HackingStolen CredentialsSupply Chain (3P Vendor)Customer Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTMediumContained
Colorado Department of Health Care Policy and Financing
bd_501ce56cdd46ef11 · schema v1 · pii pii-v1
Full breach record for Colorado Department of Health Care Policy and Financing →Colorado Department of Health Care Policy and Financing (HCPF) notified consumers of a data breach involving its third-party vendor, IBM, which uses Progress Software's MOVEit Transfer application. An unauthorized actor accessed certain HCPF files on or about May 28, 2023, containing names, addresses, phone numbers, SSNs, and financial account information for Health First Colorado and CHP+ members/providers. HCPF offered two years of credit monitoring. No HCPF systems were directly compromised.
Vermont clock✗ VT AG >45 bday16 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 11 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (10) · sorted by filing gap
- bd_4107138ac65485a0Maine State AGfiled 2023-10-03Verified
- bd_a36dbca8821d58c1California State AGfiled 2023-10-03Verified
- bd_bc4561bd8522923fDelaware State AGfiled 2023-10-03Verified
- bd_b131d9519be28ad6South Carolina State AGClopfiled 2023-08-14(50d gap)Verified
Show 6 more filings ↓Show fewer ↑up to 63d gap
- bd_651d3456f2cd7362Delaware State AGfiled 2023-08-11(53d gap)Verified
- bd_a26eef2000fb6b18Vermont State AGfiled 2023-08-11(53d gap)Verified
- bd_c8f2a8126cd41b6bMaine State AGfiled 2023-08-11(53d gap)Verified
- bd_cb8d9ebf14bedf02HHS OCRfiled 2023-08-11(53d gap)Verified
- bd_eb9bc01f2d03027bCalifornia State AGfiled 2023-08-11(53d gap)Verified
- bd_b918db91ace38228New Hampshire State AGfiled 2023-08-01(63d gap)Verified
Source provenance
- Source URL
- https://ago.vermont.gov/document/2023-10-03-colorado-department-health-care-policy-financing-progress-software-moveit-data-breach
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Oct 3, 2023
- Raw hash
- b02ef40047233f2c6b076277674923104fa2fbd3881df09dd8a5074c80938286
Reporting entity
- Name
- Colorado Department of Health Care Policy and Financingnorm: colorado department of health care policy and financing
- Domain
- hcpf.colorado.gov
Victim entity
- Name
- Colorado Department of Health Care Policy and Financingnorm: colorado department of health care policy and financing
- Domain
- hcpf.colorado.gov
Incident
- Discovered
- Jun 13, 2023
- Materiality determined
- —
- Notification sent
- Oct 3, 2023
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNT
- Attack vector
- Third-Party / Supply Chain
- MITRE ATT&CK
- T1195 Supply Chain CompromiseT1078 Valid Accounts
- Threat actor
- ExternalFinancial
- Initial access
- supply_chain
Compliance
- Time to disclose
- 16 weeks(112 days from discovery to filing)
- Compliance flags
- VT AG >45 bday
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.