Imagine360 notifies over 112,000 after two file transfer breaches
- Organization
- Imagine360, LLC
- Exploit
- Hacking
- Industry
- Healthcare
Imagine360, a Pennsylvania based administrator of self funded health plans, notified more than 112,000 people in mid 2023 that their information had been taken in two separate compromises of file transfer platforms it relied on.
The company said it detected suspicious activity on its Citrix file sharing platform in late January 2023 and later determined that files had been copied between January 28 and January 30. Days afterwards, on February 3, Fortra told Imagine360 that its GoAnywhere managed file transfer product had also been exploited and that Imagine360 data held there had been accessed.
The information involved varied by individual and included names, Social Security numbers, medical information and health insurance information. Imagine360 said it cut off the unauthorized access, reset passwords, took the Citrix platform offline, stopped using the Fortra product and added further safeguards.
Notification letters were mailed on June 30, 2023. Imagine360 initially reported 112,611 affected individuals to the U.S. Department of Health and Human Services, a total later revised upward to 132,807. Console and Associates, which reviewed the notification letters, put the figure at more than 125,000.
HIPAA Journal noted at the time that the notification materials made no mention of credit monitoring or identity theft protection being offered to those affected.
Updates
-
Imagine360 agreed to settle the resulting class action for $475,000, offering class members reimbursement of documented losses up to $5,000 or an estimated flat payment of $75, plus up to three years of credit monitoring. A final approval hearing was set for August 15, 2025.