Confirmed breach. Intrusion Jan 30, 2023, discovered Feb 4, 2023 — the first regulatory filing landed 62 days later (flagged late). 716,500 individuals reported across the linked filings.
Regulatory clocksMaine✗ ME AG >90d · 93dVermont✗ VT AG >45 bdayOregon✗ OR AG >45dCalifornia✗ CA 60-day late · 62dWashington⏱ WA AG >30dHIPAA✓ HHS notifiedFull clock table in Litigation Timeline
HHS OCRState AGConfirmedLifecycle stage 2 of 3: ConfirmedUnverified claimConfirmedEnforcedmoderate sensitivity
Affected (total reported)
49days
Time between earliest and latest filing
Not recorded for this incident
Leak precedence · Materiality delta · SEC filing delay — no leak-site claim in this cluster; no SEC 8-K in this cluster.
716,500
Data types
3
PHI · Health (basic) · Identity (basic)
Jurisdictions
9
CA DE FEDERAL ME MT NH OR VT
Linked filings
24
HHS OCR · State AG
Affected residents by state
per-filing reported counts
ME27,742
WA26,333
MT403
NH180
ME9
State AGs report only their own residents; bars show per-filing counts.
Timeline
Earliest sighting first · deep chronology in Litigation Timeline
24 filings across 9 jurisdictions · Apr 7, 2023 – May 26, 2023 · 3 milestones
Breach window
Jan 30, 2023
When the intrusion reportedly occurred, per the linked filings
Breach discoveredletter-grounded
Feb 4, 2023
Reported by VERMONT AG, WASHINGTON AG, NEW HAMPSHIRE AG, CALIFORNIA AG, OREGON AG filings
Breach discoveredconflicts with Feb 4, 2023
Feb 6, 2023
Reported by MAINE AG, HHS OCR filings
60 days
🐻CALIFORNIAHHS OCRFirst filinglinked via same-victim cross-source · 100%
Brightline, Inc. reported to HHS on 2023-04-07 a Hacking/IT Incident affecting 199,753 individuals. Breached information located on Network Server. The business associate's third-party provider was the victim of a cyber-attack. PHI involved included names, dates of birth, addresses, member/group IDs, and gender. The BA provided complimentary credit monitoring and implemented additional security safeguards.
3 State AG filingsApr 7, 2023ExpandCollapse
MEMTDE
🦞Maine State AGlinked via same-victim cross-source · 100%
🐻CALIFORNIAHHS OCRlinked via same-victim cross-source · 100%
Brightline, Inc. reported to HHS on 2023-04-07 a Hacking/IT Incident affecting 473,467 individuals. Breached information located on Network Server. The business associate's third-party provider was the victim of a cyber-attack. PHI included names, DOB, addresses, and member IDs. Brightline provided credit monitoring and implemented safeguards.
Affected (this filing): 473,467
🐻CALIFORNIAHHS OCRlinked via same-victim cross-source · 100%
Brightline, Inc. reported to HHS on 2023-04-07 a Hacking/IT Incident affecting 21,830 individuals. Breached information located on Network Server. The business associate's third-party provider was the victim of a cyber-attack. PHI included names, dates of birth, addresses, member/group IDs, and gender. Response included credit monitoring and security safeguards.
Affected (this filing): 21,830
💎Delaware State AGlinked via same-victim cross-source · 100%
Brightline, Inc. filed a Notice of Data Breach with the Delaware Attorney General in April 2023. The incident involved unauthorized access to a third-party vendor's database, resulting in the exfiltration of customer PII, including names and government-issued ID numbers. Brightline engaged forensic investigators and enhanced security measures.
3 HHS OCR filingsApr 7, 2023ExpandCollapse
CA
🐻CALIFORNIAHHS OCRlinked via same-victim cross-source · 95%
5 State AG filingsApr 7, 2023 – Apr 19, 2023ExpandCollapse
VTWACANH
🍁Vermont State AGlinked via same-victim cross-source · 95%
🇺🇸FEDERALHHS OCRlinked via same-victim cross-source · 100%
Brightline, Inc. (a Business Associate, CA) reported to HHS on 2023-04-20 a Hacking/IT Incident affecting 180,694 individuals. Breached information was located on a Network Server. Brightline's third-party provider was the victim of a cyber-attack exposing PHI including names, dates of birth, addresses, member and group ID numbers, and gender identification. The BA notified HHS, affected individuals, and the media, provided substitute notice, offered credit monitoring, and implemented additional security safeguards. OCR provided technical assistance on HIPAA rules.
