{"id":721,"date":"2023-05-04T22:32:22","date_gmt":"2023-05-05T03:32:22","guid":{"rendered":"https:\/\/kentprotect.com\/?p=721"},"modified":"2023-05-04T22:55:22","modified_gmt":"2023-05-05T03:55:22","slug":"breach-report-brightline-pediatric-startup-breached-783000-affected","status":"publish","type":"post","link":"https:\/\/kentprotect.com\/index.php\/2023\/05\/04\/breach-report-brightline-pediatric-startup-breached-783000-affected\/","title":{"rendered":"Breach Report: Brightline, pediatric startup, breached, 783,000+ affected"},"content":{"rendered":"<div class='booster-block booster-read-block'><\/div>\n<p class=\"has-medium-font-size wp-block-paragraph\"><strong>One-sentence summary: <\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Brightline was breached in the Clop ransomware group&#8217;s campaign against Fortra&#8217;s GoAnywhere MFT zero-day vulnerability, affecting over 783,606 pediatric patients and 58 covered entities and resulting in a class-action lawsuit. <\/p>\n\n\n\n<p class=\"has-medium-font-size wp-block-paragraph\"><strong>Who was involved?<\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Brightline, Inc., Fortra, LLC, 783,606 pediatric patients, and the Clop ransomware group. Brightline is also associated with many covered entities (a total of 58) which they have listed as involved in the breach as well: <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">&#8220;Seward Association for the Advancement of Marine Science dba Alaska SeaLife Center<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Competitive Health<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Diageo<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Banner Corporation dba Banner Bank<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Ben Bridge Jeweler, Inc<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Carrix, Inc<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Chelan County<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Coastal Villages Region Fund<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Legal Name: Continental Mills, Inc. Common Name: The Krusteaz Co<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">CRISTA Ministries<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Edifecs, Inc.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">First Security Bank of WAx<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">FirstFruits HoldCo, LLC<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Football Northwest, LLC<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Goodfellows Bros. LLC<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Green Diamond Resources<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Holland America Group<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Insitu, Inc.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Keller Supply<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">KPMG LLP<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Kodiak Island Borough School District<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">MacDonald-Miller Facility Solutions, LLC<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Manke Lumber Company Inc.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Municipality of Anchorage<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Nintendo of America Inc.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Northwest Cascade, Inc.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Oberto Snacks Inc.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">PND Engineers, Inc.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Pyrotek Inc<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Rail Management Services<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Seagen Inc.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">SolstenXP, Inc.