BrightSpring Health Services
bd_2a1df99c2cf14cfa · schema v1 · pii pii-v1
Full breach record for BrightSpring Health Services →BrightSpring Health Services notified affected individuals of a cybersecurity incident where an unknown third party accessed systems from March 12-13, 2023. The company discovered suspicious activity on March 14, 2023. Employee personal information was compromised. The company engaged cybersecurity advisors and offered one year of identity monitoring through Kroll.
J jump to incidentP pin to compareR raw source
Incident timeline
Mar 12, 2023
Begins
Mar 14, 2023
Discovered
Jun 12, 2023
Scope determined
Aug 11, 2023
Filed
vs. sector median
+9 wks slower
Linked disclosures
Why this link?Regulatory filings (10) · sorted by filing gap
- Maine State AGbd_3062db70843168272023-08-11Verified
- Washington State AGbd_3aa20233dfaa90872023-08-11Verified
- Massachusetts State AGbd_45077cd308ea1f642023-08-11Verified
- Vermont State AGbd_7e1fd6f523ea99c02023-08-11Verified
Show 6 more filings ↓Show fewer ↑up to 222d gap
- California State AGbd_803064993091323c2023-08-11Verified
- Oregon State AGbd_fc74412ffcf6b2da2023-08-11Verified
- Montana State AGbd_cc3e2c51c1917a142023-08-10 · +1dVerified
- Massachusetts State AGbd_5a8dd46b75958bb52023-06-21 · +51dVerified
- Indiana State AGbd_7ae4d05c30671df62023-06-21 · +51dVerified
- Illinois State AGbd_409150b18dd266af2023-01-01 · +222dCandidate
Filing propagation · 11 filings · 10 states
View merged incident ↗Pattern: first filing Jan 1 (IL), last Aug 11 (NH) — a 222-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.