---
title: "Insightin Health GoAnywhere data incident"
description: "Evidence-backed account of Insightin Health GoAnywhere data incident, covering what happened, impact, timeline, attack vector, technical details, and primary sources."
incident_type: "Data incident"
status: "active"
last_modified: "2026-08-09"
canonical_url: "https://www.ally.security/incidents/insightin-health-goanywhere-data-incident-2025"
markdown_url: "https://www.ally.security/incidents/insightin-health-goanywhere-data-incident-2025.md"
stix_url: "https://www.ally.security/incidents/insightin-health-goanywhere-data-incident-2025/stix.json"
---

# Insightin Health GoAnywhere data incident

Unauthorized access to files on a limited number of Insightin servers through GoAnywhere file-transfer software. Potential access to or copying of health-plan member and provider information held by Insightin for clients.

Last modified Aug 9, 2026 · 8 sources

## Summary

- **Environment:** GoAnywhere MFT
- **Operational impact:** No outage or recovery duration quantified
- **Financial impact:** No public cost estimate

## What happened

Unauthorized access to files on a limited number of [Insightin](https://insightinhealth.com/) servers through GoAnywhere file-transfer software. [1](#source-1) [3](#source-3) [5](#source-5)

## Impact

Potential access to or copying of health-plan member and provider information held by Insightin for clients. [1](#source-1) [2](#source-2) [3](#source-3)

Documented data types include:

- Gender information — Gender information is listed in the California supplemental sample population. [2](#source-2) [3](#source-3) [4](#source-4)
- Clinical information — Includes healthcare-provider information and medical information reported for some downstream populations. [2](#source-2) [3](#source-3) [4](#source-4)
- Names [2](#source-2) [3](#source-3) [4](#source-4)
- Health insurance information — May include insurance information, member IDs, health-plan information, contract numbers, or Medicare Beneficiary Identifiers depending on the individual and client population. [2](#source-2) [3](#source-3) [4](#source-4)
- Contact information — Texas report BR-0004895 lists addresses among its reported information types. [2](#source-2) [3](#source-3) [4](#source-4)
- Dates of birth [2](#source-2) [3](#source-3) [4](#source-4)
- Account credentials — Washington's directory flags email-address credentials or security-question answers for the three named February 20 downstream plan rows; this is not generalized to every affected individual. [2](#source-2) [3](#source-3) [4](#source-4)

A cited record reports 11,740 individuals (Washington residents in the Centene Corporation notification row; downstream and non-additive to national regulator totals; as of 2026-03-05). [1](#source-1)

A cited record reports 843 individuals (Washington residents in the Wellcare Health Insurance Company of Washington notification row; downstream and non-additive; as of 2026-02-20). [1](#source-1) [2](#source-2) [3](#source-3)

A cited record reports 1,777,141 individuals (Total individuals affected according to Texas report BR-0004895; regulator-reported and retained separately from the HHS OCR population; as of 2026-03-10). [1](#source-1) [2](#source-2) [3](#source-3)

A cited record reports 2,485 individuals (Washington residents in the Wellcare of Washington notification row; downstream and non-additive; as of 2026-02-20). [1](#source-1) [2](#source-2) [3](#source-3)

A cited record reports 143,346 individuals (Texas residents according to report BR-0004895; not a national total; as of 2026-03-10). [1](#source-1) [2](#source-2) [3](#source-3)

A cited record reports 29 individuals (Washington residents in the Coordinated Care of Washington notification row; downstream and non-additive; as of 2026-02-20). [1](#source-1) [2](#source-2) [3](#source-3)

A cited record reports 1,641 individuals (Approximate Rhode Island resident count in the March 4 sample notice; jurisdiction-scoped and non-additive; as of 2026-03-04). [1](#source-1) [2](#source-2) [3](#source-3)

A cited record reports 1,949,534 individuals (Individuals in the HHS OCR incident report; regulator-reported, not independently verified, and not reconciled with Texas's different total; as of 2026-08-08). [1](#source-1) [2](#source-2) [3](#source-3)

Insightin said an unauthorized party used a previously unknown design flaw in third-party GoAnywhere software to access or copy files on a limited number of Insightin servers; the reviewed sources assign no CVE. [3](#source-3)

Insightin said it had seen no evidence of identity theft or fraud connected with the incident at the time of its public notice and supplemental sample. [2](#source-2)

The initial and supplemental California sample populations state that Social Security numbers and financial information were not in the affected files; this negative statement is scoped to those notices and is not generalized beyond them. [2](#source-2)