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Space Needle LLC &amp; Center Art LLC<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Spokane Teachers Credit Union<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Symetra Life Insurance Company<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Tanana Chiefs Conference<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Undead Labs<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">University of Alaska<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Walla Walla University<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Washington Trust Bank<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Whitman College<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Alaska Central Express, Inc DBA Ace Air Cargo<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Alaska Hotel Properties LLC<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Alaska Railroad Corporation<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">ASML<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">MIIA<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">HARVARD UNIVERSITY FACULTY AND STAFF (HUFS)<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">HARVARD UNIVERSITY (HUGHP)<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">BOSTON CHILDRENS HOSPITAL<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">BLUE CROSS BLUE SHIELD OF MASS<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">VERTEX<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">SOUTH SHORE HEALTH<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">IUOE<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The Board of Directors of the Leland Stanford Junior University (Educated Choices)<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Stanford University Post-doctoral Scholars<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Stanford Health Care \u2013 ValleyCare Employee Health Care Plan<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Stanford Health Care Employee Health and Welfare Benefit Plan<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Stanford Medicine Partners Employee Health and Welfare Benefit Plan&#8221; (Brightline, 2023b)<\/p>\n\n\n\n<p class=\"has-medium-font-size wp-block-paragraph\"><strong>What was the timeline?<\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">January 30, 2023: Brightline is breached as a part of the GoAnywhere campaign by the Clop ransomware group <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">February 4, 2023: Brightline discovers the data breach from Fortra <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">April 7, 2023: Brightline begins consumer notification <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">May 2, 2023: Class-action lawsuit is filed against Brightline in the federal Northern District of California (<em>Rosa et al v. Brightline, Inc.<\/em>, 2023) <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">May 3, 2023: The Clop ransomware group tells Bleeping Computer they deleted the data (Toulas, 2023)<\/p>\n\n\n\n<p class=\"has-medium-font-size wp-block-paragraph\"><strong>What occurred?<\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Brightline, a pediatric mental health services startup, was breached in the Clop ransomware group&#8217;s campaign against Fortra&#8217;s GoAnywhere MFT solution, potentially exposing the following sensitive data for at least 783,606 individuals (primarily pediatric patients): &#8220;limited amount of protected health information\/personal information&#8221; with &#8220;some combination of the following data elements: individuals\u2019 names, addresses, dates of birth, member identification numbers, date of health plan coverage, and\/or employer names&#8221; (Brightline, 2023a; HHS, 2023). Over 58 covered entities are implicated (Brightline, 2023b). The Clop ransomware group ultimately reached out to Bleeping Computer expressing an apology and a statement that they deleted the data belonging to Brightline (Toulas, 2023). Ultimately, Bleeping Computer confirmed the data was removed from Clop&#8217;s leak portal (Toulas, 2023). This did not stop a federal, class-action lawsuit from being filed in the Northern District of California against Brightline (<em>Rosa et al v. Brightline, Inc.<\/em>, 2023). <\/p>\n\n\n\n<p class=\"has-medium-font-size wp-block-paragraph\"><strong>Estimated costs:<\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Incident response costs, breach notification costs, 2 years of identity theft services from Cyberscout<\/p>\n\n\n\n<p class=\"has-medium-font-size wp-block-paragraph\"><strong>Involved laws: <\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Federal: HIPAA, HITECH, and COPPA<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">State: California CCPA and Cal. Civ. Code \u00a7 1798.29(a)<\/p>\n\n\n\n<p class=\"has-medium-font-size wp-block-paragraph\"><strong>Root cause: <\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The zero-day, remote code execution vulnerability in Fortra\u2019s GoAnywhere MFT solution (CVE-2023-0669) (Brightline, 2023a)<\/p>\n\n\n\n<p class=\"has-medium-font-size wp-block-paragraph\"><strong>Lessons learned: <\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">TBA or N\/A (see disclaimer) (GoAnywhere is marketed as a HIPAA and HITECH-compliant SFTP solution) (Fortra, n.d.).