Cognisight LLC
bd_76686ee42a8574b0 · schema v1 · pii pii-v1
Cognisight LLC, a healthcare management services provider for San Diego PACE, disclosed a data breach resulting from the global MOVEit Transfer vulnerability. On May 31, 2023, Cognisight learned of the attack and stopped access to the service. A forensic investigation confirmed that files were taken from the MOVEit server. A subsequent review completed on August 2, 2023, determined that protected health information (PHI) and names of some individuals were impacted. The company restored servers from backups, applied vendor patches, and offered 12 months of credit monitoring and identity protection services to affected individuals.
J jump to incidentP pin to compareR raw source
Incident timeline
May 28, 2023
Begins
May 31, 2023
Discovered
Oct 13, 2023
Filed
vs. sector median
+8 wks slower
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.