Brightside Health
Disclosed Apr 30, 20233 years ago767 affectedConfirmed
The covered entity (CE), Brightside Health, reported that an unauthorized individual accessed the protected health information (PHI) of 767 individuals. The PHI involved included names, Social Security numbers, addresses, and diagnoses. The CE notified HHS and affected individuals. In response to the breach, the CE sanctioned the responsible employee and implemented additional administrative and technical safeguards and retrained its staff. OCR provided technical assistance regarding the HIPAA Security Rule.
What is known
| People affected | 767 (as reported to HHS) |
|---|---|
| Disclosed | Apr 30, 2023 |
| Attack | Insider |
| Data exposed | Names, Health |
| Sector | Healthcare · US |
| Status | Confirmed |
Sources
| Source | |
|---|---|
| HHS OCR breach report (archive, resolved): Brightside Health (Healthcare Provider, CA)ocrportal.hhs.gov · Official notice | Official notice |
Notices filed
| Where | Filed | People |
|---|---|---|
| HHS archivetotal | Apr 30, 2023 | 767 |
History of this record
- 2026-09-25 · added · backfill source
First seen 2026-09-25 (HHS archive), confirmed by HHS OCR. Record counts are as reported. Not legal advice.