HackingVulnerability ExploitCustomer Data InvolvedIDENTITY_BASICHEALTH_BASICPHILowContained
Insightin Health
bd_3bdd8091c9b79d35 · schema v1 · pii pii-v1
Full breach record for Insightin Health →Insightin Health, Inc. disclosed that an unauthorized party exploited a design flaw in its GoAnywhere file-transfer tool to access data between September 17 and September 23, 2025. The incident affected personal information including names, provider names, insurance info, and member IDs. No SSNs or financial data were involved. Insightin engaged experts, contained the breach, and offered 12 months of credit monitoring.
California clockDiscovered Sep 23, 2025 → Notified Mar 4, 2026162d ✗ CA 60-day late23 weeks discovery → filing
This filing is one of 2 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (1) · sorted by filing gap
- bd_35cace97c849afa2Vermont State AGfiled 2026-01-28(35d gap)Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-619662
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Mar 4, 2026
- Raw hash
- b0dc85b3debd6729c9e1c3372b88b50bf958c69a59b2fff3cd0545c7789e0af7
Reporting entity
- Name
- Insightin Healthnorm: insightin health
- Domain
- insightinhealth.com
Victim entity
- Name
- Insightin Healthnorm: insightin health
- Domain
- insightinhealth.com
Incident
- Discovered
- Sep 23, 2025
- Materiality determined
- —
- Notification sent
- Mar 4, 2026
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICHEALTH_BASICPHI
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing Application
- Threat actor
- External
- Regulator citations
- Reported the incident to law enforcement and regulators
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 23 weeks(162 days from discovery to filing)
- Compliance flags
- CA 60-day late · 162dLeak >90dCA AG copy ≤15d · 0d
- Discovery-date grounding
- letter-groundedThe discovery date is the detection date narrated in the notification letter — the defensible tier.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Sep 23, 2025→ Notified: Mar 4, 2026162d 60 days (analyst band, pre-2026 discoveries) CA 60-day late California Consumers notified: Mar 4, 2026→ AG copy submitted: Mar 4, 20260d 15 calendar days CA AG copy ≤15d
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.