Sleep Data Holdings, LLC
bd_ac9f26db9a632fa2 · schema v1 · pii pii-v1
Full breach record for Sleep Data Holdings, LLC →Sleep Data Holdings, LLC notified California residents that their personal information may have been accessed due to a vulnerability in Progress Software’s MOVEit Transfer software, used by Philips Respironics to exchange therapy data. An unauthorized party exploited this vulnerability on May 31, 2023, extracting files containing patient names, addresses, dates of birth, emails, phone numbers, insurance policy numbers, and device serial numbers. Philips Respironics informed Sleep Data Holdings on December 20, 2023. The company suspended MOVEit use and is offering one year of complimentary identity monitoring through Experian.
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-584606
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Apr 29, 2024
- Raw hash
- 175145193b2b4dead751ff4ff67f523099ffd10e910cb1f2f5f31be87dca9dd3
Reporting entity
- Name
- Sleep Foundationnorm: sleep foundation
- Domain
- sleepfoundation.org
Victim entity
- Name
- Sleep Data Holdings, LLCnorm: sleep data
Incident
- Discovered
- Dec 20, 2023
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICHEALTH_BASICPII
- Attack vector
- Third-Party / Supply Chain
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1195 Supply Chain CompromiseT1041 Exfiltration Over C2 Channel
- Threat actor
- External
- Third party
- via Progress Software
- Initial access
- supply_chain
Compliance
- Time to disclose
- 19 weeks(131 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.