Brightline
ent_4a9ab54c8c9cfb66421b5d56
Brightline provides in-person and virtual mental health care services for children, teenagers, and parents, offering therapy, psychiatry, testing, and focused programs.
AI-summarized from indexed web sources · 2026-08-16 · source
Disclosures
25+
HHS OCR · State AG · 8 jurisdictions
Multi-filing incidents
1
incidents joining 2+ filings here
Max affected reported
473,467
nationwide · HHS OCR CA
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- Brightline
- Normalized
- brightline— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- No match
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- hellobrightline.com
Disclosure history (newest 25)newest first
- CALIFORNIAHHS OCRas victim2023-05-26
Brightline, Inc. reported to HHS on 2023-05-26 a Hacking/IT Incident affecting 8432 individuals. Breached information located on Network Server. The business associate's third-party provider was the victim of a cyber-attack. PHI involved included names, dates of birth, addresses, member/group IDs, and gender. Brightline provided credit monitoring and implemented additional safeguards.
- California State AGas victim2023-05-17
Brightline, Inc., a virtual behavioral health provider, notified the California AG of a data breach affecting subscriber eligibility information. The incident stemmed from a third-party vendor, Fortra, whose GoAnywhere MFT service was compromised via a previously unknown vulnerability on January 30, 2023. Brightline became aware of the incident on February 4, 2023. Affected data included names, addresses, member IDs, dates of birth, phone numbers, and employer information. No SSNs, financial accounts, or medical records were involved. Brightline removed data from the service, implemented additional security measures, and offered 2 years of credit monitoring.
- California State AGas victim2023-05-12
Brightline, Inc., a virtual healthcare services provider, disclosed a data security incident involving its vendor, Fortra (formerly HelpSystems). On January 30, 2023, Fortra identified unauthorized access to its GoAnywhere file transfer software. Brightline learned of the incident on February 4, 2023, and immediately engaged its incident response plan, terminating unauthorized access. The incident involved the acquisition of files containing eligibility information, including name, member ID, group ID, gender, and date of birth. Brightline is offering 24 months of complimentary identity theft restoration and credit monitoring services through Cyberscout.
- California State AGas victim2023-05-10
Brightline, Inc. notified the California AG of a data breach involving its third-party provider Fortra (GoAnywhere MFT SaaS). An unauthorized party exploited a previously unknown vulnerability on Jan 30, 2023, to access accounts and download files. Brightline became aware on Feb 4, 2023. Affected data includes names, DOB, SSN, and employment info for HP employees. No clinical data or financial accounts were involved. Brightline rebuilt infrastructure, removed data from the service, and offered 2 years of credit monitoring.
- CALIFORNIAHHS OCRas victim2023-05-10
Brightline, Inc. reported to HHS on 2023-05-10 a Hacking/IT Incident affecting 28,975 individuals. Breached information located on Network Server. The business associate's third-party provider was the victim of a cyber-attack. PHI involved included names, dates of birth, addresses, member/group IDs, and gender. Brightline provided credit monitoring and implemented safeguards.
- Maine State AGas victim2023-05-10
Brightline, Inc., a healthcare organization, reported a data breach affecting 9 Maine residents. The breach, which occurred on January 30, 2023, and was discovered on February 6, 2023, was attributed to a vendor incident. The compromised information includes names and Social Security numbers. In response, Brightline is offering 24 months of complimentary credit monitoring services through TransUnion.
- Oregon State AGas victim2023-05-02
Brightline, Inc reported a data breach to the Oregon Attorney General. The breach was reported on 2023-05-02. The breach occurred during 1/30/2023. The breach was discovered on 2/4/2023. Notice was sent on 4/7/2023.
- California State AGas victim2023-04-21
Brightline, Inc. notified the California AG of a data breach involving a third-party vendor, Fortra (GoAnywhere MFT). An unauthorized party exploited a previously unknown vulnerability in Fortra's SaaS to access and download files containing personal information of Stanford group health plan members. Affected data includes names, addresses, DOBs, phone numbers, member IDs, employer names, and coverage dates. Brightline deactivated credentials, rebuilt infrastructure, and removed data from the affected service. Identity theft protection services were offered.
