Brightline
bd_954187ed06e346b7 · schema v1 · pii pii-v1
Full breach record for Brightline →Brightline, Inc., a virtual behavioral health provider, notified affected individuals of a data security incident involving Fortra's GoAnywhere MFT SaaS, a third-party file transfer service. On January 30, 2023, Fortra discovered suspicious activity; an unauthorized party exploited a previously-unknown vulnerability to access customer accounts and download files. Brightline learned of the incident on February 4, 2023. Exposed data included names, addresses, member IDs, dates of birth, phone numbers, employer names, group IDs, coverage dates, and for some, Social Security numbers. Brightline responded by rebuilding infrastructure, restricting access, and offering 2 years of credit monitoring via Cyberscout.
J jump to incidentP pin to compareR raw source
Incident timeline
Jan 30, 2023
Begins
Apr 12, 2023
Filed
Linked disclosures
Why this link?Regulatory filings (10) · sorted by filing gap
- Vermont State AGbd_5ea7d3fbb2a5464a2023-04-19 · +7dVerified
- HHS OCRbd_a0176e4142b0a3702023-04-20 · +8dVerified
- California State AGbd_a1b16fb406ed3ce92023-04-21 · +9dVerified
- Oregon State AGbd_163db05cc4cb89582023-05-02 · +20dVerified by operator
Show 6 more filings ↓Show fewer ↑up to 44d gap
- California State AGbd_0868c3f9cf5006022023-05-10 · +28dVerified
- HHS OCRbd_4c63e3855981b1222023-05-10 · +28dVerified
- Maine State AGbd_b69375073a6e96d42023-05-10 · +28dVerified
- California State AGbd_d59ed55c5ee4770a2023-05-12 · +30dVerified
- California State AGbd_bf99fc2a4df4a34d2023-05-17 · +35dVerified
- HHS OCRbd_f567c60a6fd57cc42023-05-26 · +44dVerified
Showing first 10 of 25 linked disclosures.
Filing propagation · 11 filings · 4 states
View merged incident ↗Pattern: first filing Apr 12 (CA), last May 26 (CA) — a 44-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?
Cascade drawn from the first 10 linked disclosures of 25 — the full spread may be wider.
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.