Insightin's supplemental notice says it provided incident information to clients between December 4 and December 18, 2025 and worked with them to identify potentially affected people. [2](#source-2)

## Timeline

### September 17, 2025 — Activity began

Start of the interval during which files may have been accessed or copied. [3](#source-3) [5](#source-5)

### September 23, 2025 — Documented activity ended

End of the interval during which files may have been accessed or copied. [3](#source-3) [5](#source-5)

### September 23, 2025 — Discovery

Insightin's initial California notice says it identified unusual server activity on this date. [3](#source-3)

### January 6, 2026 — Discovery

Discovery date recorded in Texas report BR-0004895; it conflicts with Insightin's September 23 notice statement and is retained without reconciliation. [7](#source-7)

### January 14, 2026 — Public disclosure

Publication date recorded in the metadata of Insightin's public Notice of Data Event page. [4](#source-4)

### August 9, 2026 — Briefing updated

This briefing was last reviewed and updated on August 9, 2026.

## Threat Group & Attack Vector

The incident involved GoAnywhere MFT. [3](#source-3)

### Actors

- No threat actor group has been identified in the reviewed public evidence.

### TTPs

- No specific MITRE ATT\&CK technique is currently mapped for this case.

## Response

Insightin said the event did not affect its ability to serve customers. Insightin said it engaged forensic specialists, stopped further access, secured its environment, reviewed security policies, added safeguards, and reported the incident to law enforcement and regulators. The California sample notices offered twelve months of Cyberscout single-bureau credit monitoring, credit-report and credit-score services, and proactive fraud assistance. The evidence ledger retains 1 disputed claim with the original citations rather than silently resolving the conflict. No access path, attribution, scale, or recovery detail is inferred beyond the cited claims. [2](#source-2) [3](#source-3) [4](#source-4)

## Assets

[Download the case-scoped STIX 2.1 bundle](<https://www.ally.security/incidents/insightin-health-goanywhere-data-incident-2025/stix.json>)

## Sources

Primary source records used to research this incident.

<a id="source-1"></a>

### Data Breach Notifications Directory — 2026 entries

regulatory · Washington State Office of the Attorney General

<https://www.atg.wa.gov/data-breach-notifications?page=1>

<a id="source-2"></a>

### Insightin Health notice of data breach — California supplemental sample

official · Insightin Health, Inc.

<https://oag.ca.gov/system/files/InsightinHealth%2C%20Inc.%20-%20Notice%20of%20Data%20Event%20-%20Supplemental%20-%20CA_0.pdf>

<a id="source-3"></a>

### Insightin Health notice of data breach — March 4 California sample

official · Insightin Health, Inc.

<https://oag.ca.gov/system/files/Insightin%20Health%2C%20Inc.%20-%20Sample%20Notice.pdf>

<a id="source-4"></a>

### Notice of Data Event

official · Insightin Health, Inc.

<https://insightinhealth.com/notice-of-data-event/>

<a id="source-5"></a>

### Submitted breach notification sample — Insightin Health initial notice

regulatory · California Department of Justice, Office of the Attorney General

<https://oag.ca.gov/ecrime/databreach/reports/sb24-619662>

<a id="source-6"></a>

### Submitted breach notification sample — Insightin Health supplemental notice

regulatory · California Department of Justice, Office of the Attorney General

<https://oag.ca.gov/ecrime/databreach/reports/sb24-621162>

<a id="source-7"></a>

### Data Security Breach Reports — 2026 public records

regulatory · Office of the Attorney General of Texas

<https://www.texasattorneygeneral.gov/consumer-protection/data-breach-reporting>

<a id="source-8"></a>

### Breach Portal current investigation table

regulatory · U.S. Department of Health and Human Services Office for Civil Rights

<https://ocrportal.hhs.gov/ocr/breach/breach_report_hip.jsf>

<details>
<summary>Evidence ledger</summary>

Review the supporting structured claims.

