AccidentalMisconfigurationCustomer Data InvolvedDelayed DiscoveryPIIIDENTITY_BASICLowContained
Cohere
bd_b712e6035cf93a5d · schema v1 · pii pii-v1
Full breach record for Cohere →Cohere Health, Inc. notified the New Hampshire Attorney General on August 11, 2023, of a misconfiguration incident where two files containing personal information of Humana insureds were inadvertently set for public access on its cloud provider's platform. Cohere Health became aware of the issue on June 15, 2023. The files were accessible from July 2021 until discovery. One New Hampshire resident was affected. Cohere Health secured the files, launched an investigation, and is offering credit monitoring services.
Tracked as a single-filing incident — the only disclosure on record for this event so far.Confirmed1 affectedView incident
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/cohere-health-20230811.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Aug 11, 2023
- Raw hash
- ae80ecaa0dbfcbdaf6b8acd424ff9b00a0b48ad14fb1b07aff32d9a29862d8b8
Reporting entity
- Name
- Coherenorm: cohere
- Domain
- cohere.com
Victim entity
- Name
- Coherenorm: cohere
- Domain
- cohere.com
Incident
- Discovered
- Jun 15, 2023
- Materiality determined
- —
- Notification sent
- Aug 11, 2023
- Affected individuals
- 1
- Data types
- PIIIDENTITY_BASIC
- Attack vector
- Misconfiguration
- MITRE ATT&CK
- T1190 Exploit Public-Facing Application
- Threat actor
- ExternalFinancial
- Regulator citations
- Notified New Hampshire Attorney General
Compliance
- Time to disclose
- 8 weeks(57 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.