<\/p>\n\n\n\n<p class=\"has-medium-font-size wp-block-paragraph\"><strong>Sources: <\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Brightline. (2023a, April 7). <em>Notice of Fortra Data Security Incident<\/em>. Virtual Mental Health Care for Kids and Teens | Brightline. Retrieved May 4, 2023, from https:\/\/www.hellobrightline.com\/fortra-data-notice<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Brightline. (2023b, April 7). <em>Virtual Mental Health Care for Kids and Teens | Brightline<\/em>. hellobrightline.com. Retrieved May 4, 2023, from https:\/\/www.hellobrightline.com\/list-of-impacted-covered-entities<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Brightline (Bleeping Computer). (2023, May 3). <em>brightline-header.jpg<\/em>. bleepstatic.com. https:\/\/www.bleepstatic.com\/content\/posts\/2023\/05\/03\/brightline-header.jpg<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Fortra. (n.d.).&nbsp;<em>HIPAA &amp; HITECH Compliant File Transfers<\/em>. goanywhere.com. Retrieved February 16, 2023, from https:\/\/www.goanywhere.com\/solutions\/compliance\/hipaa-hitech<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">HHS. (2023). Cases Currently Under Investigation. In <em>Breach Portal: Notice to the Secretary of HHS Breach of Unsecured Protected Health Information<\/em>. U.S. Department of Health and Human Services Office for Civil Rights. Retrieved May 4, 2023, from https:\/\/ocrportal.hhs.gov\/ocr\/breach\/breach_report.jsf<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/www.bloomberglaw.com\/ms\/public\/desktop\/document\/RosaetalvBrightlineIncDocketNo323cv02132NDCalMay022023CourtDocket\">Rosa et al v. Brightline, Inc., Docket No. 4:23-cv-02132 (N.D. Cal. May 02, 2023), Court Docket<\/a><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Toulas, B. (2023, May 3). Brightline data breach impacts 783K pediatric mental health patients. <em>BleepingComputer<\/em>. https:\/\/www.bleepingcomputer.com\/news\/security\/brightline-data-breach-impacts-783k-pediatric-mental-health-patients\/<\/p>\n\n\n\n<figure class=\"wp-block-embed is-type-video is-provider-youtube wp-block-embed-youtube wp-embed-aspect-16-9 wp-has-aspect-ratio\"><div class=\"wp-block-embed__wrapper\">\n<iframe loading=\"lazy\" title=\"Brightline, a pediatric startup in Palo Alto, California, was breached by the Clop ransomware group\" width=\"640\" height=\"360\" src=\"https:\/\/www.youtube.com\/embed\/tor0dZQszok?feature=oembed\" frameborder=\"0\" allow=\"accelerometer; autoplay; clipboard-write; encrypted-media; gyroscope; picture-in-picture; web-share\" referrerpolicy=\"strict-origin-when-cross-origin\" allowfullscreen><\/iframe>\n<\/div><figcaption class=\"wp-element-caption\">YouTube\/Blog Notification Post<\/figcaption><\/figure>\n","protected":false},"excerpt":{"rendered":"<p>One-sentence summary: Brightline was breached in the Clop ransomware group&#8217;s campaign against Fortra&#8217;s GoAnywhere MFT zero-day vulnerability, affecting<\/p>\n","protected":false},"author":4,"featured_media":723,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[480,3,12,85,13,76,63,274,597,75,61,11,10,74,430,14,45,566,43,44,355,567,8,27,595,220,598,596,67,15,81],"class_list":["post-721","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-the-breach-report","tag-breach","tag-breach-report","tag-breaches","tag-california","tag-ciso","tag-cloud","tag-computer-security","tag-computers","tag-counseling","tag-cyber-security","tag-cybercrime","tag-cybersecurity","tag-dallas","tag-data-breach","tag-doctors","tag-executive","tag-healthcare","tag-healthinsurance","tag-hipaa","tag-hitech","tag-hospitals","tag-insurance","tag-kent-protect","tag-kentprotect","tag-mental-health","tag-nursing","tag-paloalto","tag-pediatric","tag-pwned","tag-summary","tag-texas"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.7 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Breach Report: Brightline, pediatric startup, breached, 783,000+ affected - Kent Protect<\/title>\n<meta name=\"description\" content=\"Brightline was breached in the Clop ransomware group&#039;s campaign against Fortra&#039;s GoAnywhere MFT zero-day vulnerability, affecting over 783,606 pediatric patients and 58 covered entities and resulting in a class-action lawsuit.