The Insightin Health 2025 data breach involved unauthorized access to the network of a Baltimore digital-health platform provider serving health insurers and payers from September 17 through September 23, 2025. Insightin identified suspicious network activity in September. A forensic investigation confirmed the access window and found protected health information associated with clients in the exposed files.
The current breach list maintained by the US Department of Health and Human Services Office for Civil Rights shows 1,949,534 affected individuals. pwnCount and totalRecords use this value from the single federal report. The scope includes names, birth dates, contract numbers, health-insurer identifiers, Medicare beneficiary identifiers, and attributed-provider information; LeakData imports no records.
How Was the Breach Confirmed?
Insightin Health described suspicious network activity and its third-party investigation in a substitute notice. The forensic review confirmed unauthorized access between September 17 and September 23, 2025. File review showed that protected health information associated with its clients was present in affected files, making the event a genuine regulated health-data breach.
The HHS OCR entry classifies Insightin Health as a Business Associate, the event as a Hacking/IT Incident, and the information location as Network Server. HIPAA Journal reviewed the organization notice and incident context, corroborating the access range, data types, and protection offer. Sources specifically state that Social Security numbers were not compromised.
What Was the Access and Notification Timeline?
Verified network access began on September 17, 2025 and ended on September 23. breachDate is September 17, the beginning of the access window. Insightin detected unusual activity in September and opened a forensic review to determine the nature, scope, and affected files.
The HHS row carries a January 16, 2026 submission date and now shows 1,949,534 people. Public sources do not disclose when every client was notified or provide health-plan-level subtotals. LeakData uses the federal total for the single event and does not add different record volumes appearing in older coverage or on an attacker page.
What Identity and Insurance Information Was Affected?
Files could contain names and dates of birth. Contract numbers and non-unique identifiers used by health-insurance providers were also in the disclosed scope. These fields can support phishing and insurance-account fraud, but a non-unique provider identifier is not itself a personal account password.
Medicare beneficiary identifiers were present in some files. Insightin also disclosed information associated with healthcare providers attributed to individuals. This combination can help attackers craft persuasive fake Medicare communications or messages based on a known provider relationship.
What Data Types Were Kept Out of Scope?
Insightin Health expressly said Social Security numbers were not compromised. Sources also do not list payment cards, bank accounts, account passwords, diagnoses, detailed treatment notes, or prescription information among the confirmed general fields. Those categories are not added to LeakData merely because they might exist somewhere in a health platform.
The data combination may vary by person and Insightin client; the record does not imply that every field appeared for all 1,949,534 people. The phrase “protected health information” is not used to infer undisclosed clinical details. This entry is limited to published name, birth-date, contract, insurance, Medicare, and provider information.
How Is Medusa's 378 GB Claim Treated?
The Medusa ransomware group claimed responsibility, asserting that it exfiltrated 378 GB from Insightin's network and threatening to publish the data. Those details did not appear in the organization's substitute notice. Public sources do not show that Insightin confirmed Medusa's name, the file volume, a ransom demand, or the entire claimed content.
LeakData separates the group assertion as context; it does not convert 378 GB into pwnCount or treat every technical claim as verified. The reliable core is company-confirmed network access and file scope plus the HHS population of 1,949,534. The attacker assertion is not used to broaden data classes.
What Should Affected People Do?
Insightin Health offered affected people twelve months of complimentary credit monitoring and identity-theft protection. Although Social Security numbers were outside the scope, notice recipients should monitor credit reports, carefully verify messages claiming to represent a health plan or Medicare, and refuse information requests in unexpected calls seeking a beneficiary identifier.
An unfamiliar provider, service, or claim in Medicare and health-insurance statements should be reported through the plan's official fraud channel. Contact details should be obtained independently from a card or official website instead of following a message link. importedRecordCount is zero; LeakData does not store or publish names, birth dates, contracts, insurance, Medicare, or provider data.