Nuance Communications, Inc
bd_b80d8c8f8a2bace4 · schema v1 · pii pii-v1
Full breach record for Nuance Communications, Inc →Nuance Communications, Inc. disclosed a security incident involving its third-party vendor, Progress Software Corporation's MOVEit Transfer software. An unauthorized third party exploited a previously unknown vulnerability (0-day) in the software between May 28-29, 2023, to exfiltrate data. Nuance discovered the incident on May 31, 2023, secured its systems, and notified law enforcement. The affected data included patient names, DOB, medical record numbers, gender, and radiology study details for healthcare provider customers. Nuance notified affected individuals on August 1, 2023. This is a Delaware state AG breach notification.
Linked disclosures
Why this link?Regulatory filings (6) · sorted by filing gap
- bd_119ca48980839f9bDelaware State AGfiled 2023-09-18Verified
- bd_61e841c1c6509034Oregon State AGfiled 2023-09-19(1d gap)Verified
- bd_2d18f75acad25ac9Maine State AGfiled 2023-09-15(3d gap)Candidate
- bd_42ba23005cabceb8New Hampshire State AGfiled 2023-09-15(3d gap)Verified
Show 2 more filings ↓Show fewer ↑up to 3d gap
- bd_829cc01dc8d0b732California State AGfiled 2023-09-15(3d gap)Verified
- bd_f82949cd77b8e1acMontana State AGfiled 2023-09-15(3d gap)Verified
Source provenance
- Source URL
- https://attorneygeneral.delaware.gov/wp-content/uploads/sites/50/2023/09/Nuance-Notice-Template-gen.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Sep 18, 2023
- Raw hash
- d141a18c51ffc2067c7f130510684dcb8c3a38149e1cb70dc8b9d5ae0523f508
Reporting entity
- Name
- Nuance Communications, Incnorm: nuance communications
Victim entity
- Name
- Nuance Communications, Incnorm: nuance communications
Incident
- Discovered
- May 31, 2023
- Materiality determined
- —
- Notification sent
- Aug 1, 2023
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASIC
- Attack vector
- Third-Party / Supply Chain
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1195 Supply Chain Compromise
- Threat actor
- External
- Regulator citations
- Notified law enforcement authorities
- Third party
- via Progress Software Corporation
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 16 weeks(110 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.