Insightin Health
ent_8f8e0b447b311b857664c3a2
Disclosures
13
State AG · HHS OCR · Leak Site · 9 jurisdictions
Multi-filing incidents
1
incidents joining 2+ filings here
Max affected reported
1,949,534
nationwide · HHS OCR MD
Leak-site claims
2
unverified actor claims
Identity resolution
- Canonical name
- Insightin Health
- Normalized
- insightin health— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- No match
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- insightinhealth.com
Disclosure history (13)newest first
- California State AGas victim2026-04-01
Insightin Health, Inc. disclosed a data breach where an unauthorized actor exploited a previously unknown vulnerability in a vendor's software to access the company's network between September 17 and September 23, 2025. The actor may have viewed or copied files containing names, dates of birth, gender, and health plan information. No SSNs or financial data were involved. Insightin engaged forensic experts, secured systems, and is offering 12 months of credit monitoring. This is a supplemental notice.
- Vermont State AGas victim2026-04-01
Insightin Health, Inc. notified the Vermont Attorney General of a data breach affecting 11,496 Vermont residents. The incident involved unauthorized access to Insightin's network via a zero-day vulnerability in GoAnywhere software between September 17-23, 2025. Affected data included names, dates of birth, gender, and health plan information. Insightin engaged law enforcement, provided 12 months of credit monitoring through TransUnion, and implemented additional security safeguards.
- Texas State AGas victim2026-03-10
Insightin Health, Inc. based in Baltimore, Maryland, a business – retail or merchant entity reported a data breach to the Texas Attorney General. The breach was discovered on 2026-01-06 and reported on 2026-03-10. 143,346 Texas residents were affected. 1,777,141 individuals affected in total. Types of information involved: Name of individual;Address;Medical Information;Health Insurance Information. Consumers were notified via Notice by publication in print media;Posted at company website or special website;U.S. Mail.
- Washington State AGas victim2026-03-05
Insightin Health, Inc. notified Washington AG of a cyberattack exploiting a zero-day vulnerability in GoAnywhere software. Unauthorized access occurred Sept 17-23, 2025, affecting 11,740 WA residents. Data included names, DOBs, and health/insurance info. Insightin engaged forensic specialists, notified law enforcement, and provided 12 months of credit monitoring.
- Oregon State AGas victim2026-03-05
Insightin Health, Inc. reported a data breach to the Oregon Attorney General. The breach was reported on 2026-03-05. The breach occurred during 9/17/2025 - 9/23/2025. The breach was discovered on 9/23/2025. 1,144,686 individuals were affected. Notice was sent on 3/4/2026.
- California State AGas victim2026-03-05
Insightin Health, Inc. disclosed that an unauthorized party exploited a design flaw in its GoAnywhere file-transfer tool to access data between September 17 and September 23, 2025. The incident affected personal information including names, provider names, insurance info, and member IDs. No SSNs or financial data were involved. Insightin engaged experts, contained the breach, and offered 12 months of credit monitoring.
- Vermont State AGas victim2026-03-04
Insightin Health, Inc. disclosed a cybersecurity incident involving the GoAnywhere file-transfer tool. An unauthorized party exploited an unknown design flaw to access files between September 17 and 23, 2025. The breach exposed names, provider names, insurance info, and member IDs of approximately 1,641 Rhode Island residents. Insightin secured the environment, engaged experts, and offered 12 months of credit monitoring.
- Montana State AGas victim2026-03-04
Insightin Health, Inc. disclosed a cybersecurity incident involving its GoAnywhere file-transfer tool. An unauthorized party exploited a design flaw in the software to access data on a subset of servers between September 17 and 23, 2025. The incident affected personal information, including names, healthcare provider names, insurance information, and member IDs, for a subset of individuals associated with Insightin's health plan clients. Insightin engaged third-party experts, secured the environment, and offered 12 months of credit monitoring. The notification was sent on March 4, 2026.
- Vermont State AGas victim2026-01-28
Insightin Health, Inc. notified consumers of a security incident in September 2025 where an unauthorized actor exploited a previously unknown vulnerability in a third-party application to access the network. Files containing names were accessed between Sept 17-23, 2025. Insightin engaged forensic specialists, reported to law enforcement, and offers 12 months of credit monitoring.
- MARYLANDHHS OCRas victim2026-01-16
Insightin Health, Inc. reported to HHS on 2026-01-16 a Hacking/IT Incident affecting 1949534 individuals. Breached information located on Network Server. Business associate present.
- Illinois State AGas victim2026-01-01
INSIGHTIN HEALTH, INC. filed a data-breach notice with the Illinois Attorney General in January 2026 (case 26-01-772). The register records the breach as discovered on March 24, 2026. Personal information types reported: medical information. Illinois does not publish the number of people affected — 815 ILCS 530/10 permits the Attorney General to publish only the entity name, the types of personal information and the date range.
- GLOBALLeak Siteas victim2025-09-26
Insightin Health helps healthcare payers eliminate data silos and deliver highly satisfying consumer-centric experiences. inGAGE our software as a service (Saas) platform is the industry leading solution for quickly creating a connected data ecosystem. Using artificial intelligence and machine learning techniques, inGAGE leverages the totality of the connected data, in real-time, to produce insights that drive Next Best Action (NBA) recommendations to solve pressing healthcare challenges. inGAGE allows healthcare payers to deliver lifetime member value, driving growth and increasing overall plan profitability. company is headquartered in 333 W Ostend St. Suite 100 Baltimore, MD 21230. 45 Employees. The total amount of data leakage is 378 GB
- GLOBALLeak Siteas victim2025-09-23
Insightin Health helps healthcare payers eliminate data silos and deliver highly satisfying consumer-centric experiences. inGAGE our software as a service (Saas) platform is the industry leading solution for quickly creating a connected data ecosystem. Using artificial intelligence and machine learning techniques, inGAGE leverages the totality of the connected data, in real-time, to produce insights that drive Next Best Action (NBA) recommendations to solve pressing healthcare challenges. inGAGE allows healthcare payers to deliver lifetime member value, driving growth and increasing overall plan profitability. company is headquartered in 333 W Ostend St. Suite 100 Baltimore, MD 21230. 45 Employees. The total amount of data leakage is 378 GB