DisclosureLens
HackingHealthcareTechnologyHealthcareVulnerability ExploitCapture Stored DataData ExfiltratedTargetedDelayed DiscoveryFinancial accountIdentity (basic)Government IDPHIHealth (basic)CVE-2023-34362HighContained

Rotech Healthcare (Philips Respironics, Inc.)

bd_2ee71137b16c076c · schema v1 · pii pii-v1

Severity

High

Discovered

Jun 5, 2023

Filed

Jun 3, 2024

To disclose

52 weeks

Affected

2,802state residents only

Confidence

69%
Full breach record for Rotech Healthcare (Philips Respironics, Inc.)

Philips Respironics experienced a cybersecurity incident involving the exploitation of a vulnerability in Progress Software's MOVEit Transfer software. An unauthorized third party accessed and extracted files from a Philips Respironics server between May 31 and June 5, 2023. The data included patient names, addresses, dates of birth, insurance policy numbers, and device serial numbers. Rotech Healthcare, a business associate, was also impacted. Notifications were sent to affected individuals in January 2024.

Washington clock WA AG >90d52 weeks discovery → filing
AG web formThe discovery date came from the AG web-form field, which is systematically later than the detection date stated in the letter. Treat the clock as indicative.

Incident timeline

undetected · 5 days
discovery → filing · 52 weeks / 364 days

May 31, 2023

Begins

Jun 5, 2023

Discovered

Jun 3, 2024

Filed

vs. sector median

+41 wks slower

Tracked as a single-filing incident — the only disclosure on record for this event so far.Confirmed2,802 affectedView incident

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.