary credit monitoring and remediation services through Cyberscout, a TransUnion company, at no cost to affected individuals.
You may have legal options if your information was exposed. A legal professional can review your situation during a free consultation.
If you received a notification letter from Elara Caring, your information may have been involved. A dedicated call center was also established for questions about the incident.

