DisclosureLens
HackingHealthcareProfessional ServicesHealthcareVulnerability ExploitStolen CredentialsSupply Chain (3P Vendor)Data ExfiltratedCustomer Data InvolvedPHIIdentity (basic)LowContained

Cognisight LLC

bd_76686ee42a8574b0 · schema v1 · pii pii-v1

Severity

Low

Discovered

May 31, 2023

Filed

Oct 13, 2023

To disclose

19 weeks

Affected

Not disclosed

Confidence

64%

Cognisight LLC, a healthcare management services provider for San Diego PACE, disclosed a data breach resulting from the global MOVEit Transfer vulnerability. On May 31, 2023, Cognisight learned of the attack and stopped access to the service. A forensic investigation confirmed that files were taken from the MOVEit server. A subsequent review completed on August 2, 2023, determined that protected health information (PHI) and names of some individuals were impacted. The company restored servers from backups, applied vendor patches, and offered 12 months of credit monitoring and identity protection services to affected individuals.

California clockDiscovered May 31, 2023Notified Oct 13, 2023135d CA 60-day late19 weeks discovery → filing

Incident timeline

undetected · 3 days
discovery → filing · 19 weeks / 135 days

May 28, 2023

Begins

May 31, 2023

Discovered

Oct 13, 2023

Filed

vs. sector median

+8 wks slower

Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.