Colorado Department of Health Care Policy and Financing
bd_a36dbca8821d58c1 · schema v1 · pii pii-v1
Full breach record for Colorado Department of Health Care Policy and Financing →Colorado Department of Health Care Policy & Financing (HCPF) disclosed a data breach involving personal information of Health First Colorado and CHP+ members and providers. The incident occurred on May 28, 2023, when an unauthorized actor accessed files on the MOVEit Transfer application used by third-party vendor IBM. HCPF discovered the issue on May 31, 2023. Affected data included full names, business mailing addresses, business phone numbers, and Social Security numbers (if used as taxpayer ID). No provider portal credentials or financial account information were involved. HCPF offered two years of credit monitoring and identity restoration via Experian.
Linked disclosures
Why this link?Regulatory filings (10) · sorted by filing gap
- bd_4107138ac65485a0Maine State AGfiled 2023-10-03Verified
- bd_501ce56cdd46ef11Vermont State AGfiled 2023-10-03Verified
- bd_bc4561bd8522923fDelaware State AGfiled 2023-10-03Verified
- bd_b131d9519be28ad6South Carolina State AGClopfiled 2023-08-14(50d gap)Verified
Show 6 more filings ↓Show fewer ↑up to 63d gap
- bd_651d3456f2cd7362Delaware State AGfiled 2023-08-11(53d gap)Verified
- bd_a26eef2000fb6b18Vermont State AGfiled 2023-08-11(53d gap)Verified
- bd_c8f2a8126cd41b6bMaine State AGfiled 2023-08-11(53d gap)Verified
- bd_cb8d9ebf14bedf02HHS OCRfiled 2023-08-11(53d gap)Verified
- bd_eb9bc01f2d03027bCalifornia State AGfiled 2023-08-11(53d gap)Verified
- bd_b918db91ace38228New Hampshire State AGfiled 2023-08-01(63d gap)Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-574615
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Oct 3, 2023
- Raw hash
- 737c2a7599f71083a300eab189e30a2789f43dbf1d8289f5806eaeabdce75451
Reporting entity
- Name
- Colorado Department of Health Care Policy and Financingnorm: colorado department of health care policy and financing
- Domain
- hcpf.colorado.gov
Victim entity
- Name
- Colorado Department of Health Care Policy and Financingnorm: colorado department of health care policy and financing
- Domain
- hcpf.colorado.gov
Incident
- Discovered
- May 31, 2023
- Materiality determined
- —
- Notification sent
- Oct 3, 2023
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTPHI
- Attack vector
- Third-Party / Supply Chain
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1195 Supply Chain Compromise
- Threat actor
- External
- Initial access
- supply_chain
Compliance
- Time to disclose
- 18 weeks(125 days from discovery to filing)
- Compliance flags
- CA 60-day late · 125d
- Discovery-date grounding
- letter-groundedThe discovery date is the detection date narrated in the notification letter — the defensible tier.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: May 31, 2023→ Notified: Oct 3, 2023125d 60 days (analyst band, pre-2026 discoveries) CA 60-day late
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.