Bodybuilding.com, LLC
ent_019ec1bc20bcd5e85682e2e2d5c5e583
Disclosures
3
State AG · HHS OCR · 3 jurisdictions
Multi-filing incidents
1
incidents joining 2+ filings here
Max affected reported
3,193
nationwide · HHS OCR ID
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- Bodybuilding.com, LLC
- Normalized
- bodybuildingcom— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- 549300MKZ8LDQYYH6278
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- None on record
- Corporate parent
- Vitalize LLC— as stated in the breach filing
Disclosure history (3)newest first
- Delaware State AGas victim2019-06-24
Bodybuilding.com (a subsidiary of Vitalize LLC) notified customers of a data breach involving unauthorized access to systems. The incident originated from a phishing email in July 2018, discovered in February 2019. Potentially accessed data included names, emails, passwords, and billing addresses. No full credit card numbers were stored. The company engaged forensic consultants, reset passwords, and coordinated with law enforcement.
- California State AGas victim2019-04-19
Bodybuilding.com (Vitalize, LLC) disclosed a data breach affecting customer accounts. Unauthorized access originated from a phishing email received in July 2018, but the incident was not discovered until February 2019. The investigation confirmed that some data was exfiltrated, though the specific files are unknown. Affected data may include names, email addresses, passwords, billing/shipping addresses, phone numbers, order history, birthdates, and BodySpace profile information. Full credit card numbers were not stored. The company engaged forensic consultants, reset passwords, and coordinated with law enforcement.
- IDAHOHHS OCRas victim2019-04-19
Bodybuilding.com LLC, operated by Vitalize, LLC reported to HHS on 2019-04-19 a Hacking/IT Incident affecting 3,193 individuals. Breached information located on Network Server. The incident involved protected health information (PHI) including names, dates of birth, Social Security numbers, health insurance information, treatment information, and claims data. The covered entity implemented administrative and technical safeguards and retrained staff.