HackingVulnerability ExploitData ExfiltratedCustomer Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASICHighContained
Philips Respironics International Colorado, Inc. (RICO)
bd_e6273ed93643e09b · schema v1 · pii pii-v1
Full breach record for Philips Respironics International Colorado, Inc. (RICO) →Phillips Respironics International Colorado, Inc. disclosed a data breach involving the MOVEit Transfer software vulnerability. An unauthorized party exploited the vulnerability on May 31, 2023, to exfiltrate patient data including names, addresses, DOBs, and device usage records. The incident affected 30,002 Texas residents. The company suspended use of the tool and offered one year of credit monitoring.
This filing is one of 3 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (2) · sorted by filing gap
- bd_58678c09f4528217Delaware State AGfiled 2024-01-11Candidate
- bd_5f4e360acb510b9fWashington State AGfiled 2024-01-22(11d gap)Verified
Source provenance
- Source URL
- https://attorneygeneral.delaware.gov/wp-content/uploads/sites/50/2024/01/Patient-RICO-Notice.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jan 11, 2024
- Raw hash
- 8ff09d7ffcb0d4150f1317733a96192e23f368f8e7eb005e9239f5af1e375e62
Reporting entity
- Name
- Philips Respironics International Colorado, Inc. (RICO)norm: philips respironics international colorado inc rico
Victim entity
- Name
- Philips Respironics International Colorado, Inc. (RICO)norm: philips respironics international colorado inc rico
Incident
- Discovered
- Jun 5, 2023
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- 30,002
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing Application
- Threat actor
- ExternalFinancial
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 31 weeks(220 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.