Brightline, Inc.
ent_4011d0cb56c7ae20539ff97a
Disclosures
14
State AG · HHS OCR · 8 jurisdictions
Multi-filing incidents
3
incidents joining 2+ filings here
Max affected reported
35,492
nationwide · State AG IN
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- Brightline, Inc.
- Normalized
- brightline— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- No match
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- gobrightline.com
Disclosure history (14)newest first
- Idaho State AGas victim2023-05-30
Brightline, Inc. notified Idaho AG of a data breach involving third-party vendor Fortra's GoAnywhere MFT SaaS. An unauthorized party exploited a previously unknown vulnerability on Jan 30, 2023, to access and download files containing names, addresses, member IDs, DOBs, and health coverage data. Brightline was notified Feb 4, 2023, contained the incident, and began notifying affected individuals on April 7, 2023, offering 2 years of credit monitoring.
- CALIFORNIAHHS OCRas victim2023-05-26
Brightline, Inc. reported to HHS on 2023-05-26 a Hacking/IT Incident affecting 8432 individuals. Breached information located on Network Server. The business associate's third-party provider was the victim of a cyber-attack. PHI involved included names, dates of birth, addresses, member/group IDs, and gender. Brightline provided credit monitoring and implemented additional safeguards.
- Massachusetts State AGas victim2023-05-17
Brightline, Inc. reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2023-05-17. 9 Massachusetts residents were affected. The report records the breach type as electronic.
- California State AGas victim2023-05-12
Brightline, Inc., a virtual healthcare services provider, disclosed a data security incident involving its vendor, Fortra (formerly HelpSystems). On January 30, 2023, Fortra identified unauthorized access to its GoAnywhere file transfer software. Brightline learned of the incident on February 4, 2023, and immediately engaged its incident response plan, terminating unauthorized access. The incident involved the acquisition of files containing eligibility information, including name, member ID, group ID, gender, and date of birth. Brightline is offering 24 months of complimentary identity theft restoration and credit monitoring services through Cyberscout.
- Massachusetts State AGas victim2023-05-10
Brightline, Inc. reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2023-05-10. 137 Massachusetts residents were affected. The report records the breach type as electronic.
- South Carolina State AGas victim2023-04-19
Brightline, Inc. notified individuals of a data breach involving its third-party file transfer provider, Fortra. An unauthorized party exploited a vulnerability in Fortra's GoAnywhere MFT service on Jan 30, 2023, to access files containing demographic PII (name, address, DOB, member ID). Brightline was notified on Feb 4, 2023, and sent notices on Apr 7, 2023. No PHI or SSNs were involved. Credit monitoring offered.
- Massachusetts State AGas victim2023-04-10
Brightline, Inc. reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2023-04-10. 8,513 Massachusetts residents were affected. The report records the breach type as electronic.
- Indiana State AGas victim2023-04-07
Brightline, Inc reported a data breach to the Indiana Attorney General. 2,373 Indiana residents were affected. 35,492 individuals affected in total.
- Delaware State AGas victim2023-04-07
Brightline, Inc., a virtual behavioral health provider, disclosed a data breach involving its third-party file transfer vendor, Fortra. An unauthorized party exploited a previously unknown vulnerability in Fortra's GoAnywhere MFT service on January 30, 2023, to access files containing demographic PII (name, address, DOB, member ID) of plan participants. Brightline was notified on February 4, 2023, deactivated credentials, and engaged forensic counsel. Notices were sent on April 7, 2023, offering 2 years of credit monitoring.
- CALIFORNIAHHS OCRas victim2023-04-07
Brightline, Inc. (a Business Associate) reported to HHS on 2023-04-07 a Hacking/IT Incident affecting 7,672 individuals. The breach originated from a cyber-attack on Brightline's vendor. PHI involved included names, dates of birth, and addresses, located on a Network Server. Brightline notified HHS, affected individuals, and the media, provided credit monitoring, and implemented additional safeguards. OCR provided technical assistance regarding HIPAA Privacy Rules.
- CALIFORNIAHHS OCRas victim2023-04-07
Brightline, Inc. reported to HHS on 2023-04-07 a Hacking/IT Incident affecting 31440 individuals. Breached information located on Network Server. The business associate's third-party provider was the victim of a cyber-attack affecting PHI including names, DOB, addresses, and member IDs. Brightline provided credit monitoring and implemented safeguards.
- CALIFORNIAHHS OCRas victim2023-04-07
Brightline, Inc. reported to HHS on 2023-04-07 a Hacking/IT Incident affecting 4044 individuals. Breached information located on Network Server. The business associate's third-party provider was the victim of a cyber-attack. PHI involved included names, dates of birth, addresses, member/group IDs, and gender. The BA provided credit monitoring and implemented safeguards.
- Vermont State AGas victim2023-04-07
Brightline, Inc. notified consumers of a data breach involving its third-party file transfer provider, Fortra. An unauthorized party exploited a previously unknown vulnerability in Fortra's GoAnywhere MFT service on Jan 30, 2023, to access files containing demographic PII (name, address, DOB, member ID) of Brightline plan enrollees. No SSNs or financial data were compromised. Brightline engaged cyber counsel and offered 2 years of credit monitoring via Cyberscout.
- Illinois State AGas victim2023-01-01
BRIGHTLINE, INC. filed a data-breach notice with the Illinois Attorney General during 2023 (case 23-214). The register records the breach as discovered on January 28, 2023. Illinois does not publish the number of people affected — 815 ILCS 530/10 permits the Attorney General to publish only the entity name, the types of personal information and the date range.
Supply-chain cascadesreviewed and confirmed
- Brightline, Inc.’s filing is one of at least 12 in the FORTRA, LLC supply-chain incident (2023).