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/kentprotect.com\/index.php\/2023\/05\/04\/breach-report-brightline-pediatric-startup-breached-783000-affected\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Breach Report: Brightline, pediatric startup, breached, 783,000+ affected - Kent Protect\" \/>\n<meta property=\"og:description\" content=\"Brightline was breached in the Clop ransomware group&#039;s campaign against Fortra&#039;s GoAnywhere MFT zero-day vulnerability, affecting over 783,606 pediatric patients and 58 covered entities and resulting in a class-action lawsuit.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/kentprotect.com\/index.php\/2023\/05\/04\/breach-report-brightline-pediatric-startup-breached-783000-affected\/\" \/>\n<meta property=\"og:site_name\" content=\"Kent Protect\" \/>\n<meta property=\"article:published_time\" content=\"2023-05-05T03:32:22+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2023-05-05T03:55:22+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/kentprotect.com\/wp-content\/uploads\/2023\/05\/brightline-header.webp\" \/>\n\t<meta property=\"og:image:width\" content=\"1600\" \/>\n\t<meta property=\"og:image:height\" content=\"900\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/webp\" \/>\n<meta name=\"author\" content=\"Kyler Kent CISSP\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Kyler Kent CISSP\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"4 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/kentprotect.com\\\/index.php\\\/2023\\\/05\\\/04\\\/breach-report-brightline-pediatric-startup-breached-783000-affected\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/kentprotect.com\\\/index.php\\\/2023\\\/05\\\/04\\\/breach-report-brightline-pediatric-startup-breached-783000-affected\\\/\"},\"author\":{\"name\":\"Kyler Kent CISSP\",\"@id\":\"https:\\\/\\\/kentprotect.com\\\/#\\\/schema\\\/person\\\/f9b4d76bd2f5b5559a08ad2e004a1116\"},\"headline\":\"Breach Report: Brightline, pediatric startup, breached, 783,000+ affected\",\"datePublished\":\"2023-05-05T03:32:22+00:00\",\"dateModified\":\"2023-05-05T03:55:22+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/kentprotect.com\\\/index.php\\\/2023\\\/05\\\/04\\\/breach-report-brightline-pediatric-startup-breached-783000-affected\\\/\"},\"wordCount\":756,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\\\/\\\/kentprotect.com\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/kentprotect.com\\\/index.php\\\/2023\\\/05\\\/04\\\/breach-report-brightline-pediatric-startup-breached-783000-affected\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/kentprotect.com\\\/wp-content\\\/uploads\\\/2023\\\/05\\\/brightline-header.webp\",\"keywords\":[\"breach\",\"breach report\",\"breaches\",\"california\",\"ciso\",\"cloud\",\"computer security\",\"computers\",\"counseling\",\"cyber security\",\"cybercrime\",\"cybersecurity\",\"dallas\",\"data breach\",\"doctors\",\"executive\",\"healthcare\",\"healthinsurance\",\"HIPAA\",\"HITECH\",\"hospitals\",\"insurance\",\"kent protect\",\"kentprotect\",\"mental health\",\"nursing\",\"paloalto\",\"pediatric\",\"pwned\",\"summary\",\"texas\"],\"articleSection\":[\"The Breach Report!\"],\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\\\/\\\/kentprotect.com\\\/index.php\\\/2023\\\/05\\\/04\\\/breach-report-brightline-pediatric-startup-breached-783000-affected\\\/#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/kentprotect.com\\\/index.php\\\/2023\\\/05\\\/04\\\/breach-report-brightline-pediatric-startup-breached-783000-affected\\\/\",\"url\":\"https:\\\/\\\/kentprotect.com\\\/index.php\\\/2023\\\/05\\\/04\\\/breach-report-brightline-pediatric-startup-breached-783000-affected\\\/\",\"name\":\"Breach Report: Brightline, pediatric startup, breached, 783,000+ affected - Kent Protect\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/kentprotect.com\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/kentprotect.com\\\/index.php\\\/2023\\\/05\\\/04\\\/breach-report-brightline-pediatric-startup-breached-783000-affected\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/kentprotect.com\\\/index.php\\\/2023\\\/05\\\/04\\\/breach-report-brightline-pediatric-startup-breached-783000-affected\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/kentprotect.com\\\/wp-content\\\/uploads\\\/2023\\\/05\\\/brightline-header.webp\",\"datePublished\":\"2023-05-05T03:32:22+00:00\",\"dateModified\":\"2023-05-05T03:55:22+00:00\",\"description\":\"Brightline was breached in the Clop ransomware group's campaign against Fortra's GoAnywhere MFT zero-day vulnerability, affecting over 783,606 pediatric patients and 58 covered entities and resulting in a class-action lawsuit.