Imagine360
ent_be917c29ab1a4f04c9212dd4
Disclosures
12
State AG · HHS OCR · Leak Site · 8 jurisdictions
Incidents
2
filings grouped by incident
Max affected reported
132,651
nationwide · State AG ME
Leak-site claims
1
unverified actor claims
Identity resolution
- Canonical name
- Imagine360
- Normalized
- imagine360— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- No match
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- imagine360.com
Disclosure history (12)newest first
- ⛰️New Hampshire State AGas victim2025-03-07
Imagine360, LLC notified New Hampshire residents that unauthorized access to an employee's email account occurred on May 10 and May 16, 2024. The company discovered the breach on January 24, 2025. Personal information and protected health information were accessible in the emails. No evidence of data download or copying was found. Imagine360 reset passwords, enhanced email security, and offered credit monitoring to affected individuals.
- PAHHS OCRas victim2024-07-17
Imagine360, LLC (a Business Associate in PA) reported to HHS on 2024-07-17 a Hacking/IT Incident (email phishing scheme) affecting 6,926 individuals. Multiple employees were targeted; PHI exposed included names, dates of birth, diagnoses, claims and financial information, health insurance information, and Social Security numbers. Breached information located on Email. In response, the CE reset all passwords, disabled open sessions for compromised accounts, notified HHS, affected individuals, the media, and posted substitute notice on its website.
- ⛰️New Hampshire State AGas victim2023-07-21
Imagine360, LLC notified individuals of a data security incident involving third-party file sharing platforms (Citrix and Fortra/ShareFile). Unauthorized actors copied files between January 28-30, 2023. Imagine360 detected unusual activity on January 30, 2023, terminated access, reset passwords, and engaged in investigations. Personal information, potentially including SSNs and health plan data, was compromised. Remediation included suspending the vendor platform, implementing safeguards, and offering credit monitoring.
- 🦞Maine State AGas victim2023-07-21
Imagine360, a healthcare entity based in Wayne, PA, reported a data breach affecting 132,651 individuals, including 260 Maine residents. The breach occurred on January 28, 2023, and was discovered on June 1, 2023. The incident involved the unauthorized acquisition of names and Social Security Numbers. Imagine360 provided written notification to affected individuals on July 21, 2023, and offered 12 months of identity theft and credit monitoring services through IDX.
- 🐻California State AGas victim2023-07-21
Imagine360, LLC notified the California AG of a data security incident involving unauthorized access to third-party file sharing platforms (Citrix and Fortra). An unauthorized actor copied data between January 28 and January 30, 2023. Imagine360 identified unusual activity on January 30, 2023, and was notified by Fortra on February 3, 2023. The incident involved personal information including names and potentially other health-related data. Imagine360 suspended use of the platforms, reset passwords, engaged in investigation, and offered identity monitoring services.
- ⛰️New Hampshire State AGas victim2023-07-05
Imagine360, LLC notified the New Hampshire AG of a data incident involving third-party file-sharing platforms (Citrix and Fortra/GoAnywhere). Unauthorized actors copied data between Jan 28-30, 2023. The breach affected 82 NH residents, exposing personal and health insurance claims information. Imagine360 terminated access, reset passwords, engaged in investigations, notified law enforcement, and offered credit monitoring.
- 🍁Vermont State AGas victim2023-06-30
Imagine360, LLC notified consumers of a data breach involving third-party file-sharing platforms (Citrix and Fortra). Unauthorized actors copied files containing personal information (names, government IDs) between Jan 28-30, 2023. Imagine360 terminated access, reset passwords, engaged in investigations, reported to law enforcement, and offered 1-2 years of identity monitoring. The incident is classified as a third-party supply chain compromise.
- 🐻California State AGas victim2023-06-30
Imagine360, LLC notified the California AG of a data security incident involving third-party file sharing platforms (Citrix and Fortra). Unauthorized actors copied files between January 28 and January 30, 2023. Imagine360 identified unusual activity on January 30, 2023, and was notified by Fortra on February 3, 2023. The incident affected health insurance claim data, including names and potentially other PHI. Imagine360 terminated access, reset passwords, engaged law enforcement, and offered identity monitoring services.
- 🌲Washington State AGas victim2023-06-30
Imagine360, a health sector entity reported a unclear/unknown incident to the Washington Attorney General. The organization became aware of the incident on 2023-01-30 and filed notice on 2023-06-30. 1,478 Washington residents were affected. 151 days elapsed between awareness and notification. 2 days to identify the breach. 0 days to contain the breach.
- 🦫Oregon State AGas victim2023-06-30
Imagine360 reported a data breach to the Oregon Attorney General. The breach was reported on 2023-06-30. The breach occurred during 1/28/2023 - 1/30/2023. The breach was discovered on 6/1/2023. 112,611 individuals were affected. Notice was sent on 6/30/2023.
- 🦞Maine State AGas victim2023-06-30
Imagine360, a healthcare entity based in Pennsylvania, reported a data breach affecting 112,611 individuals, including 249 Maine residents. The breach occurred on January 28, 2023, and was discovered on June 1, 2023. The incident involved the acquisition of names and Social Security Numbers. Imagine360 provided 12 months of identity theft and credit monitoring services through IDX to affected individuals.
- GLOBALLeak Siteas victim2023-03-24
403 Forbidden