LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

Recent Breaches › Insightin Health, Inc. Data Breach Notice (Oregon Attorney General)

HIGH severityConfirmedHow we verify

Insightin Health, Inc. Data Breach Notice (Oregon Attorney General): What Was Exposed & What To Do

RBRecent Breaches Breach Intelligence·March 5, 2026
Insightin Health, Inc. Data Breach Notice (Oregon Attorney General)

Occurred September 17, 2025 · publicly disclosed March 5, 2026. Approximately 1144686 people affected.

HIGH
Severity
1144686
People affected
1
Data types exposed
March 5, 2026
Disclosed
ShareXLinkedInFacebookRedditWhatsAppTelegram

Insightin Health, Inc. reported a data breach on March 5, 2026, that exposed the personal information of 1,144,686 individuals and was noticed by the Oregon Attorney General. Anyone who received services or provided information to the organization should review the notice and take steps to protect their data.

Severity & verification
HIGH severityConfirmed
Data types not itemised.
Corroborated by an official disclosure or a verified breach feed.
Check your exposure
1144686 accounts were exposed here. We can’t confirm any single incident against the sources we search — but we can show you every leak and listing tied to your email. 15-sec check, no card.

By running your scan you agree to the Terms and Conditions and the Privacy Policy, and to GalaxyWarden emailing you the results of this scan.

Insightin Health, Inc. notified Oregon residents of a data breach in a filing reported to the Oregon Department of Justice on March 5, 2026. According to that notice, the incident itself is dated September 17, 2025, and the filing indicates that 1,144,686 people were affected. The notification describes the exposed material as personal information; further technical detail about how the incident occurred has not been laid out in the public summary associated with this record.

For people who may have a relationship with Insightin Health or whose data may have been handled in connection with its work, the scale of the notice and the category of data named make the disclosure worth understanding in plain terms. Public detail beyond the filing’s core points remains limited.

Inside the incident

What is established from the Oregon Attorney General–related breach notice is straightforward. Insightin Health, Inc. is the organization named. The incident date given in the filing is September 17, 2025. The report to the Oregon Department of Justice is dated March 5, 2026. The number of people affected is stated as 1,144,686. The data types named as exposed are described as personal information, per the breach notification.

The public summary does not describe the attack method, whether systems were encrypted or data were copied, how long unauthorized access lasted, or which systems were involved. It also does not attribute the activity to a named threat group. Those elements are undisclosed in the facts available here. The gap between the stated incident date and the Oregon filing date is part of the record as reported; reasons for the timing of notice are not detailed in the summary provided.

How a breach like this happens

In general terms, incidents that lead to notices about personal information often begin with stolen or guessed account credentials, phishing that tricks an employee or contractor, exploitation of an unpatched remote-access or internet-facing system, or misuse of legitimate access. Once inside a network or a cloud environment, an unauthorized party may search for databases, file shares, backups, or exports that contain customer, member, or patient-related records.

Organizations that process health-related or benefits-related data frequently connect multiple systems—enrollment, claims support, analytics, customer service tools, and vendor platforms. A compromise in one connected environment can expose information that was collected for ordinary business purposes. None of this describes a proven path for this specific Insightin Health incident; it is background on how events of this general type typically unfold when method is not publicly detailed. No specific threat actor is named in the facts for this case, and none should be assumed.

Insightin Health, Inc. and its sector

Insightin Health, Inc. operates in the health-related technology and services space. Firms in this sector commonly support health plans, providers, or related organizations with data analytics, member engagement, population-health tools, or similar services. In that role they often receive or process information needed to identify people, coordinate outreach, or support care and benefits workflows.

A breach notice from such an organization matters because the data involved is rarely limited to a single trivial field. Even when a filing only says “personal information,” the sector context means affected individuals may include members, patients, or consumers whose records were shared with a vendor or partner for legitimate operations. Consequences can extend across state lines when a company serves clients nationally, which is why a single state filing can reference a large affected count.

The information in question

The breach notification names the exposed data as personal information. It does not itemize fields such as Social Security numbers, dates of birth, addresses, medical details, insurance identifiers, or financial account data in the facts provided here. Those specifics are unconfirmed in this record.

Organizations of this kind typically hold or process identifiers and contact details, and may hold health-coverage or service-related attributes depending on the product. That is general sector practice, not a statement of what was confirmed stolen or viewed in this incident. Readers should treat only the notification’s phrasing—“personal information”—as the named category unless a fuller official notice lists more.

What's at stake

For affected people, the practical risks center on misuse of personal information: targeted phishing that references a real company relationship, account takeover attempts if identifiers can be matched to other breaches, and, if sensitive identifiers were involved (still unconfirmed here), longer-term identity-theft or insurance-related fraud concerns. Even without a public field-by-field list, a notice covering more than a million people means many households may need to treat unsolicited messages and unexpected account activity with extra caution for an extended period.

For the organization, stakes include regulatory follow-up, notification and support costs, contractual obligations to clients, and reputational harm. Large affected counts often bring scrutiny from state attorneys general and, where health-related data are involved, questions under applicable privacy and security rules. Those outcomes depend on facts not fully public in this summary and are not a finding of fault.

Were you affected?

If you have been a member, customer, or otherwise linked to services involving Insightin Health, watch for an official breach notice by mail or other channels the company uses. Consider placing fraud alerts or credit freezes if you later learn sensitive identifiers were included; use unique passwords and multifactor authentication on email and benefits portals; and treat unexpected calls or emails about the incident as potential scams unless you verify the source.

You can also run a free exposure scan of your email to check whether your information has surfaced in known breach data, which may help you see if the same address appears in other incidents and prioritize password changes and monitoring accordingly.

AICompiled with AI assistance from public sources and published under our editorial standards.

Editorial & sourcing policy
Recent Breaches is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data, and we do not hold the data claimed in leak-site listings. Incidents are compiled from publicly accessible sources and threat-intelligence platforms and are reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — write to support@galaxywarden.com or press@recentbreaches.com.
Check if you’re exposed →

How this breach connects

Company

CompanyInsightin Health, Inc. security record
74/100
DoxxScan™ · Moderate doxx risk
C- 62Below-average record

1 reported incident on record.

See Insightin Health, Inc.’s full breach history →

More recent breaches

ASOS US Sales LLC Data Breach Notice (Oregon Attorney General)September 9, 2026BestCare treatment Services, Inc. Data Breach Notice (Oregon Attorney General)September 8, 2026Boston Health Care for the Homeless Program Data Breach Notice (Oregon Attorney General)September 3, 2026American Addiction Centers Data Breach Notice (Oregon Attorney General)September 3, 2026

Latest breaches

Read GalaxyWarden’s full analysis of the Insightin Health, Inc. Data Breach Notice (Oregon Attorney General) →

Source: Oregon Department of Justice breach notification

Verified breach

Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.

Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.

ShareXLinkedInFacebookRedditWhatsAppTelegram