Blue Shield of California
bd_6beb8ba0bda9123f · schema v1 · pii pii-v1
Blue Shield of California notified members that a contracted vendor managing vision benefits was compromised in the global MOVEit data security incident. An unauthorized third party exploited an unknown vulnerability in the MOVEit server to exfiltrate information on May 28 and May 31, 2023. The vendor discovered the breach on August 23, 2023. Affected data may include member eligibility, authorized third parties, and vision claims processing information. Blue Shield is offering complimentary credit monitoring and identity restoration services through Kroll.
J jump to incidentP pin to compareR raw source
Incident timeline
May 28, 2023
Begins
Aug 23, 2023
Discovered
Nov 17, 2023
Filed
vs. sector median
on median
Linked disclosures
Why this link?Regulatory filings (2) · sorted by filing gap
- HHS OCRbd_4f096d3a71532eca2023-11-17Verified
- New Hampshire State AGbd_57de58eb876f18d72023-11-22 · +5dVerified
Filing propagation · 3 filings · 2 states
View merged incident ↗Pattern: first filing Nov 17 (CA), last Nov 22 (NH) — a 5-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.