HackingVulnerability ExploitStolen CredentialsZero-DaySupply Chain (3P Vendor)Data ExfiltratedCustomer Data InvolvedIDENTITY_BASICHEALTH_BASICLowContained
Insightin Health
bd_7fc85ada2e1884b9 · schema v1 · pii pii-v1
Full breach record for Insightin Health →Insightin Health, Inc. disclosed a data breach where an unauthorized actor exploited a previously unknown vulnerability in a vendor's software to access the company's network between September 17 and September 23, 2025. The actor may have viewed or copied files containing names, dates of birth, gender, and health plan information. No SSNs or financial data were involved. Insightin engaged forensic experts, secured systems, and is offering 12 months of credit monitoring. This is a supplemental notice.
Leak gap clock⏱ Leak >30d15 weeks discovery → filing
This filing is one of 6 about the same incident.View merged incident
Linked disclosures
Why this link?Ransomware claims (2)
- bd_5735d224535af425Leak Sitemedusafiled 2025-09-26(82d gap)Candidate
- bd_04a0838032966f07Leak Sitemedusafiled 2025-09-23(86d gap)Verified by operator
Regulatory filings (3) · sorted by filing gap
- bd_17bef6ae03a1347eWashington State AGfiled 2026-03-05(77d gap)Verified by operator
- bd_3070c615628a9518Oregon State AGfiled 2026-03-05(77d gap)Verified
- bd_d1b693a2d4ddee3fTexas State AGfiled 2026-03-10(82d gap)Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-621162
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Dec 18, 2025
- Raw hash
- a736de96babbd79b15cf895fac94690e9ee4032bfcd0884cf33b82a6d69e6774
Reporting entity
- Name
- Insightin Healthnorm: insightin health
- Domain
- insightinhealth.com
Victim entity
- Name
- Insightin Healthnorm: insightin health
- Domain
- insightinhealth.com
Incident
- Discovered
- Sep 1, 2025
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICHEALTH_BASIC
- Attack vector
- Unknown
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1078 Valid AccountsT1041 Exfiltration Over C2 Channel
- Threat actor
- External
- Regulator citations
- Reported the incident to law enforcement and regulators
- Third party
- via Vendor (unnamed)
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 15 weeks(108 days from discovery to filing)
- Compliance flags
- Leak >30d
- Discovery-date grounding
- letter-groundedThe discovery date is the detection date narrated in the notification letter — the defensible tier.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.