HackingVulnerability ExploitData ExfiltratedData EncryptedCustomer Data InvolvedDelayed DiscoveryIDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASICHighContained
Philips Respironics International Colorado, Inc. (RICO)
bd_58678c09f4528217 · schema v1 · pii pii-v1
Full breach record for Philips Respironics International Colorado, Inc. (RICO) →Philips Respironics International Colorado, Inc. (RICO) notified 30,002 Texas residents of a data breach involving the MOVEit Transfer software vulnerability. The incident occurred on May 31, 2023, when an unauthorized party exploited the vulnerability to exfiltrate files containing patient names, addresses, dates of birth, and medical device usage data. RICO suspended use of the tool and offered one year of Experian Identity Works services to affected individuals.
This filing is one of 3 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (2) · sorted by filing gap
- bd_e6273ed93643e09bDelaware State AGfiled 2024-01-11Candidate
- bd_5f4e360acb510b9fWashington State AGfiled 2024-01-22(11d gap)Verified
Source provenance
- Source URL
- https://attorneygeneral.delaware.gov/wp-content/uploads/sites/50/2024/01/Patient-RICO-Notice.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jan 11, 2024
- Raw hash
- c81baabec4c6c6d896129c66042c83ff78c4cf55902c75ed480eeb7aa94a3e8d
Reporting entity
- Name
- Philips Respironics International Colorado, Inc. (RICO)norm: philips respironics international colorado inc rico
Victim entity
- Name
- Philips Respironics International Colorado, Inc. (RICO)norm: philips respironics international colorado inc rico
Incident
- Discovered
- Jun 5, 2023
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- 30,002
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1041 Exfiltration Over C2 Channel
- Threat actor
- ExternalFinancial
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 31 weeks(220 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.