HackingVulnerability ExploitCapture Stored DataDelayed DiscoveryCustomer Data InvolvedIDENTITY_BASICHEALTH_BASICMediumContained
Insightin Health
bd_30942dbf93d1eb24 · schema v1 · pii pii-v1
Full breach record for Insightin Health →Insightin Health, Inc. disclosed a cybersecurity incident involving the GoAnywhere file-transfer tool. An unauthorized party exploited an unknown design flaw to access files between September 17 and 23, 2025. The breach exposed names, provider names, insurance info, and member IDs of approximately 1,641 Rhode Island residents. Insightin secured the environment, engaged experts, and offered 12 months of credit monitoring.
Vermont clock✗ VT AG >45 bday23 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 2 about the same incident.View merged incident
A leak claim by medusa about this victim predates this filing by 162 days.View originating leak claim
Linked disclosures
Why this link?Regulatory filings (1) · sorted by filing gap
- bd_9a2bd835940a4149Vermont State AGfiled 2026-04-01(28d gap)Candidate
Source provenance
- Source URL
- https://ago.vermont.gov/document/2026-03-04-insightin-health-data-breach-notice-consumers
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Mar 4, 2026
- Raw hash
- 1bfa106d21c111c6ba7a7c313a649ffad0865981a0f37d7cbf6d9d4b51cab464
Reporting entity
- Name
- Insightin Healthnorm: insightin health
- Domain
- insightinhealth.com
Victim entity
- Name
- Insightin Healthnorm: insightin health
- Domain
- insightinhealth.com
Incident
- Discovered
- Sep 23, 2025
- Materiality determined
- Mar 4, 2026
- Notification sent
- Mar 4, 2026
- Affected individuals
- 1,641
- Data types
- IDENTITY_BASICHEALTH_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1119 Automated Collection
- Threat actor
- External
- Regulator citations
- Reported the incident to law enforcement and regulators
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 23 weeks(162 days from discovery to filing)
- Compliance flags
- VT AG >45 bdayLeak >90d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.