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/kentprotect.com\\\/index.php\\\/2023\\\/05\\\/04\\\/breach-report-brightline-pediatric-startup-breached-783000-affected\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/kentprotect.com\\\/index.php\\\/2023\\\/05\\\/04\\\/breach-report-brightline-pediatric-startup-breached-783000-affected\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/kentprotect.com\\\/index.php\\\/2023\\\/05\\\/04\\\/breach-report-brightline-pediatric-startup-breached-783000-affected\\\/#primaryimage\",\"url\":\"https:\\\/\\\/kentprotect.com\\\/wp-content\\\/uploads\\\/2023\\\/05\\\/brightline-header.webp\",\"contentUrl\":\"https:\\\/\\\/kentprotect.com\\\/wp-content\\\/uploads\\\/2023\\\/05\\\/brightline-header.webp\",\"width\":1600,\"height\":900,\"caption\":\"Brightline Logo (image source: Brightline (Bleeping Computer), 2023)\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/kentprotect.com\\\/index.php\\\/2023\\\/05\\\/04\\\/breach-report-brightline-pediatric-startup-breached-783000-affected\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/kentprotect.com\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Breach Report: Brightline, pediatric startup, breached, 783,000+ affected\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/kentprotect.com\\\/#website\",\"url\":\"https:\\\/\\\/kentprotect.com\\\/\",\"name\":\"Kent Protect\",\"description\":\"Starring the Breach Report! and other security and cybersecurity series\",\"publisher\":{\"@id\":\"https:\\\/\\\/kentprotect.com\\\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/kentprotect.com\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/kentprotect.com\\\/#organization\",\"name\":\"Kent Protect\",\"url\":\"https:\\\/\\\/kentprotect.com\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/kentprotect.com\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/kentprotect.com\\\/wp-content\\\/uploads\\\/2023\\\/04\\\/cropped-FullLogo_Transparent-1-with-KP-Smaller.png\",\"contentUrl\":\"https:\\\/\\\/kentprotect.com\\\/wp-content\\\/uploads\\\/2023\\\/04\\\/cropped-FullLogo_Transparent-1-with-KP-Smaller.png\",\"width\":209,\"height\":161,\"caption\":\"Kent Protect\"},\"image\":{\"@id\":\"https:\\\/\\\/kentprotect.com\\\/#\\\/schema\\\/logo\\\/image\\\/\"}},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/kentprotect.com\\\/#\\\/schema\\\/person\\\/f9b4d76bd2f5b5559a08ad2e004a1116\",\"name\":\"Kyler Kent CISSP\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/kentprotect.com\\\/wp-content\\\/uploads\\\/2023\\\/03\\\/Retry-3-150x150.jpg\",\"url\":\"https:\\\/\\\/kentprotect.com\\\/wp-content\\\/uploads\\\/2023\\\/03\\\/Retry-3-150x150.jpg\",\"contentUrl\":\"https:\\\/\\\/kentprotect.com\\\/wp-content\\\/uploads\\\/2023\\\/03\\\/Retry-3-150x150.jpg\",\"caption\":\"Kyler Kent CISSP\"},\"description\":\"Kyler Kent is a Senior Cybersecurity Analyst on CrowdStrike\u2019s Falcon Complete MDR team, where he helps large enterprises detect, investigate, and contain real intrusions across cloud and hybrid environments. His work spans threat hunting, incident response, and security automation\u2014turning noisy telemetry into clear, repeatable actions that reduce risk quickly. Previously, Kyler served as a Threat Hunting and Intelligence Specialist supporting a critical infrastructure provider in Dallas, and led security automation and operational coordination at CyberConvoy. He holds a Master\u2019s in Cybersecurity Risk Management from Georgetown University and maintains certifications including CISSP, AWS Solutions Architect \u2013 Professional, AWS Security \u2013 Specialty, and multiple CrowdStrike credentials. He writes to close the gap between \u201cwhat the textbook says\u201d and what analysts actually do on shift with his published book: \\\"SOC Analyst Career Guide\\\" (ISBN-13: 9781835467466). https:\\\/\\\/linktr.ee\\\/kentprotect.com Corrections: corrections@kentprotect.com\",\"sameAs\":[\"http:\\\/\\\/kylerkent.com\"],\"url\":\"https:\\\/\\\/kentprotect.com\\\/index.php\\\/author\\\/kylerkent\\\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Breach Report: Brightline, pediatric startup, breached, 783,000+ affected - Kent Protect","description":"Brightline was breached in the Clop ransomware group's campaign against Fortra's GoAnywhere MFT zero-day vulnerability, affecting over 783,606 pediatric patients and 58 covered entities and resulting in a class-action lawsuit.