California Cancer Associates for Research and Excellence – High Desert Data Breach

California Cancer Associates for Research and Excellence – High Desert (CCARE High Desert) has notified patients that it was the target of a phishing attack. The organization learned on June 13, 2025 that unauthorized parties had gained access to a small number of employee email and SharePoint accounts. A subsequent investigation determined the unauthorized access actually occurred earlier, between December 13 and December 16, 2024, and that the intruders viewed certain emails, attachments, and SharePoint files during that window. The notice states the likely goal was to run further phishing scams using the compromised accounts, but confirms that files containing patient information were accessed in the process.

The letter is addressed to patients whose information appeared in one or more of the affected emails or SharePoint files. Because the copy of the notice reviewed by BreachLetter used placeholder fields for the specific data types involved, we cannot confirm the exact list of information exposed for every recipient — but the letter does confirm that names were involved, along with other unspecified personal information, and that the incident was serious enough for the provider to offer paid identity protection services in response.

What information was exposed?
  • Name
  • Additional information contained in the accessed emails or SharePoint files — the notification letter did not specify which other data elements applied to each individual recipient

CCARE High Desert is offering affected patients enrollment in Epiq Privacy Solutions ID credit monitoring, which includes credit monitoring and score access, SSN and dark web monitoring, credit report lock/freeze assistance, identity restoration support, and up to $1 million in identity theft and unauthorized funds transfer insurance. To enroll, visit www.privacysolutionsid.com, click ‘Activate Account,’ and enter the activation code printed on your individual letter, then complete the identity verification steps. The coverage length and enrollment deadline are listed on each recipient’s personal copy of the letter. If you need help enrolling, call 866.675.2006.

What should you do now?
  • Enroll in the free Epiq Privacy Solutions ID monitoring offered in your letter before the stated deadline — it’s already paid for and can catch misuse early.
  • Since a healthcare provider is involved, watch closely for unfamiliar medical bills, insurance statements, or collection notices that could signal medical identity theft.
  • Review your bank and credit card statements regularly for unrecognized activity, and check your free credit reports at annualcreditreport.com.
  • Consider placing a free fraud alert or security freeze on your credit file with Equifax, Experian, and TransUnion — this makes it harder for anyone to open new accounts in your name.
  • Be cautious of follow-up phishing emails or calls that reference this incident, since attackers sometimes use breach news to trick victims into giving up more information.
  • For ongoing peace of mind, consider signing up for a service like Aura or LifeLock, which can alert you if your information appears elsewhere.
  • If you spot signs of fraud, file a report with local police and the FTC at ftc.gov/idtheft, and keep copies for your records.

If you have questions, CCARE High Desert can be reached at 855-361-0308, Monday through Friday between 8:00 a.m. and 8:00 p.m. Central Time.

Leave a Comment