Almeida Law Group is investigating a data breach at Elara Caring. The breach occurred on an unspecified date and was discovered on an unspecified date. If you were affected, contact Almeida Law Group.
About Elara Caring
Elara Caring is one of the largest providers of home-based care services in the United States, headquartered in Dallas, Texas. Founded in 2018 through the merger of Great Lakes Caring, National Home Health Care, and Jordan Health Services, the company employs approximately 26,000 caregivers and serves more than 60,000 patients daily across more than 200 locations in 17 states. Its services include skilled home health, hospice care, personal care, behavioral health, and palliative care. Because Elara Caring is a healthcare provider, the information it handles is protected under HIPAA, and a breach involving patient data can carry serious consequences for those affected.
What Happened?
Elara Caring was listed in an HHS Office for Civil Rights breach portal report submitted on June 23rd, 2026, identifying a hacking/IT incident affecting 22,172 individuals. The HHS filing categorizes the breach location as “Email” and notes no business associate was involved, but reporting from HIPAA Journal and other sources tells a more detailed story.
According to HIPAA Journal, the breach originated at Doctor Alliance, a Dallas-based platform used to manage and facilitate electronic physician signatures for home health care services. An unauthorized actor accessed and downloaded documents from Doctor Alliance’s systems during two windows: November 4th through 6th and November 14th through 17th, 2025. Doctor Alliance notified Elara Caring of the unauthorized access on December 12th, 2025. Elara Caring’s own systems were not compromised. By March 12th, 2026, Elara Caring determined that patient personal information was among the affected documents, and notification letters were mailed on May 12th, 2026—approximately six months after the breach occurred. Elara Caring has since ended its relationship with the vendor.
The information involved includes names, addresses, dates of birth, Social Security numbers, medical records, and health insurance information, according to HIPAA Journal’s reporting and corroborated by a Massachusetts state filing cited by ClassAction.org. Elara Caring offered 24 months of complimentary credit monitoring to affected individuals.
In November 2025, a threat actor using the alias “Kazu” claimed on a hacking forum to have exfiltrated 353 GB—over 1.2 million files—from Doctor Alliance and demanded a $200,000 ransom. Doctor Alliance acknowledged that an unauthorized party accessed a single client account through an exploited vulnerability, but was initially skeptical of the full scale of the attacker’s claims. DataBreaches.net and SuspectFile reported that Doctor Alliance was breached twice by Kazu. These attacker-side claims have not been independently confirmed as fully accurate by Doctor Alliance or Elara Caring.
This is Elara Caring’s second significant data breach. In December 2020, a phishing and business email compromise attack exposed the protected health information of 100,487 patients; that incident was reported to HHS on February 24th, 2021. As of the research date for this post, no class action lawsuit has been filed in connection with the 2026 incident, though at least two law firms—Edelson Lechtzin LLP and Shamis & Gentile P.A.—have announced investigations.
Key Facts at a Glance
- Company or Organization: Elara Caring
- Industry: Home-based healthcare / Home health and hospice care
- Location: Dallas, Texas
- Incident type: Hacking/IT Incident (third-party vendor breach)
- Date of consumer notification: May 12th, 2026
- Total persons affected: 22,172
- Identity theft protection offered: 24 months of complimentary credit monitoring
- Prior breach: December 2020 phishing/business email compromise affecting 100,487 patients; reported to HHS February 24th, 2021
- Litigation status: No class action filed as of research date; Edelson Lechtzin LLP and Shamis & Gentile P.A. are actively investigating
- Source: HHS Office for Civil Rights breach portal report (https://ocrportal.hhs.gov/ocr/breach/breach_report_hip.jsf#1467692); HIPAA Journal (https://www.hipaajournal.com/data-breaches-elara-caring-excelas-pulpdent-corp/); HIPAA Journal on Doctor Alliance (https://www.hipaajournal.com/doctor-alliance-data-breach-claim/); DataBreaches.net (https://databreaches.net/2025/11/12/doctor-alliance-data-breach-353gb-of-patient-files-allegedly-compromised-ransom-demanded/)
What Should You Do?
If you received a notification letter from Elara Caring, enroll in the 24 months of complimentary credit monitoring offered before the deadline stated in your letter. Regardless of whether you enroll, you should place a fraud alert or credit freeze with the three major credit bureaus—Equifax, Experian, and TransUnion—to help prevent new accounts from being opened in your name. Review your credit reports for any unfamiliar accounts or activity; you can access free reports at AnnualCreditReport.com. Because health insurance information and medical records were involved in this breach, review your Explanation of Benefits statements and request copies of your medical records to check for any services you did not receive. If you spot signs of fraud or identity theft, report them and get a recovery plan at IdentityTheft.gov.
Your Legal Rights
If your personal or health information was involved in this breach, you may have legal rights depending on the facts of the incident and the law in your state. Almeida Law Group represents consumers in data breach and privacy litigation and can help you evaluate whether you may have a claim. Contact us at (708) 529-5418 or through our contact page for a free case evaluation.