Skip to content

Brightline

Disclosed Apr 7, 20233 years ago199,753 affectedConfirmed

Official notice

The business associate (BA), Brightline, reported that its third-party provider was the victim of a cyber-attack affecting the protected health information (PHI) of 8,432 individuals. The PHI involved included names, dates of birth, addresses, member and group identification numbers, and gender identification. The BA notified HHS, affected individuals, the media, and provided substitute notice. In response to the breach, the BA provided complimentary credit monitoring services and implemented additional security and technical safeguards. OCR provided the BA with technical assistance regarding the HIPAA Privacy, Security, and Breach Notification Rules.

What is known

People affected199,753 (as reported to HHS)
DisclosedApr 7, 2023
DiscoveredFeb 4, 2023
HappenedJan 30, 2023
AttackHacking
Data exposedNames, Health
SectorHealthcare · US
StatusConfirmed

Sources

Source
California Attorney General breach notice: Brightlineoag.ca.gov · Official notice
Washington Attorney General breach notice: Brightlineatg.wa.gov · Official notice
Notice letter filed with the Delaware DOJ: Brightlineattorneygeneral.delaware.gov · Official notice
Oregon DOJ breach notice: Brightlinejustice.oregon.gov · Official notice
Vermont Attorney General: 2023-04-19 Brightline Data Breach Notice to Consumersago.vermont.gov · Official notice
Indiana Attorney General 2023 data breach report: Brightlinein.gov · Official notice
HHS OCR breach report (archive, resolved): Brightline (Business Associate, CA)ocrportal.hhs.gov · Official notice

Notices filed

WhereFiledPeople
Delaware DOJresidents of DEApr 7, 202319
Indiana AGresidents of INApr 7, 20232,373
HHS archivetotalApr 7, 2023199,753
Washington AGresidents of WAApr 10, 202326,333
California AGresidents of CAApr 12, 2023
HHS archivetotalApr 13, 202349,968
Vermont AGresidents of VTApr 19, 2023
HHS archivetotalApr 20, 2023180,694
California AGresidents of CAApr 21, 2023
Oregon DOJresidents of ORMay 2, 2023
California AGresidents of CAMay 10, 2023
HHS archivetotalMay 10, 202328,975
California AGresidents of CAMay 12, 2023
California AGresidents of CAMay 17, 2023
HHS archivetotalMay 26, 20238,432
History of this record
  • 2026-09-25 · records: 180694 to 199753 · backfill source
  • 2026-09-25 · records_basis: organization to hhs · backfill source
  • 2026-09-25 · records: 35492 to 180694 · backfill source
  • 2026-09-25 · data_types: ["names"] to ["names","health"] · backfill source
  • 2026-09-25 · summary: empty to The business associate (BA), Brightline, reported that its third-party provider was the victim of a cyber-attack affecting the protected health information (PHI) of 8,432 individuals. The PHI involved included names, dates of birth, address · backfill source
  • 2026-09-25 · records_basis: empty to organization · backfill source
  • 2026-09-25 · records: empty to 35492 · backfill source
  • 2026-09-25 · source: empty to https://ago.vermont.gov/document/2023-04-19-brightline-data-breach-notice-consumers · backfill source
  • 2026-09-25 · data_types: [] to ["names"] · backfill source
  • 2026-09-25 · disclosed: 2023-04-10 to 2023-04-07 · backfill source
  • 2026-09-25 · sector: other to health · backfill source
  • 2026-09-25 · attack: unknown to hacking · backfill source
  • 2026-09-25 · disclosed: 2023-04-12 to 2023-04-10 · backfill source
  • 2026-09-25 · discovered: empty to 2023-02-04 · backfill source
  • 2026-09-25 · disclosed: 2023-04-21 to 2023-04-12 · backfill source
  • 2026-09-25 · disclosed: 2023-05-10 to 2023-04-21 · backfill source
  • 2026-09-25 · disclosed: 2023-05-12 to 2023-05-10 · backfill source
  • 2026-09-25 · disclosed: 2023-05-17 to 2023-05-12 · backfill source
  • 2026-09-25 · added · backfill source

First seen 2026-09-25 (California AG), confirmed by California AG. Record counts are as reported. Not legal advice.

Everything about Brightline

New breaches by email

Wednesdays, only in weeks with newly disclosed breaches, the largest first.

Double opt-in. Unsubscribe any time.