HackingStolen CredentialsSupply Chain (3P Vendor)Data ExfiltratedCustomer Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTMediumContained
Colorado Department of Health Care Policy and Financing
bd_6f832e7ad75b6a0c · schema v1 · pii pii-v1
Full breach record for Colorado Department of Health Care Policy and Financing →Colorado Department of Health Care Policy & Financing (HCPF) issued a supplemental data breach notice regarding a third-party supply chain incident involving IBM and Progress Software's MOVEit Transfer application. Unauthorized access occurred on or about May 28, 2023, affecting files containing names, Social Security numbers, and insurance policy identifiers for Health First Colorado and CHP+ members. HCPF offered two years of credit monitoring via Experian. The filing was submitted to the Delaware Attorney General in February 2024.
This filing is one of 6 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (5) · sorted by filing gap
- bd_276c06374e7a08fcMaine State AGfiled 2024-02-19Candidate
- bd_5167088d02685ddfOregon State AGfiled 2024-02-19Verified
- bd_5ebd8c098e6a6f5fVermont State AGfiled 2024-02-19Verified
- bd_90735d0659ea8b49California State AGfiled 2024-02-19Verified
Show 1 more filing ↓Show fewer ↑up to 1d gap
- bd_a3f112b2ddad6d7aNew Hampshire State AGfiled 2024-02-20(1d gap)Verified
Source provenance
- Source URL
- https://attorneygeneral.delaware.gov/wp-content/uploads/sites/50/2024/02/Colorado-Department-of-Health-Care-Policy-Financing-Supplemental-Notice-of-Data-Event-DE.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Feb 19, 2024
- Raw hash
- 5cb57a37d782b06eeedee77a09c0aaa43e7c5376494e6b20161ee7e34bb3a570
Reporting entity
- Name
- Colorado Department of Health Care Policy and Financingnorm: colorado department of health care policy and financing
- Domain
- hcpf.colorado.gov
Victim entity
- Name
- Colorado Department of Health Care Policy and Financingnorm: colorado department of health care policy and financing
- Domain
- hcpf.colorado.gov
Incident
- Discovered
- May 31, 2023
- Materiality determined
- —
- Notification sent
- Feb 19, 2024
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Third-Party / Supply Chain
- MITRE ATT&CK
- T1195 Supply Chain Compromise
- Threat actor
- ExternalFinancial
- Regulator citations
- Notified state Attorneys General (Delaware, California, DC, Maryland, New Mexico, New York, North Carolina, Rhode Island)
- Third party
- via IBM
- Initial access
- supply_chain
Compliance
- Time to disclose
- 38 weeks(264 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.