Affected (this filing): 180,694
3 State AG filingsApr 21, 2023 – May 10, 2023ExpandCollapse
CAOR
🐻California State AGlinked via same-victim cross-source · 95%
🐻CALIFORNIAHHS OCRlinked via same-victim cross-source · 100%
Brightline, Inc. reported to HHS on 2023-05-10 a Hacking/IT Incident affecting 28,975 individuals. Breached information located on Network Server. The business associate's third-party provider was the victim of a cyber-attack. PHI involved included names, dates of birth, addresses, member/group IDs, and gender. Brightline provided credit monitoring and implemented safeguards.
Affected (this filing): 28,975
3 State AG filingsMay 10, 2023 – May 17, 2023ExpandCollapse
MECA
🦞Maine State AGlinked via same-victim cross-source · 95%
🐻CALIFORNIAHHS OCRMost recentlinked via same-victim cross-source · 100%
Brightline, Inc. reported to HHS on 2023-05-26 a Hacking/IT Incident affecting 8432 individuals. Breached information located on Network Server. The business associate's third-party provider was the victim of a cyber-attack. PHI involved included names, dates of birth, addresses, member/group IDs, and gender. Brightline provided credit monitoring and implemented additional safeguards.
Affected (this filing): 8,432
About this clustering
DisclosureLens links filings into incidents through layered matchers: deterministic rules (same source document, multistate filings of one breach, tight-window same-victim pairs), a weighted-similarity scorer for cross-source candidates, and an operator review queue for everything uncertain. Each link records its own method and confidence — shown per filing in the timeline below. The system defaults to NOT merging when uncertain, because a false merge (collapsing two unrelated breaches) is more harmful than a false split (showing related filings separately); uncertain pairs route to human review instead of auto-merging. Filing summaries shown in the timeline are AI-generated extracts — verify each against its linked source.
Brightline, Inc. reported a cybersecurity incident involving its vendor, Fortra, occurring on January 30, 2023. The breach affected 27,742 individuals, including 58 Maine residents. The incident involved the unauthorized acquisition of names and Social Security Numbers. Brightline notified affected individuals on April 7, 2023, and offered two years of complimentary credit monitoring services.
Affected (this filing): 27,742
ME AG >30d · 60d
🦬Montana State AGlinked via same-victim cross-source · 95%
Brightline, Inc reported a data breach to the Montana Attorney General. The breach was reported on 2023-04-07. The breach occurred on 1/30/2023. 403 Montana residents were affected.
Affected (this filing): 403
💎Delaware State AGlinked via same-victim cross-source · 95%
Brightline, Inc. filed a data breach notice with the Delaware Attorney General regarding an incident involving Forta, a third-party provider of GoAnywhere MFT SaaS. The source document provided was a PDF placeholder with no extractable text content, resulting in null values for counts, dates, and specific data types affected.
Brightline, Inc. (a Business Associate) reported to HHS on 2023-04-07 a Hacking/IT Incident affecting 7,672 individuals. The breach originated from a cyber-attack on Brightline's vendor. PHI involved included names, dates of birth, and addresses, located on a Network Server. Brightline notified HHS, affected individuals, and the media, provided credit monitoring, and implemented additional safeguards. OCR provided technical assistance regarding HIPAA Privacy Rules.
Affected (this filing): 7,672
HHS notified
🐻CALIFORNIAHHS OCRlinked via same-victim cross-source · 100%
Brightline, Inc. reported to HHS on 2023-04-07 a Hacking/IT Incident affecting 31440 individuals. Breached information located on Network Server. The business associate's third-party provider was the victim of a cyber-attack affecting PHI including names, DOB, addresses, and member IDs. Brightline provided credit monitoring and implemented safeguards.
Affected (this filing): 31,440
HHS notified
🐻CALIFORNIAHHS OCRlinked via same-victim cross-source · 100%
Brightline, Inc. reported to HHS on 2023-04-07 a Hacking/IT Incident affecting 4044 individuals. Breached information located on Network Server. The business associate's third-party provider was the victim of a cyber-attack. PHI involved included names, dates of birth, addresses, member/group IDs, and gender. The BA provided credit monitoring and implemented safeguards.
Brightline, Inc. notified consumers of a data breach involving its third-party file transfer provider, Fortra. An unauthorized party exploited a previously unknown vulnerability in Fortra's GoAnywhere MFT service on Jan 30, 2023, to access files containing demographic PII (name, address, DOB, member ID) of Brightline plan enrollees. No SSNs or financial data were compromised. Brightline engaged cyber counsel and offered 2 years of credit monitoring via Cyberscout.
VT AG >14 bday
🌲Washington State AGlinked via same-victim cross-source · 100%
Brightline, Inc., a health sector entity reported a other incident to the Washington Attorney General. The organization became aware of the incident on 2023-02-04 and filed notice on 2023-04-10. 26,333 Washington residents were affected. 65 days elapsed between awareness and notification. 5 days to identify the breach. 0 days to contain the breach.
