Imagine360
ent_be917c29ab1a4f04c9212dd4
Disclosures
19
State AG · HHS OCR · Leak Site · 11 jurisdictions
Multi-filing incidents
2
incidents joining 2+ filings here
Max affected reported
132,807
nationwide · HHS OCR PA
Leak-site claims
1
unverified actor claims
Identity resolution
- Canonical name
- Imagine360
- Normalized
- imagine360— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- No match
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- imagine360.com
Disclosure history (19)newest first
- New Hampshire State AGas victim2025-03-07
Imagine360, LLC notified New Hampshire residents that unauthorized access to an employee's email account occurred on May 10 and May 16, 2024. The company discovered the breach on January 24, 2025. Personal information and protected health information were accessible in the emails. No evidence of data download or copying was found. Imagine360 reset passwords, enhanced email security, and offered credit monitoring to affected individuals.
- Massachusetts State AGas victim2025-03-07
Imagine360, LLC reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2025-03-07. 36 Massachusetts residents were affected.
- Illinois State AGas victim2025-03-01
IMAGINE360, LLC filed a data-breach notice with the Illinois Attorney General in March 2025 (case 25-03-011). The register records the breach as discovered on May 10, 2024. Illinois does not publish the number of people affected — 815 ILCS 530/10 permits the Attorney General to publish only the entity name, the types of personal information and the date range.
- PENNSYLVANIAHHS OCRas victim2024-07-17
Imagine360, LLC (a Business Associate in PA) reported to HHS on 2024-07-17 a Hacking/IT Incident (email phishing scheme) affecting 6,926 individuals. Multiple employees were targeted; PHI exposed included names, dates of birth, diagnoses, claims and financial information, health insurance information, and Social Security numbers. Breached information located on Email. In response, the CE reset all passwords, disabled open sessions for compromised accounts, notified HHS, affected individuals, the media, and posted substitute notice on its website.
- New Hampshire State AGas victim2023-07-21
Imagine360, LLC notified individuals of a data security incident involving third-party file sharing platforms (Citrix and Fortra/ShareFile). Unauthorized actors copied files between January 28-30, 2023. Imagine360 detected unusual activity on January 30, 2023, terminated access, reset passwords, and engaged in investigations. Personal information, potentially including SSNs and health plan data, was compromised. Remediation included suspending the vendor platform, implementing safeguards, and offering credit monitoring.
- Maine State AGas victim2023-07-21
Imagine360, a healthcare entity based in Wayne, PA, reported a data breach affecting 132,651 individuals, including 260 Maine residents. The breach occurred on January 28, 2023, and was discovered on June 1, 2023. The incident involved the unauthorized acquisition of names and Social Security Numbers. Imagine360 provided written notification to affected individuals on July 21, 2023, and offered 12 months of identity theft and credit monitoring services through IDX.
- California State AGas victim2023-07-21
Imagine360, LLC notified the California AG of a data security incident involving unauthorized access to third-party file sharing platforms (Citrix and Fortra). An unauthorized actor copied data between January 28 and January 30, 2023. Imagine360 identified unusual activity on January 30, 2023, and was notified by Fortra on February 3, 2023. The incident involved personal information including names and potentially other health-related data. Imagine360 suspended use of the platforms, reset passwords, engaged in investigation, and offered identity monitoring services.
- New Hampshire State AGas victim2023-07-05
Imagine360, LLC notified the New Hampshire AG of a data incident involving third-party file-sharing platforms (Citrix and Fortra/GoAnywhere). Unauthorized actors copied data between Jan 28-30, 2023. The breach affected 82 NH residents, exposing personal and health insurance claims information. Imagine360 terminated access, reset passwords, engaged in investigations, notified law enforcement, and offered credit monitoring.
- South Carolina State AGas victim2023-07-03
Imagine360, LLC notified South Carolina consumers of a data breach involving a third-party file sharing platform (Fortra/Citrix). Unauthorized actors copied data between Jan 28-30, 2023. Data included names and potentially government IDs. Imagine360 terminated access, reset passwords, engaged law enforcement, and offered 1 year of identity monitoring. 81 Rhode Island residents were impacted.
- Vermont State AGas victim2023-06-30
Imagine360, LLC notified consumers of a data breach involving third-party file-sharing platforms (Citrix and Fortra). Unauthorized actors copied files containing personal information (names, government IDs) between Jan 28-30, 2023. Imagine360 terminated access, reset passwords, engaged in investigations, reported to law enforcement, and offered 1-2 years of identity monitoring. The incident is classified as a third-party supply chain compromise.
- Massachusetts State AGas victim2023-06-30
Imagine360 reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2023-06-30. 257 Massachusetts residents were affected. The report records the breach type as electronic.
- California State AGas victim2023-06-30
Imagine360, LLC notified the California AG of a data security incident involving third-party file sharing platforms (Citrix and Fortra). Unauthorized actors copied files between January 28 and January 30, 2023. Imagine360 identified unusual activity on January 30, 2023, and was notified by Fortra on February 3, 2023. The incident affected health insurance claim data, including names and potentially other PHI. Imagine360 terminated access, reset passwords, engaged law enforcement, and offered identity monitoring services.
- Washington State AGas victim2023-06-30
Imagine360, LLC issued a supplemental notice to the Washington State Attorney General regarding a data security incident involving third-party file-sharing platforms (Citrix and Fortra). Unauthorized actors copied data between January 28 and 30, 2023. The breach affected 1,478 Washington residents, exposing names, dates of birth, medical information, health insurance IDs, and Social Security numbers. Imagine360 terminated access, reset passwords, reported to law enforcement, and provided identity monitoring services.
- PENNSYLVANIAHHS OCRas victim2023-06-30
Imagine360 reported to HHS on 2023-06-30 a Hacking/IT Incident affecting 132,807 individuals. Breached information located on Network Server. The business associate reported that two of its vendors experienced a cyber-attack compromising PHI including names, addresses, DOB, driver's license, SSN, financial info, and diagnoses. The BA offered identity protection services and implemented additional technical safeguards.
- Oregon State AGas victim2023-06-30
Imagine360 reported a data breach to the Oregon Attorney General. The breach was reported on 2023-06-30. The breach occurred during 1/28/2023 - 1/30/2023. The breach was discovered on 6/1/2023. 112,611 individuals were affected. Notice was sent on 6/30/2023.
- Maine State AGas victim2023-06-30
Imagine360, a healthcare entity based in Pennsylvania, reported a data breach affecting 112,611 individuals, including 249 Maine residents. The breach occurred on January 28, 2023, and was discovered on June 1, 2023. The incident involved the acquisition of names and Social Security Numbers. Imagine360 provided 12 months of identity theft and credit monitoring services through IDX to affected individuals.
- GLOBALLeak Siteas victim2023-03-24
- Illinois State AGas victim2023-01-01
IMAGINE360, LLC filed a data-breach notice with the Illinois Attorney General during 2023 (case 23-438). The register records the breach as discovered on June 1, 2023. Illinois does not publish the number of people affected — 815 ILCS 530/10 permits the Attorney General to publish only the entity name, the types of personal information and the date range.
- Illinois State AGas victim2023-01-01
IMAGINE360, LLC filed a data-breach notice with the Illinois Attorney General during 2023 (case 23-482). The register records the breach as discovered on May 30, 2023. Illinois does not publish the number of people affected — 815 ILCS 530/10 permits the Attorney General to publish only the entity name, the types of personal information and the date range.