Nuance Communications, Inc
bd_829cc01dc8d0b732 · schema v1 · pii pii-v1
Full breach record for Nuance Communications, Inc →Nuance Communications, Inc. disclosed a data breach resulting from a previously unknown vulnerability in MOVEit Transfer software provided by third-party vendor Progress Software Corporation. An unauthorized third party exfiltrated data between May 28 and May 29, 2023. Nuance was notified of the vulnerability on May 31, 2023. Affected data included names, dates of birth, medical record numbers, gender, and details about radiology studies (provider, facility, date of service, study identifiers, and study reports). Social Security numbers and financial information were not involved. Nuance secured systems, engaged forensic experts, notified law enforcement, and sent notices to affected individuals starting August 1, 2023.
Linked disclosures
Why this link?Regulatory filings (6) · sorted by filing gap
- bd_2d18f75acad25ac9Maine State AGfiled 2023-09-15Candidate
- bd_42ba23005cabceb8New Hampshire State AGfiled 2023-09-15Verified
- bd_f82949cd77b8e1acMontana State AGfiled 2023-09-15Verified
- bd_119ca48980839f9bDelaware State AGfiled 2023-09-18(3d gap)Verified
Show 2 more filings ↓Show fewer ↑up to 4d gap
- bd_b80d8c8f8a2bace4Delaware State AGfiled 2023-09-18(3d gap)Verified
- bd_61e841c1c6509034Oregon State AGfiled 2023-09-19(4d gap)Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-573426
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Sep 15, 2023
- Raw hash
- e6ed0ef9eafb88da190e7f8e7214501b10d3954e477158268834484477dd81be
Reporting entity
- Name
- Nuance Communications, Incnorm: nuance communications
Victim entity
- Name
- Nuance Communications, Incnorm: nuance communications
Incident
- Discovered
- May 31, 2023
- Materiality determined
- —
- Notification sent
- Aug 1, 2023
- Affected individuals
- Not disclosed
- Data types
- PHIHEALTH_BASICIDENTITY_BASIC
- Attack vector
- Third-Party / Supply Chain
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1195 Supply Chain CompromiseT1041 Exfiltration Over C2 Channel
- Threat actor
- External
- Regulator citations
- Notified law enforcement authorities
- Third party
- via Progress Software Corporation
- Initial access
- supply_chain
Compliance
- Time to disclose
- 15 weeks(107 days from discovery to filing)
- Compliance flags
- CA 60-day late · 62d
- Discovery-date grounding
- letter-groundedThe discovery date is the detection date narrated in the notification letter — the defensible tier.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: May 31, 2023→ Notified: Aug 1, 202362d 60 days (analyst band, pre-2026 discoveries) CA 60-day late
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.