HackingVulnerability ExploitStolen CredentialsSupply Chain (3P Vendor)Data ExfiltratedCustomer Data InvolvedBusiness Associate (HIPAA)PHIIDENTITY_GOVERNMENTIDENTITY_BASICHEALTH_BASICFINANCIALMediumContained
Colorado Department of Health Care Policy and Financing
bd_90735d0659ea8b49 · schema v1 · pii pii-v1
Full breach record for Colorado Department of Health Care Policy and Financing →Colorado Department of Health Care Policy & Financing (HCPF) notified residents of a data breach involving Health First Colorado and CHP+ members. An unauthorized actor accessed files on IBM's MOVEit Transfer application (used by HCPF vendor IBM) between May 28-31, 2023. HCPF discovered the access on June 13, 2023. Affected data includes names, SSNs, Medicaid/Medicare IDs, DOB, addresses, and clinical/medical information. HCPF offered 2 years of credit monitoring via Experian. This is a supplemental notice.
California clockDiscovered Jun 13, 2023 → Notified Feb 19, 2024251d ✗ CA 60-day late36 weeks discovery → filing
This filing is one of 6 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (5) · sorted by filing gap
- bd_276c06374e7a08fcMaine State AGfiled 2024-02-19Candidate
- bd_5167088d02685ddfOregon State AGfiled 2024-02-19Verified
- bd_5ebd8c098e6a6f5fVermont State AGfiled 2024-02-19Verified
- bd_6f832e7ad75b6a0cDelaware State AGfiled 2024-02-19Verified
Show 1 more filing ↓Show fewer ↑up to 1d gap
- bd_a3f112b2ddad6d7aNew Hampshire State AGfiled 2024-02-20(1d gap)Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-581211
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Feb 19, 2024
- Raw hash
- a51b12805ae0464b080afa540ee31e127d954020438a53cfc6869ad0c25cfec6
Reporting entity
- Name
- Colorado Department of Health Care Policy and Financingnorm: colorado department of health care policy and financing
- Domain
- hcpf.colorado.gov
Victim entity
- Name
- Colorado Department of Health Care Policy and Financingnorm: colorado department of health care policy and financing
- Domain
- hcpf.colorado.gov
Incident
- Discovered
- Jun 13, 2023
- Materiality determined
- —
- Notification sent
- Feb 19, 2024
- Affected individuals
- Not disclosed
- Data types
- PHIIDENTITY_GOVERNMENTIDENTITY_BASICHEALTH_BASICFINANCIAL
- Attack vector
- Third-Party / Supply Chain
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1195 Supply Chain CompromiseT1041 Exfiltration Over C2 Channel
- Threat actor
- External
- Initial access
- supply_chain
Compliance
- Time to disclose
- 36 weeks(251 days from discovery to filing)
- Compliance flags
- CA 60-day late · 251d
- Discovery-date grounding
- letter-groundedThe discovery date is the detection date narrated in the notification letter — the defensible tier.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Jun 13, 2023→ Notified: Feb 19, 2024251d 60 days (analyst band, pre-2026 discoveries) CA 60-day late
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.