1. **Resulted In · 100% confidence · current**  
   September 2025 Insightin GoAnywhere incident: Insightin said an unauthorized party used a previously unknown design flaw in third-party GoAnywhere software to access or copy files on a limited number of Insightin servers; the reviewed sources assign no CVE.
2. **Affected Individual Count · 100% confidence · current**  
   Insightin healthcare-client data exposure: 11,740 individual
3. **Began At · 100% confidence · current**  
   September 2025 Insightin GoAnywhere incident: 2025-09-17
4. **Affected Organization · 100% confidence · current**  
   September 2025 Insightin GoAnywhere incident: Wellcare Health Insurance Company of Washington, Inc.
5. **Affected Organization · 100% confidence · current**  
   September 2025 Insightin GoAnywhere incident: Centene Corporation
6. **Exposed Data Category · 100% confidence · current**  
   Insightin healthcare-client data exposure: Gender information
7. **Exposed Data Category · 100% confidence · current**  
   Insightin healthcare-client data exposure: Clinical information
8. **Resulted In · 100% confidence · current**  
   Insightin client, public, regulator, and individual notifications: Insightin said it had seen no evidence of identity theft or fraud connected with the incident at the time of its public notice and supplemental sample.
9. **Affected Organization · 100% confidence · current**  
   September 2025 Insightin GoAnywhere incident: Insightin Health, Inc.
10. **Resulted In · 100% confidence · current**  
   Insightin healthcare-client data exposure: The initial and supplemental California sample populations state that Social Security numbers and financial information were not in the affected files; this negative statement is scoped to those notices and is not generalized beyond them.
11. **Affected Individual Count · 100% confidence · current**  
   Insightin healthcare-client data exposure: 843 individual
12. **Affected Individual Count · 100% confidence · current**  
   Insightin healthcare-client data exposure: 1,777,141 individual
13. **Resulted In · 100% confidence · current**  
   September 2025 Insightin GoAnywhere incident: Insightin said the event did not affect its ability to serve customers.
14. **Discovered At · 100% confidence · disputed**  
   September 2025 Insightin GoAnywhere incident: 2026-01-06
15. **Affected Organization · 100% confidence · current**  
   September 2025 Insightin GoAnywhere incident: Coordinated Care of Washington, Inc.
16. **Resulted In · 100% confidence · current**  
   September 2025 Insightin GoAnywhere incident: Insightin said it engaged forensic specialists, stopped further access, secured its environment, reviewed security policies, added safeguards, and reported the incident to law enforcement and regulators.
17. **Affected Individual Count · 100% confidence · current**  
   Insightin healthcare-client data exposure: 2,485 individual
18. **Affected Individual Count · 100% confidence · current**  
   Insightin healthcare-client data exposure: 143,346 individual
19. **Resulted In · 100% confidence · current**  
   September 2025 Insightin GoAnywhere incident: Insightin client, public, regulator, and individual notifications
20. **Resulted In · 100% confidence · current**  
   Insightin client, public, regulator, and individual notifications: Insightin's supplemental notice says it provided incident information to clients between December 4 and December 18, 2025 and worked with them to identify potentially affected people.
21. **Affected Individual Count · 100% confidence · current**  
   Insightin healthcare-client data exposure: 29 individual
22. **Affected Organization · 100% confidence · current**  
   September 2025 Insightin GoAnywhere incident: Wellcare of Washington, Inc.
23. **Ended At · 100% confidence · current**  
   September 2025 Insightin GoAnywhere incident: 2025-09-23
24. **Discovered At · 100% confidence · current**  
   September 2025 Insightin GoAnywhere incident: 2025-09-23
25. **Exposed Data Category · 100% confidence · current**  
   Insightin healthcare-client data exposure: Names
26. **Exposed Data Category · 100% confidence · current**  
   Insightin healthcare-client data exposure: Health insurance information
27. **Used Product · 100% confidence · current**  
   September 2025 Insightin GoAnywhere incident: GoAnywhere MFT
28. **Affected Individual Count · 100% confidence · current**  
   Insightin healthcare-client data exposure: 1,641 individual
29. **Affected Individual Count · 100% confidence · current**  
   Insightin healthcare-client data exposure: 1,949,534 individual
30. **Disclosed At · 100% confidence · current**  
   September 2025 Insightin GoAnywhere incident: 2026-01-14
31. **Exposed Data Category · 100% confidence · current**  
   Insightin healthcare-client data exposure: Contact information
32. **Exposed Data Category · 100% confidence · current**  
   Insightin healthcare-client data exposure: Dates of birth
33. **Exposed Data Category · 100% confidence · current**  
   Insightin healthcare-client data exposure: Account credentials
34. **Resulted In · 100% confidence · current**  
   September 2025 Insightin GoAnywhere incident: Insightin healthcare-client data exposure
35. **Resulted In · 100% confidence · current**  
   Insightin client, public, regulator, and individual notifications: The California sample notices offered twelve months of Cyberscout single-bureau credit monitoring, credit-report and credit-score services, and proactive fraud assistance.

</details>
