BrightSpring Health Services
ent_da6facc3b21060d37678640f
Disclosures
11
State AG · 10 jurisdictions
Multi-filing incidents
1
incidents joining 2+ filings here
Max affected reported
535,203
nationwide · State AG ME
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- BrightSpring Health Services
- Normalized
- brightspring health— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- No match
- SEC EDGAR CIK
- 0001865782
- Domain
- None on record
Disclosure history (11)newest first
- New Hampshire State AGas victim2023-08-11
BrightSpring Health Services notified affected individuals of a cybersecurity incident where an unknown third party accessed systems from March 12-13, 2023. The company discovered suspicious activity on March 14, 2023. Employee personal information was compromised. The company engaged cybersecurity advisors and offered one year of identity monitoring through Kroll.
- Maine State AGas victim2023-08-11
BrightSpring Healthcare Services, Inc. reported an external system breach (hacking) occurring March 12-13, 2023, discovered May 20, 2023. The incident affected 535,203 individuals, including 547 Maine residents. Acquired data included names and Social Security Numbers. BrightSpring provided 12 months of credit monitoring services through Kroll.
- Washington State AGas victim2023-08-11
BrightSpring Health Services, Inc. disclosed a ransomware incident affecting employee data, including names, SSNs, addresses, and DOBs. Unauthorized access occurred March 12-13, 2023; discovered March 14, 2023. 28,194 Washington residents affected. Remediation included enhanced security measures and 1-year Kroll identity monitoring.
- Massachusetts State AGas victim2023-08-11
BrightSpring Health Services, Inc. reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2023-08-11. 2,382 Massachusetts residents were affected. The report records the breach type as electronic.
- Vermont State AGas victim2023-08-11
BrightSpring Health Services notified consumers of a cybersecurity incident where an unknown third party accessed systems from March 12-13, 2023. The breach exposed names, Social Security numbers, addresses, and dates of birth. No financial or health information was compromised. The company engaged cybersecurity advisors, enhanced security measures, and offered one year of Kroll identity monitoring.
- California State AGas victim2023-08-11
BrightSpring Health Services, Inc. reported that an unknown third party accessed its computer systems from March 12-13, 2023. The company discovered suspicious activity on March 14, 2023. The incident involved employee personal information, including names, Social Security numbers, and for some, addresses and dates of birth. Financial and health information were not involved. The company engaged cybersecurity advisors, enhanced technical security measures, and offered one year of identity monitoring through Kroll.
- Oregon State AGas victim2023-08-11
BrightSpring Health Services reported a data breach to the Oregon Attorney General. The breach was reported on 2023-08-11. The breach occurred during 3/12/2023 - 3/13/2023. The breach was discovered on 5/20/2023. 535,203 individuals were affected. Notice was sent on 6/21/20238/11/2023.
- Montana State AGas victim2023-08-10
BrightSpring Health Services notified individuals of a cybersecurity incident where an unknown third party accessed systems from March 12-13, 2023. Suspicious activity was detected on March 14, 2023. The incident involved employee personal information, including names, Social Security numbers, addresses, and dates of birth. No financial or health information was compromised. The company engaged cybersecurity advisors and is offering one year of identity monitoring.
- Massachusetts State AGas victim2023-06-21
BrightSpring Health Services, Inc. reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2023-06-21. 22 Massachusetts residents were affected. The report records the breach type as electronic.
- Indiana State AGas victim2023-06-21
BrightSpring Health Services, Inc reported a data breach to the Indiana Attorney General. The breach occurred on 2023-03-12 and was reported on 2023-06-21. 37,646 Indiana residents were affected. 535,203 individuals affected in total.
- Illinois State AGas victim2023-01-01
AMERITA/PHARMERICA CORP./BRIGHTSPRING HEALTH SERVICES filed a data-breach notice with the Illinois Attorney General during 2023 (case 23-615). The register records the breach as discovered on March 14, 2023. Illinois does not publish the number of people affected — 815 ILCS 530/10 permits the Attorney General to publish only the entity name, the types of personal information and the date range.