- CALIFORNIAHHS OCRas victim2023-04-20
Brightline, Inc. (a Business Associate, CA) reported to HHS on 2023-04-20 a Hacking/IT Incident affecting 180,694 individuals. Breached information was located on a Network Server. Brightline's third-party provider was the victim of a cyber-attack exposing PHI including names, dates of birth, addresses, member and group ID numbers, and gender identification. The BA notified HHS, affected individuals, and the media, provided substitute notice, offered credit monitoring, and implemented additional security safeguards. OCR provided technical assistance on HIPAA rules.
- Vermont State AGas victim2023-04-19
Brightline, Inc. notified consumers of a data breach involving its third-party file transfer provider, Fortra (GoAnywhere MFT SaaS). The incident, occurring around Jan 30, 2023, exploited a vulnerability to access accounts. Affected data included names, DOB, SSN, and employment info. Brightline disabled access, removed data, and offered 2 years of credit monitoring.
- New Hampshire State AGas victim2023-04-17
Brightline, Inc. notified the NH AG of a data breach involving its third-party vendor Fortra's GoAnywhere MFT SaaS. An unauthorized party exploited a previously unknown vulnerability to access accounts and download files starting Jan 30, 2023. Brightline learned of the incident on Feb 4, 2023. Approximately 180 NH residents were affected, with data including names, addresses, DOBs, member IDs, and some SSNs. Brightline engaged its incident response plan, retained counsel, and offered 2 years of credit monitoring.
- CALIFORNIAHHS OCRas victim2023-04-13
Brightline, Inc. reported to HHS on 2023-04-13 a Hacking/IT Incident affecting 49,968 individuals. Breached information located on Network Server. The business associate's third-party provider was the victim of a cyber-attack. PHI included names, DOB, addresses, and member IDs. BA provided credit monitoring and implemented safeguards.
- California State AGas victim2023-04-12
Brightline, Inc., a virtual behavioral health provider, notified affected individuals of a data security incident involving Fortra's GoAnywhere MFT SaaS, a third-party file transfer service. On January 30, 2023, Fortra discovered suspicious activity; an unauthorized party exploited a previously-unknown vulnerability to access customer accounts and download files. Brightline learned of the incident on February 4, 2023. Exposed data included names, addresses, member IDs, dates of birth, phone numbers, employer names, group IDs, coverage dates, and for some, Social Security numbers. Brightline responded by rebuilding infrastructure, restricting access, and offering 2 years of credit monitoring via Cyberscout.
- Washington State AGas victim2023-04-10
Brightline, Inc. notified Washington AG of a breach involving third-party vendor Fortra's GoAnywhere MFT service. Unauthorized access occurred Jan 30, 2023, exploiting a previously unknown vulnerability. Brightline was notified Feb 4, 2023. Data exposed included names, addresses, DOBs, member IDs, and SSNs for ~26,333 WA residents. Notifications sent April 7, 2023.
- CALIFORNIAHHS OCRas victim2023-04-07
Brightline, Inc. reported to HHS on 2023-04-07 a Hacking/IT Incident affecting 199,753 individuals. Breached information located on Network Server. The business associate's third-party provider was the victim of a cyber-attack. PHI involved included names, dates of birth, addresses, member/group IDs, and gender. The BA provided complimentary credit monitoring and implemented additional security safeguards.
- Maine State AGas victim2023-04-07
Brightline, Inc. reported a cybersecurity incident involving its vendor, Fortra, occurring on January 30, 2023. The breach affected 27,742 individuals, including 58 Maine residents. The incident involved the unauthorized acquisition of names and Social Security Numbers. Brightline notified affected individuals on April 7, 2023, and offered two years of complimentary credit monitoring services.
