Sleep Data Holdings, LLC
bd_ac9f26db9a632fa2 · schema v1 · pii pii-v1
Full breach record for Sleep Data Holdings, LLC →Sleep Data Holdings, LLC notified California residents that their personal information may have been accessed due to a vulnerability in Progress Software’s MOVEit Transfer software, used by Philips Respironics to exchange therapy data. An unauthorized party exploited this vulnerability on May 31, 2023, extracting files containing patient names, addresses, dates of birth, emails, phone numbers, insurance policy numbers, and device serial numbers. Philips Respironics informed Sleep Data Holdings on December 20, 2023. The company suspended MOVEit use and is offering one year of complimentary identity monitoring through Experian.
J jump to incidentP pin to compareR raw source
Incident timeline
May 31, 2023
Begins
Dec 20, 2023
Discovered
Apr 29, 2024
Filed
vs. sector median
+8 wks slower
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.