Affected (this filing): 26,333
WA AG >30d
🐻California State AGlinked via same-victim cross-source · 95%
Brightline, Inc., a virtual behavioral health provider, notified affected individuals of a data security incident involving Fortra's GoAnywhere MFT SaaS, a third-party file transfer service. On January 30, 2023, Fortra discovered suspicious activity; an unauthorized party exploited a previously-unknown vulnerability to access customer accounts and download files. Brightline learned of the incident on February 4, 2023. Exposed data included names, addresses, member IDs, dates of birth, phone numbers, employer names, group IDs, coverage dates, and for some, Social Security numbers. Brightline responded by rebuilding infrastructure, restricting access, and offering 2 years of credit monitoring via Cyberscout.
⛰️New Hampshire State AGlinked via same-victim cross-source · 100%
Brightline, Inc. notified the NH AG of a data breach involving its third-party vendor Fortra's GoAnywhere MFT SaaS. An unauthorized party exploited a previously unknown vulnerability to access accounts and download files starting Jan 30, 2023. Brightline learned of the incident on Feb 4, 2023. Approximately 180 NH residents were affected, with data including names, addresses, DOBs, member IDs, and some SSNs. Brightline engaged its incident response plan, retained counsel, and offered 2 years of credit monitoring.
Affected (this filing): 180
🍁Vermont State AGlinked via same-victim cross-source · 95%
Brightline, Inc. notified consumers of a data breach involving its third-party file transfer provider, Fortra (GoAnywhere MFT SaaS). The incident, occurring around Jan 30, 2023, exploited a vulnerability to access accounts. Affected data included names, DOB, SSN, and employment info. Brightline disabled access, removed data, and offered 2 years of credit monitoring.
Brightline, Inc. notified the California AG of a data breach involving a third-party vendor, Fortra (GoAnywhere MFT). An unauthorized party exploited a previously unknown vulnerability in Fortra's SaaS to access and download files containing personal information of Stanford group health plan members. Affected data includes names, addresses, DOBs, phone numbers, member IDs, employer names, and coverage dates. Brightline deactivated credentials, rebuilt infrastructure, and removed data from the affected service. Identity theft protection services were offered.
🦫Oregon State AGlinked via same-victim cross-source · 95%
Brightline, Inc reported a data breach to the Oregon Attorney General. The breach was reported on 2023-05-02. The breach occurred during 1/30/2023. The breach was discovered on 2/4/2023. Notice was sent on 4/7/2023.
OR AG >45d
🐻California State AGlinked via same-victim cross-source · 95%
Brightline, Inc. notified the California AG of a data breach involving its third-party provider Fortra (GoAnywhere MFT SaaS). An unauthorized party exploited a previously unknown vulnerability on Jan 30, 2023, to access accounts and download files. Brightline became aware on Feb 4, 2023. Affected data includes names, DOB, SSN, and employment info for HP employees. No clinical data or financial accounts were involved. Brightline rebuilt infrastructure, removed data from the service, and offered 2 years of credit monitoring.
Brightline, Inc., a healthcare organization, reported a data breach affecting 9 Maine residents. The breach, which occurred on January 30, 2023, and was discovered on February 6, 2023, was attributed to a vendor incident. The compromised information includes names and Social Security numbers. In response, Brightline is offering 24 months of complimentary credit monitoring services through TransUnion.
Affected (this filing): 9
ME AG >90d · 93d
🐻California State AGlinked via same-victim cross-source · 95%
Brightline, Inc., a virtual healthcare services provider, disclosed a data security incident involving its vendor, Fortra (formerly HelpSystems). On January 30, 2023, Fortra identified unauthorized access to its GoAnywhere file transfer software. Brightline learned of the incident on February 4, 2023, and immediately engaged its incident response plan, terminating unauthorized access. The incident involved the acquisition of files containing eligibility information, including name, member ID, group ID, gender, and date of birth. Brightline is offering 24 months of complimentary identity theft restoration and credit monitoring services through Cyberscout.
🐻California State AGlinked via same-victim cross-source · 95%
Brightline, Inc., a virtual behavioral health provider, notified the California AG of a data breach affecting subscriber eligibility information. The incident stemmed from a third-party vendor, Fortra, whose GoAnywhere MFT service was compromised via a previously unknown vulnerability on January 30, 2023. Brightline became aware of the incident on February 4, 2023. Affected data included names, addresses, member IDs, dates of birth, phone numbers, and employer information. No SSNs, financial accounts, or medical records were involved. Brightline removed data from the service, implemented additional security measures, and offered 2 years of credit monitoring.