BrightSpring Health Services
ent_da6facc3b21060d37678640f
Disclosures
7
State AG · 7 jurisdictions
Incidents
1
filings grouped by incident
Max affected reported
535,203
nationwide · State AG ME
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- BrightSpring Health Services
- Normalized
- brightspring health— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- No match
- SEC EDGAR CIK
- 0001865782
- Domain
- None on record
Disclosure history (7)newest first
- ⛰️New Hampshire State AGas victim2023-08-11
BrightSpring Health Services notified affected individuals of a cybersecurity incident where an unknown third party accessed systems from March 12-13, 2023. The company discovered suspicious activity on March 14, 2023. Employee personal information was compromised. The company engaged cybersecurity advisors and offered one year of identity monitoring through Kroll.
- 🦞Maine State AGas victim2023-08-11
BrightSpring Healthcare Services, Inc. reported an external system breach (hacking) occurring March 12-13, 2023, discovered May 20, 2023. The incident affected 535,203 individuals, including 547 Maine residents. Acquired data included names and Social Security Numbers. BrightSpring provided 12 months of credit monitoring services through Kroll.
- 🌲Washington State AGas victim2023-08-11
BrightSpring Health Services, Inc., a health sector entity reported a ransomware incident to the Washington Attorney General. The organization became aware of the incident on 2023-03-14 and filed notice on 2023-08-11. 28,194 Washington residents were affected. 150 days elapsed between awareness and notification. 2 days to identify the breach. 0 days to contain the breach.
- 🍁Vermont State AGas victim2023-08-11
BrightSpring Health Services notified consumers of a cybersecurity incident where an unknown third party accessed systems from March 12-13, 2023. The breach exposed names, Social Security numbers, addresses, and dates of birth. No financial or health information was compromised. The company engaged cybersecurity advisors, enhanced security measures, and offered one year of Kroll identity monitoring.
- 🐻California State AGas victim2023-08-11
BrightSpring Health Services, Inc. reported that an unknown third party accessed its computer systems from March 12-13, 2023. The company discovered suspicious activity on March 14, 2023. The incident involved employee personal information, including names, Social Security numbers, and for some, addresses and dates of birth. Financial and health information were not involved. The company engaged cybersecurity advisors, enhanced technical security measures, and offered one year of identity monitoring through Kroll.
- 🦫Oregon State AGas victim2023-08-11
BrightSpring Health Services reported a data breach to the Oregon Attorney General. The breach was reported on 2023-08-11. The breach occurred during 3/12/2023 - 3/13/2023. The breach was discovered on 5/20/2023. 535,203 individuals were affected. Notice was sent on 6/21/20238/11/2023.
- 🦬Montana State AGas victim2023-08-10
BrightSpring Health Services reported a data breach to the Montana Attorney General. The breach was reported on 2023-08-10. The breach occurred from 3/12/2023 to 3/13/2023. 2,207 Montana residents were affected.
Subsidiary disclosures (9)filed by group companies
◈ These filings were made by or about subsidiaries of BrightSpring Health Services — not by BrightSpring Health Services itself. Corporate relationships are mapped from GLEIF relationship records and SEC Exhibit 21 filings.
- 🐻California State AGvia PharMerica Corporation2023-06-19
PharMerica Corporation reported that an unknown third party accessed its computer systems from March 12-13, 2023. The company discovered suspicious activity on March 14, 2023. Affected data included names, addresses, dates of birth, Social Security numbers, medications, and health insurance information. PharMerica engaged cybersecurity advisors and is offering one year of identity monitoring through Kroll.
- 🦞Maine State AGvia PharMerica Corporation2023-06-09
PharMerica Corporation reported an external system breach (hacking) occurring March 12-13, 2023, discovered on March 21, 2023. The incident affected 5,815,591 individuals, including 40,248 in Maine. Personal information acquired included names and Social Security Numbers. PharMerica provided written notification and offered one year of credit and identity monitoring services through Kroll.
- 💎Delaware State AGvia PharMerica Corporation2023-06-08
PharMerica notified affected individuals in Delaware and other states of a cybersecurity incident occurring March 12-13, 2023, discovered on March 14, 2023. An unknown third party accessed systems, obtaining names, addresses, DOBs, SSNs, medications, and health insurance info. PharMerica engaged cybersecurity advisors, enhanced technical security, and offered one year of Kroll identity monitoring.
- 💎Delaware State AGvia PharMerica Corporation2023-06-08
PharMerica Corporation notified Delaware AG of a cybersecurity incident occurring March 12-13, 2023, discovered March 14, 2023. An unknown third party accessed systems, obtaining names, addresses, DOBs, SSNs, medications, and health insurance info. PharMerica engaged cybersecurity advisors, enhanced technical security, and offered one year of Kroll identity monitoring.
- ⛰️New Hampshire State AGvia PharMerica Corporation2023-06-08
PharMerica Corporation reported a data security incident to the New Hampshire Attorney General on June 8, 2023. An unknown third party accessed PharMerica's computer systems from March 12-13, 2023. The breach affected 17,451 New Hampshire residents, whose personal information was potentially obtained. PharMerica engaged cybersecurity experts, notified law enforcement, and offered complimentary credit monitoring and identity protection services to affected individuals.
- 🦬Montana State AGvia PharMerica Corporation2023-06-08
PharMerica Corporation reported a data breach to the Montana Attorney General. The breach was reported on 2023-06-08. The breach occurred from 3/12/2023 to 3/13/2023. 10,567 Montana residents were affected.
- 🦫Oregon State AGvia PharMerica Corporation2023-05-12
PharMerica Corporation reported a data breach to the Oregon Attorney General. The breach was reported on 2023-05-12. The breach occurred during 3/12/2023 - 3/13/2023. The breach was discovered on 3/21/2023. 5,815,591 individuals were affected. Notice was sent on 5/12/2023.
- KYHHS OCRvia PharMerica Corporation2023-05-12
PharMerica Corporation reported to HHS on 2023-05-12 a Hacking/IT Incident affecting 5,815,591 individuals. Breached information located on Network Server. The incident involved PHI including names, addresses, DOB, SSNs, claims, and medications. Response included credit monitoring and enhanced safeguards.
- GLOBALLeak Sitevia PharMerica Corporation2023-04-08
Headquartered in Louisville, Kentucky, PharMerica is one of the largest and fastest-growing institutional pharmacy companies in the United States. Our premier pharmacy services, with more than 180 long-term care pharmacies in almost every state, have a national scope but a local approach.Revenue: $3BBrightSpring Health Services is the leading provider of complementary home- and community-based health services for complex populations in need of specialized and/or chronic care. We focus on providing quality outcomes, through best-in-class service and technology capabilities.Revenue: $5.4B