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/kentprotect.com\/index.php\/2023\/05\/04\/breach-report-brightline-pediatric-startup-breached-783000-affected\/","og_locale":"en_US","og_type":"article","og_title":"Breach Report: Brightline, pediatric startup, breached, 783,000+ affected - Kent Protect","og_description":"Brightline was breached in the Clop ransomware group's campaign against Fortra's GoAnywhere MFT zero-day vulnerability, affecting over 783,606 pediatric patients and 58 covered entities and resulting in a class-action lawsuit.","og_url":"https:\/\/kentprotect.com\/index.php\/2023\/05\/04\/breach-report-brightline-pediatric-startup-breached-783000-affected\/","og_site_name":"Kent Protect","article_published_time":"2023-05-05T03:32:22+00:00","article_modified_time":"2023-05-05T03:55:22+00:00","og_image":[{"width":1600,"height":900,"url":"https:\/\/kentprotect.com\/wp-content\/uploads\/2023\/05\/brightline-header.webp","type":"image\/webp"}],"author":"Kyler Kent CISSP","twitter_card":"summary_large_image","twitter_misc":{"Written by":"Kyler Kent CISSP","Est. reading time":"4 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/kentprotect.com\/index.php\/2023\/05\/04\/breach-report-brightline-pediatric-startup-breached-783000-affected\/#article","isPartOf":{"@id":"https:\/\/kentprotect.com\/index.php\/2023\/05\/04\/breach-report-brightline-pediatric-startup-breached-783000-affected\/"},"author":{"name":"Kyler Kent CISSP","@id":"https:\/\/kentprotect.com\/#\/schema\/person\/f9b4d76bd2f5b5559a08ad2e004a1116"},"headline":"Breach Report: Brightline, pediatric startup, breached, 783,000+ affected","datePublished":"2023-05-05T03:32:22+00:00","dateModified":"2023-05-05T03:55:22+00:00","mainEntityOfPage":{"@id":"https:\/\/kentprotect.com\/index.php\/2023\/05\/04\/breach-report-brightline-pediatric-startup-breached-783000-affected\/"},"wordCount":756,"commentCount":0,"publisher":{"@id":"https:\/\/kentprotect.com\/#organization"},"image":{"@id":"https:\/\/kentprotect.com\/index.php\/2023\/05\/04\/breach-report-brightline-pediatric-startup-breached-783000-affected\/#primaryimage"},"thumbnailUrl":"https:\/\/kentprotect.com\/wp-content\/uploads\/2023\/05\/brightline-header.webp","keywords":["breach","breach report","breaches","california","ciso","cloud","computer security","computers","counseling","cyber security","cybercrime","cybersecurity","dallas","data breach","doctors","executive","healthcare","healthinsurance","HIPAA","HITECH","hospitals","insurance","kent protect","kentprotect","mental health","nursing","paloalto","pediatric","pwned","summary","texas"],"articleSection":["The Breach Report!"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/kentprotect.com\/index.php\/2023\/05\/04\/breach-report-brightline-pediatric-startup-breached-783000-affected\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/kentprotect.com\/index.php\/2023\/05\/04\/breach-report-brightline-pediatric-startup-breached-783000-affected\/","url":"https:\/\/kentprotect.com\/index.php\/2023\/05\/04\/breach-report-brightline-pediatric-startup-breached-783000-affected\/","name":"Breach Report: Brightline, pediatric startup, breached, 783,000+ affected - Kent Protect","isPartOf":{"@id":"https:\/\/kentprotect.com\/#website"},"primaryImageOfPage":{"@id":"https:\/\/kentprotect.com\/index.php\/2023\/05\/04\/breach-report-brightline-pediatric-startup-breached-783000-affected\/#primaryimage"},"image":{"@id":"https:\/\/kentprotect.com\/index.php\/2023\/05\/04\/breach-report-brightline-pediatric-startup-breached-783000-affected\/#primaryimage"},"thumbnailUrl":"https:\/\/kentprotect.com\/wp-content\/uploads\/2023\/05\/brightline-header.webp","datePublished":"2023-05-05T03:32:22+00:00","dateModified":"2023-05-05T03:55:22+00:00","description":"Brightline was breached in the Clop ransomware group's campaign against Fortra's GoAnywhere MFT zero-day vulnerability, affecting over 783,606 pediatric patients and 58 covered entities and resulting in a class-action lawsuit.","breadcrumb":{"@id":"https:\/\/kentprotect.com\/index.php\/2023\/05\/04\/breach-report-brightline-pediatric-startup-breached-783000-affected\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/kentprotect.com\/index.php\/2023\/05\/04\/breach-report-brightline-pediatric-startup-breached-783000-affected\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/kentprotect.com\/index.php\/2023\/05\/04\/breach-report-brightline-pediatric-startup-breached-783000-affected\/#primaryimage","url":"https:\/\/kentprotect.com\/wp-content\/uploads\/2023\/05\/brightline-header.webp","contentUrl":"https:\/\/kentprotect.com\/wp-content\/uploads\/2023\/05\/brightline-header.webp","width":1600,"height":900,"caption":"Brightline