HackingStolen CredentialsCapture Stored DataSupply Chain (3P Vendor)Data ExfiltratedCustomer Data InvolvedBusiness Associate (HIPAA)PHIIDENTITY_BASICIDENTITY_GOVERNMENTMediumContained
Colorado Department of Health Care Policy and Financing
bd_a3f112b2ddad6d7a · schema v1 · pii pii-v1
Full breach record for Colorado Department of Health Care Policy and Financing →Supplemental notice from Colorado HCPF regarding a third-party supply chain breach involving IBM's MOVEit Transfer application. Unauthorized access occurred on or about May 28, 2023, affecting PHI and PII of Health First Colorado and CHP+ members. Discovery was confirmed on June 13, 2023. Notices sent to NH residents began August 11, 2023.
This filing is one of 6 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (5) · sorted by filing gap
- bd_276c06374e7a08fcMaine State AGfiled 2024-02-19(1d gap)Candidate
- bd_5167088d02685ddfOregon State AGfiled 2024-02-19(1d gap)Verified
- bd_5ebd8c098e6a6f5fVermont State AGfiled 2024-02-19(1d gap)Verified
- bd_6f832e7ad75b6a0cDelaware State AGfiled 2024-02-19(1d gap)Verified
Show 1 more filing ↓Show fewer ↑up to 1d gap
- bd_90735d0659ea8b49California State AGfiled 2024-02-19(1d gap)Verified
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/colorado-department-health-care-policy-financing-20240220.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Feb 20, 2024
- Raw hash
- 98e9b146b7a3837cb9a70b2199ff5106362760121f8e910edda9311b489445e7
Reporting entity
- Name
- Colorado Department of Health Care Policy and Financingnorm: colorado department of health care policy and financing
- Domain
- hcpf.colorado.gov
Victim entity
- Name
- Colorado Department of Health Care Policy and Financingnorm: colorado department of health care policy and financing
- Domain
- hcpf.colorado.gov
Incident
- Discovered
- Jun 13, 2023
- Materiality determined
- Jan 17, 2024
- Notification sent
- Aug 11, 2023
- Affected individuals
- 410
- Data types
- PHIIDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Third-Party / Supply Chain
- MITRE ATT&CK
- T1195 Supply Chain CompromiseT1119 Automated Collection
- Threat actor
- ExternalFinancial
- Regulator citations
- Pursuant to state law and the Health Insurance Portability and Accountability Act (HIPAA), we are required to give you notice of this breach
- Third party
- via IBM
- Initial access
- supply_chain
Compliance
- Time to disclose
- 36 weeks(252 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.