Philips Respironics International Colorado, Inc. (RICO)
bd_5f4e360acb510b9f · schema v1 · pii pii-v1
Full breach record for Philips Respironics International Colorado, Inc. (RICO) →Philips Respironics International Colorado, Inc. (RICO) notified affected individuals of a data breach involving the MOVEit transfer tool. An unauthorized party exploited a vulnerability in the software on May 31, 2023, extracting files containing patient and customer data. RICO discovered the vulnerability on June 5, 2023, and confirmed the breach on November 2, 2023. Notifications were sent on December 1, 2023. The incident affected 30,002 Texas residents, exposing names, addresses, dates of birth, and medical device usage data. RICO suspended the tool, enhanced encryption, and offered one year of Experian Identity Works.
J jump to incidentP pin to compareR raw source
Incident timeline
May 31, 2023
Begins
Jun 5, 2023
Discovered
Jan 22, 2024
Filed
vs. sector median
+20 wks slower
Linked disclosures
Why this link?Regulatory filings (1) · sorted by filing gap
- Delaware State AGbd_58678c09f45282172024-01-11 · +11dCandidate
Filing propagation · 2 filings · 2 states
View merged incident ↗Pattern: first filing Jan 11 (DE), last Jan 22 (WA) — a 11-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.