Subsidiary disclosures (newest 10)filed by group companies
◈ These filings were made by or about subsidiaries of BrightSpring Health Services — not by BrightSpring Health Services itself. Corporate relationships are mapped from GLEIF relationship records and SEC Exhibit 21 filings.
- California State AGvia PharMerica Corporation2023-06-19
PharMerica Corporation reported that an unknown third party accessed its computer systems from March 12-13, 2023. The company discovered suspicious activity on March 14, 2023. Affected data included names, addresses, dates of birth, Social Security numbers, medications, and health insurance information. PharMerica engaged cybersecurity advisors and is offering one year of identity monitoring through Kroll.
- South Carolina State AGvia PharMerica Corporation2023-06-09
PharMerica Corporation notified South Carolina residents of a cybersecurity incident where an unknown third party accessed systems from March 12-13, 2023. Discovered March 14, 2023, the breach exposed names, addresses, DOBs, SSNs, and health/insurance data. PharMerica engaged forensic advisors, enhanced security, and offered one year of Kroll identity monitoring.
- Maine State AGvia PharMerica Corporation2023-06-09
PharMerica Corporation reported an external system breach (hacking) occurring March 12-13, 2023, discovered on March 21, 2023. The incident affected 5,815,591 individuals, including 40,248 in Maine. Personal information acquired included names and Social Security Numbers. PharMerica provided written notification and offered one year of credit and identity monitoring services through Kroll.
- Massachusetts State AGvia PharMerica Corporation2023-06-08
PharMerica Corporation reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2023-06-08. 384,938 Massachusetts residents were affected. The report records the breach type as electronic.
- Delaware State AGvia PharMerica Corporation2023-06-08
PharMerica notified affected individuals in Delaware and other states of a cybersecurity incident occurring March 12-13, 2023, discovered on March 14, 2023. An unknown third party accessed systems, obtaining names, addresses, DOBs, SSNs, medications, and health insurance info. PharMerica engaged cybersecurity advisors, enhanced technical security, and offered one year of Kroll identity monitoring.
- New Hampshire State AGvia PharMerica Corporation2023-06-08
PharMerica Corporation reported a data security incident to the New Hampshire Attorney General on June 8, 2023. An unknown third party accessed PharMerica's computer systems from March 12-13, 2023. The breach affected 17,451 New Hampshire residents, whose personal information was potentially obtained. PharMerica engaged cybersecurity experts, notified law enforcement, and offered complimentary credit monitoring and identity protection services to affected individuals.
- Montana State AGvia PharMerica Corporation2023-06-08
PharMerica Corporation notified affected individuals in Montana and other states of a cybersecurity incident. Unauthorized access occurred March 12-13, 2023. Data accessed included names, addresses, DOBs, SSNs, medications, and health insurance info. PharMerica engaged cybersecurity advisors, enhanced security measures, and offered one year of Kroll identity monitoring.
- Oregon State AGvia PharMerica Corporation2023-05-12
PharMerica Corporation reported a data breach to the Oregon Attorney General. The breach was reported on 2023-05-12. The breach occurred during 3/12/2023 - 3/13/2023. The breach was discovered on 3/21/2023. 5,815,591 individuals were affected. Notice was sent on 5/12/2023.
- KENTUCKYHHS OCRvia PharMerica Corporation2023-05-12
PharMerica Corporation reported to HHS on 2023-05-12 a Hacking/IT Incident affecting 5,815,591 individuals. Breached information located on Network Server. The incident involved PHI including names, addresses, DOB, SSNs, claims, and medications. Response included credit monitoring and enhanced safeguards.
- GLOBALLeak Sitevia PharMerica Corporation2023-04-08
Headquartered in Louisville, Kentucky, PharMerica is one of the largest and fastest-growing institutional pharmacy companies in the United States. Our premier pharmacy services, with more than 180 long-term care pharmacies in almost every state, have a national scope but a local approach.Revenue: $3BBrightSpring Health Services is the leading provider of complementary home- and community-based health services for complex populations in need of specialized and/or chronic care. We focus on providing quality outcomes, through best-in-class service and technology capabilities.Revenue: $5.4B