Colorado Department of Health Care Policy and Financing
bd_651d3456f2cd7362 · schema v1 · pii pii-v1
Full breach record for Colorado Department of Health Care Policy and Financing →Colorado Department of Health Care Policy & Financing (HCPF) notified Delaware residents of a data event involving approximately 324 individuals. The incident stemmed from a vulnerability in Progress Software's MOVEit Transfer application, exploited by an unauthorized actor who accessed files managed by third-party vendor IBM. The breach exposed names, Social Security numbers, Medicaid/Medicare IDs, dates of birth, and medical/insurance information. HCPF launched an investigation, engaged forensic review, and provided 24 months of credit monitoring via Experian to affected Delaware residents. The investigation was ongoing as of the notice date of August 11, 2023.
Linked disclosures
Why this link?Regulatory filings (10) · sorted by filing gap
- bd_a26eef2000fb6b18Vermont State AGfiled 2023-08-11Verified
- bd_c8f2a8126cd41b6bMaine State AGfiled 2023-08-11Verified
- bd_cb8d9ebf14bedf02HHS OCRfiled 2023-08-11Verified
- bd_eb9bc01f2d03027bCalifornia State AGfiled 2023-08-11Verified
Show 6 more filings ↓Show fewer ↑up to 53d gap
- bd_b131d9519be28ad6South Carolina State AGClopfiled 2023-08-14(3d gap)Verified
- bd_b918db91ace38228New Hampshire State AGfiled 2023-08-01(10d gap)Verified
- bd_4107138ac65485a0Maine State AGfiled 2023-10-03(53d gap)Verified
- bd_501ce56cdd46ef11Vermont State AGfiled 2023-10-03(53d gap)Verified
- bd_a36dbca8821d58c1California State AGfiled 2023-10-03(53d gap)Verified
- bd_bc4561bd8522923fDelaware State AGfiled 2023-10-03(53d gap)Verified
Source provenance
- Source URL
- https://attorneygeneral.delaware.gov/wp-content/uploads/sites/50/2023/08/Colorado-Department-of-Health-Care-Policy-Financing-Notice-of-Data-Event-DE.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Aug 11, 2023
- Raw hash
- 0e126c2de6ddfa4ae678cbd38f34105576eaebd357018b52d43f6a663feed1ff
Reporting entity
- Name
- Colorado Department of Health Care Policy and Financingnorm: colorado department of health care policy and financing
- Domain
- hcpf.colorado.gov
Victim entity
- Name
- Colorado Department of Health Care Policy and Financingnorm: colorado department of health care policy and financing
- Domain
- hcpf.colorado.gov
Incident
- Discovered
- May 31, 2023
- Materiality determined
- —
- Notification sent
- Aug 11, 2023
- Affected individuals
- 324
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASICFINANCIAL_ACCOUNT
- Attack vector
- Third-Party / Supply Chain
- MITRE ATT&CK
- T1195 Supply Chain Compromise
- Threat actor
- External
- Regulator citations
- Provided written notice of this incident to relevant state regulatorsNotifying the U.S. Department of Health and Human Services and prominent media pursuant to the Health Insurance Portability and Accountability Act (HIPAA)
- Third party
- via IBM
- Initial access
- supply_chain
Compliance
- Time to disclose
- 10 weeks(72 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.