They gave it all away. They do call it "inadvertent" though.
"The information disclosed may have included name, phone number, email address, date of birth, IP address, Cerebral client ID number, and other demographic or information. The information disclosed may also have included the service the individual selected, assessment responses, and certain associated health information, subscription plan type, appointment dates and other booking information, treatment, and other clinical information, health insurance/pharmacy benefit information (for example, plan name and group/member numbers), and insurance co-pay amount."
Because Cerebral is a telehealth startup and handles confidential patient data, it’s considered a company covered under the U.S. health privacy law known as HIPAA. According to a list of health-related security lapses under investigation by the U.S. Department of Health and Human Services, which oversees and enforces HIPAA, Cerebral’s data lapse is the second-largest breach of health data in 2023.