- Montana State AGas victim2023-04-07
Brightline, Inc. notified Montana residents of a data breach involving its third-party file transfer provider, Fortra. An unauthorized party exploited a vulnerability in Fortra's GoAnywhere MFT service on Jan 30, 2023, to access files containing demographic PII (name, address, DOB, member ID). Brightline detected the incident on Feb 4, 2023, and sent notifications on Apr 7, 2023. No SSNs or financial data were compromised. Credit monitoring services were offered.
- CALIFORNIAHHS OCRas victim2023-04-07
Brightline, Inc. reported to HHS on 2023-04-07 a Hacking/IT Incident affecting 7411 individuals. Breached information located on Network Server. The business associate's third-party provider was the victim of a cyber-attack. PHI included names, DOB, addresses, member/group IDs, and gender. BA provided credit monitoring and implemented safeguards.
- CALIFORNIAHHS OCRas victim2023-04-07
Brightline, Inc. reported to HHS on 2023-04-07 a Hacking/IT Incident affecting 473,467 individuals. Breached information located on Network Server. The business associate's third-party provider was the victim of a cyber-attack. PHI included names, DOB, addresses, and member IDs. Brightline provided credit monitoring and implemented safeguards.
- CALIFORNIAHHS OCRas victim2023-04-07
Brightline, Inc. reported to HHS on 2023-04-07 a Hacking/IT Incident affecting 21,830 individuals. Breached information located on Network Server. The business associate's third-party provider was the victim of a cyber-attack. PHI included names, dates of birth, addresses, member/group IDs, and gender. Response included credit monitoring and security safeguards.
- Delaware State AGas victim2023-04-07
Brightline, Inc., a virtual behavioral health provider, disclosed a data breach involving its third-party file transfer vendor, Fortra. An unauthorized party exploited a previously unknown vulnerability in Fortra's GoAnywhere MFT service on January 30, 2023, to access files containing demographic PII (name, address, DOB, member ID) of plan participants. Brightline was notified on February 4, 2023, deactivated credentials, and engaged forensic counsel. Notices were sent on April 7, 2023, offering 2 years of credit monitoring.
- CALIFORNIAHHS OCRas victim2023-04-07
Brightline, Inc. (a Business Associate) reported to HHS on 2023-04-07 a Hacking/IT Incident affecting 7,672 individuals. The breach originated from a cyber-attack on Brightline's vendor. PHI involved included names, dates of birth, and addresses, located on a Network Server. Brightline notified HHS, affected individuals, and the media, provided credit monitoring, and implemented additional safeguards. OCR provided technical assistance regarding HIPAA Privacy Rules.
- CALIFORNIAHHS OCRas victim2023-04-07
Brightline, Inc. reported to HHS on 2023-04-07 a Hacking/IT Incident affecting 31440 individuals. Breached information located on Network Server. The business associate's third-party provider was the victim of a cyber-attack affecting PHI including names, DOB, addresses, and member IDs. Brightline provided credit monitoring and implemented safeguards.
- CALIFORNIAHHS OCRas victim2023-04-07
Brightline, Inc. reported to HHS on 2023-04-07 a Hacking/IT Incident affecting 4044 individuals. Breached information located on Network Server. The business associate's third-party provider was the victim of a cyber-attack. PHI involved included names, dates of birth, addresses, member/group IDs, and gender. The BA provided credit monitoring and implemented safeguards.
- Vermont State AGas victim2023-04-07
Brightline, Inc. notified consumers of a data breach involving its third-party file transfer provider, Fortra. An unauthorized party exploited a previously unknown vulnerability in Fortra's GoAnywhere MFT service on Jan 30, 2023, to access files containing demographic PII (name, address, DOB, member ID) of Brightline plan enrollees. No SSNs or financial data were compromised. Brightline engaged cyber counsel and offered 2 years of credit monitoring via Cyberscout.
Supply-chain cascadesreviewed and confirmed
- Brightline’s filing is one of at least 12 in the FORTRA, LLC supply-chain incident (2023).