HackingStolen CredentialsCapture Stored DataSupply Chain (3P Vendor)Data ExfiltratedCustomer Data InvolvedBusiness Associate (HIPAA)PHIIDENTITY_BASICIDENTITY_GOVERNMENTMediumContained
Colorado Department of Health Care Policy and Financing
bd_b918db91ace38228 · schema v1 · pii pii-v1
Full breach record for Colorado Department of Health Care Policy and Financing →Colorado Department of Health Care Policy and Financing (HCPF) notified residents of a breach involving its third-party vendor IBM's MOVEit Transfer application. Unauthorized access occurred on or about May 28, 2023, affecting PHI and PII of Medicaid/CHP+ members. HCPF discovered the incident on June 13, 2023, and began notifying affected individuals on August 11, 2023. Credit monitoring was offered.
This filing is one of 11 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (10) · sorted by filing gap
- bd_651d3456f2cd7362Delaware State AGfiled 2023-08-11(10d gap)Verified
- bd_a26eef2000fb6b18Vermont State AGfiled 2023-08-11(10d gap)Verified
- bd_c8f2a8126cd41b6bMaine State AGfiled 2023-08-11(10d gap)Verified
- bd_cb8d9ebf14bedf02HHS OCRfiled 2023-08-11(10d gap)Verified
Show 6 more filings ↓Show fewer ↑up to 63d gap
- bd_eb9bc01f2d03027bCalifornia State AGfiled 2023-08-11(10d gap)Verified
- bd_b131d9519be28ad6South Carolina State AGClopfiled 2023-08-14(13d gap)Verified
- bd_4107138ac65485a0Maine State AGfiled 2023-10-03(63d gap)Verified
- bd_501ce56cdd46ef11Vermont State AGfiled 2023-10-03(63d gap)Verified
- bd_a36dbca8821d58c1California State AGfiled 2023-10-03(63d gap)Verified
- bd_bc4561bd8522923fDelaware State AGfiled 2023-10-03(63d gap)Verified
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/colorado-department-health-care-policy-financing-20230801.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Aug 1, 2023
- Raw hash
- cc24f02fbcbe1abb0b195414f8ccc8854668ce454e81962a8fdd603af2f5d53c
Reporting entity
- Name
- Colorado Department of Health Care Policy and Financingnorm: colorado department of health care policy and financing
- Domain
- hcpf.colorado.gov
Victim entity
- Name
- Colorado Department of Health Care Policy and Financingnorm: colorado department of health care policy and financing
- Domain
- hcpf.colorado.gov
Incident
- Discovered
- Jun 13, 2023
- Materiality determined
- —
- Notification sent
- Aug 11, 2023
- Affected individuals
- 726
- Data types
- PHIIDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Third-Party / Supply Chain
- MITRE ATT&CK
- T1195 Supply Chain CompromiseT1041 Exfiltration Over C2 Channel
- Threat actor
- ExternalFinancial
- Regulator citations
- Notified the U.S. Department of Health and Human ServicesProviding written notice of this incident to relevant state regulators
- Third party
- via IBM
- Initial access
- supply_chain
Compliance
- Time to disclose
- 7 weeks(49 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.