HackingVulnerability ExploitZero-DayData ExfiltratedCustomer Data InvolvedDelayed DiscoveryIDENTITY_BASICHEALTH_BASICMediumContained
Insightin Health
bd_9a2bd835940a4149 · schema v1 · pii pii-v1
Full breach record for Insightin Health →Insightin Health, Inc. notified the Vermont Attorney General of a data breach affecting 11,496 Vermont residents. The incident involved unauthorized access to Insightin's network via a zero-day vulnerability in GoAnywhere software between September 17-23, 2025. Affected data included names, dates of birth, gender, and health plan information. Insightin engaged law enforcement, provided 12 months of credit monitoring through TransUnion, and implemented additional security safeguards.
Vermont clock✗ VT AG >45 bday30 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 2 about the same incident.View merged incident
A leak claim by medusa about this victim predates this filing by 190 days.View originating leak claim
Linked disclosures
Why this link?Regulatory filings (1) · sorted by filing gap
- bd_30942dbf93d1eb24Vermont State AGfiled 2026-03-04(28d gap)Candidate
Source provenance
- Source URL
- https://ago.vermont.gov/document/2026-04-01-insightin-health-inc-data-breach-notice-consumers
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Apr 1, 2026
- Raw hash
- b0ad8ec597602ee00aa431be21689f1f3e9e9ca2d9a13e29f142cbbad9bf7d09
Reporting entity
- Name
- Insightin Healthnorm: insightin health
- Domain
- insightinhealth.com
Victim entity
- Name
- Insightin Healthnorm: insightin health
- Domain
- insightinhealth.com
Incident
- Discovered
- Sep 1, 2025
- Materiality determined
- —
- Notification sent
- Dec 4, 2025
- Affected individuals
- 11,496
- Data types
- IDENTITY_BASICHEALTH_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1119 Automated Collection
- Threat actor
- External
- Regulator citations
- Provided notice to Vermont Attorney General's office
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 30 weeks(212 days from discovery to filing)
- Compliance flags
- VT AG >45 bdayLeak >180d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.