HackingStolen CredentialsSupply Chain (3P Vendor)Customer Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASICPHIMediumContained
Colorado Department of Health Care Policy and Financing
bd_a26eef2000fb6b18 · schema v1 · pii pii-v1
Full breach record for Colorado Department of Health Care Policy and Financing →The Colorado Department of Health Care Policy and Financing (HCPF) disclosed a data breach involving its third-party vendor, IBM, which uses Progress Software's MOVEit Transfer application. An unauthorized actor accessed certain HCPF files on or about May 28, 2023. The incident exposed protected health information (PHI) and personal identifiers (SSN, Medicaid/Medicare IDs, DOB, addresses) of Health First Colorado and CHP+ members. HCPF offered two years of credit monitoring via Experian.
Vermont clock⏱ VT AG >14 bday8 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 11 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (10) · sorted by filing gap
- bd_651d3456f2cd7362Delaware State AGfiled 2023-08-11Verified
- bd_c8f2a8126cd41b6bMaine State AGfiled 2023-08-11Verified
- bd_cb8d9ebf14bedf02HHS OCRfiled 2023-08-11Verified
- bd_eb9bc01f2d03027bCalifornia State AGfiled 2023-08-11Verified
Show 6 more filings ↓Show fewer ↑up to 53d gap
- bd_b131d9519be28ad6South Carolina State AGClopfiled 2023-08-14(3d gap)Verified
- bd_b918db91ace38228New Hampshire State AGfiled 2023-08-01(10d gap)Verified
- bd_4107138ac65485a0Maine State AGfiled 2023-10-03(53d gap)Verified
- bd_501ce56cdd46ef11Vermont State AGfiled 2023-10-03(53d gap)Verified
- bd_a36dbca8821d58c1California State AGfiled 2023-10-03(53d gap)Verified
- bd_bc4561bd8522923fDelaware State AGfiled 2023-10-03(53d gap)Verified
Source provenance
- Source URL
- https://ago.vermont.gov/document/2023-08-11-colorado-department-health-care-policy-financing-progress-software-moveit-data-breach
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Aug 11, 2023
- Raw hash
- 95172a2328e3739728f7581ffd89f7066efca5da413f283b25248605e2b6ed69
Reporting entity
- Name
- Colorado Department of Health Care Policy and Financingnorm: colorado department of health care policy and financing
- Domain
- hcpf.colorado.gov
Victim entity
- Name
- Colorado Department of Health Care Policy and Financingnorm: colorado department of health care policy and financing
- Domain
- hcpf.colorado.gov
Incident
- Discovered
- Jun 13, 2023
- Materiality determined
- —
- Notification sent
- Aug 11, 2023
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASICPHI
- Attack vector
- Third-Party / Supply Chain
- MITRE ATT&CK
- T1195 Supply Chain CompromiseT1078 Valid Accounts
- Threat actor
- ExternalFinancial
- Third party
- via IBM
- Initial access
- supply_chain
Compliance
- Time to disclose
- 8 weeks(59 days from discovery to filing)
- Compliance flags
- VT AG >14 bday
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.