Logo (image source: Brightline (Bleeping Computer), 2023)"},{"@type":"BreadcrumbList","@id":"https:\/\/kentprotect.com\/index.php\/2023\/05\/04\/breach-report-brightline-pediatric-startup-breached-783000-affected\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/kentprotect.com\/"},{"@type":"ListItem","position":2,"name":"Breach Report: Brightline, pediatric startup, breached, 783,000+ affected"}]},{"@type":"WebSite","@id":"https:\/\/kentprotect.com\/#website","url":"https:\/\/kentprotect.com\/","name":"Kent Protect","description":"Starring the Breach Report! and other security and cybersecurity series","publisher":{"@id":"https:\/\/kentprotect.com\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/kentprotect.com\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/kentprotect.com\/#organization","name":"Kent Protect","url":"https:\/\/kentprotect.com\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/kentprotect.com\/#\/schema\/logo\/image\/","url":"https:\/\/kentprotect.com\/wp-content\/uploads\/2023\/04\/cropped-FullLogo_Transparent-1-with-KP-Smaller.png","contentUrl":"https:\/\/kentprotect.com\/wp-content\/uploads\/2023\/04\/cropped-FullLogo_Transparent-1-with-KP-Smaller.png","width":209,"height":161,"caption":"Kent Protect"},"image":{"@id":"https:\/\/kentprotect.com\/#\/schema\/logo\/image\/"}},{"@type":"Person","@id":"https:\/\/kentprotect.com\/#\/schema\/person\/f9b4d76bd2f5b5559a08ad2e004a1116","name":"Kyler Kent CISSP","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/kentprotect.com\/wp-content\/uploads\/2023\/03\/Retry-3-150x150.jpg","url":"https:\/\/kentprotect.com\/wp-content\/uploads\/2023\/03\/Retry-3-150x150.jpg","contentUrl":"https:\/\/kentprotect.com\/wp-content\/uploads\/2023\/03\/Retry-3-150x150.jpg","caption":"Kyler Kent CISSP"},"description":"Kyler Kent is a Senior Cybersecurity Analyst on CrowdStrike\u2019s Falcon Complete MDR team, where he helps large enterprises detect, investigate, and contain real intrusions across cloud and hybrid environments. His work spans threat hunting, incident response, and security automation\u2014turning noisy telemetry into clear, repeatable actions that reduce risk quickly. Previously, Kyler served as a Threat Hunting and Intelligence Specialist supporting a critical infrastructure provider in Dallas, and led security automation and operational coordination at CyberConvoy. He holds a Master\u2019s in Cybersecurity Risk Management from Georgetown University and maintains certifications including CISSP, AWS Solutions Architect \u2013 Professional, AWS Security \u2013 Specialty, and multiple CrowdStrike credentials. He writes to close the gap between \u201cwhat the textbook says\u201d and what analysts actually do on shift with his published book: \"SOC Analyst Career Guide\" (ISBN-13: 9781835467466). https:\/\/linktr.ee\/kentprotect.com Corrections: corrections@kentprotect.com","sameAs":["http:\/\/kylerkent.com"],"url":"https:\/\/kentprotect.com\/index.php\/author\/kylerkent\/"}]}},"_links":{"self":[{"href":"https:\/\/kentprotect.com\/index.php\/wp-json\/wp\/v2\/posts\/721","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/kentprotect.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/kentprotect.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/kentprotect.com\/index.php\/wp-json\/wp\/v2\/users\/4"}],"replies":[{"embeddable":true,"href":"https:\/\/kentprotect.com\/index.php\/wp-json\/wp\/v2\/comments?post=721"}],"version-history":[{"count":2,"href":"https:\/\/kentprotect.com\/index.php\/wp-json\/wp\/v2\/posts\/721\/revisions"}],"predecessor-version":[{"id":726,"href":"https:\/\/kentprotect.com\/index.php\/wp-json\/wp\/v2\/posts\/721\/revisions\/726"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/kentprotect.com\/index.php\/wp-json\/wp\/v2\/media\/723"}],"wp:attachment":[{"href":"https:\/\/kentprotect.com\/index.php\/wp-json\/wp\/v2\/media?parent=721"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/kentprotect.com\/index.php\/wp-json\/wp\/v2\/categories?post=721"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/kentprotect.com\/index.php\/wp-json\/wp\/v2\/tags?post=721"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}