San Diego PACE
bd_76686ee42a8574b0 · schema v1 · pii pii-v1
Full breach record for San Diego PACE →Cognisight LLC, a healthcare management services provider for San Diego PACE, disclosed a data breach resulting from the global MOVEit Transfer vulnerability. On May 31, 2023, Cognisight learned of the attack and stopped access to the service. A forensic investigation confirmed that files were taken from the MOVEit server. A subsequent review completed on August 2, 2023, determined that protected health information (PHI) and names of some individuals were impacted. The company restored servers from backups, applied vendor patches, and offered 12 months of credit monitoring and identity protection services to affected individuals.
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-575084
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Oct 13, 2023
- Raw hash
- 2fcda91538849919482f643dafc21af9bede62dd285b669cc24719d370640c1c
Reporting entity
- Name
- San Diego PACEnorm: san diego pace
Victim entity
- Name
- San Diego PACEnorm: san diego pace
Incident
- Discovered
- May 31, 2023
- Materiality determined
- —
- Notification sent
- Oct 13, 2023
- Affected individuals
- Not disclosed
- Data types
- PHIIDENTITY_BASIC
- Attack vector
- Third-Party / Supply Chain
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1041 Exfiltration Over C2 Channel
- Threat actor
- External
- Third party
- via MOVEit / Progress Software
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 19 weeks(135 days from discovery to filing)
- Compliance flags
- CA 60-day late · 135d
- Discovery-date grounding
- letter-groundedThe discovery date is the detection date narrated in the notification letter — the defensible tier.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: May 31, 2023→ Notified: Oct 13, 2023135d 60 days (analyst band, pre-2026 discoveries) CA 60-day late
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.