HealthFirst Bluegrass
ent_7583c05a06cc18d8f6272efb
Disclosures
5
State AG · HHS OCR · 5 jurisdictions
Multi-filing incidents
1
incidents joining 2+ filings here
Max affected reported
971
nationwide · HHS OCR KY
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- HealthFirst Bluegrass
- Normalized
- healthfirst bluegrass— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- No match
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- None on record
Disclosure history (5)newest first
- Vermont State AGas victim2026-08-27
Healthfirst Bluegrass, Inc. reported a data breach to the Vermont Attorney General. The breach was reported to the AGO on 2026-08-27. The reporting organization type is Health Care. 5 Vermont residents were affected. Categories of data breached: Social Security Numbers, Health Records.
- Massachusetts State AGas victim2026-08-01
Healthfirst Bluegrass, Inc. notified residents of a security incident at its third-party vendor, Aesto LLC, a healthcare data migration and archiving service provider. An unauthorized actor accessed Aesto's AWS infrastructure between December 2 and December 18, 2025. Aesto discovered the incident on December 18, 2025. Affected data includes full names and potentially Social Security numbers (indicated by IRS IP PIN advice). The incident is contained. Healthfirst Bluegrass is offering 24 months of credit monitoring and identity theft protection. Rhode Island reported 6 affected residents; total Massachusetts count not explicitly stated in the provided text.
- Indiana State AGas victim2020-08-21
HealthFirst Bluegrass reported a data breach to the Indiana Attorney General. The breach occurred on 2020-04-15 and was reported on 2020-08-21. 1 Indiana residents were affected. 897 individuals affected in total.
- KENTUCKYHHS OCRas victim2020-08-21
HealthFirst Bluegrass (KY) reported to HHS on 2020-08-21 a Hacking/IT Incident affecting 971 individuals. An employee was the victim of an email phishing scheme that exposed ePHI including names, addresses, dates of birth, driver's license numbers, Social Security numbers, claims information, financial information, diagnoses, lab results, and medications. Breached information located in Email. The CE notified HHS, affected individuals, and media, offered credit monitoring, sanctioned the responsible employee, and implemented additional administrative and technical safeguards. OCR obtained assurances of corrective action.
- Illinois State AGas victim2020-01-01
HEALTHFIRST BLUEGRASS filed a data-breach notice with the Illinois Attorney General during 2020 (case 20-305). The register records the breach as discovered on April 15, 2020. Illinois does not publish the number of people affected — 815 ILCS 530/10 permits the Attorney General to publish only the entity name, the types of personal information and the date range.