HackingVulnerability ExploitStolen CredentialsSupply Chain (3P Vendor)Data ExfiltratedCustomer Data InvolvedDownstream VictimsPHIIDENTITY_GOVERNMENTIDENTITY_BASICHEALTH_BASICFINANCIALMediumContained
Colorado Department of Health Care Policy and Financing
bd_eb9bc01f2d03027b · schema v1 · pii pii-v1
Full breach record for Colorado Department of Health Care Policy and Financing →The Colorado Department of Health Care Policy & Financing (HCPF) notified individuals that their personal and protected health information may have been accessed by an unauthorized actor via a third-party vendor, IBM, which used the MOVEit Transfer application. The breach occurred on May 28, 2023, and was discovered on June 13, 2023. Affected data includes names, SSNs, Medicaid/Medicare IDs, dates of birth, addresses, and clinical information. HCPF is offering two years of credit monitoring.
California clockDiscovered Jun 13, 2023 → Notified Aug 11, 202359d ✓ CA 60-day OK8 weeks discovery → filing
This filing is one of 11 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (10) · sorted by filing gap
- bd_651d3456f2cd7362Delaware State AGfiled 2023-08-11Verified
- bd_a26eef2000fb6b18Vermont State AGfiled 2023-08-11Verified
- bd_c8f2a8126cd41b6bMaine State AGfiled 2023-08-11Verified
- bd_cb8d9ebf14bedf02HHS OCRfiled 2023-08-11Verified
Show 6 more filings ↓Show fewer ↑up to 53d gap
- bd_b131d9519be28ad6South Carolina State AGClopfiled 2023-08-14(3d gap)Verified
- bd_b918db91ace38228New Hampshire State AGfiled 2023-08-01(10d gap)Verified
- bd_4107138ac65485a0Maine State AGfiled 2023-10-03(53d gap)Verified
- bd_501ce56cdd46ef11Vermont State AGfiled 2023-10-03(53d gap)Verified
- bd_a36dbca8821d58c1California State AGfiled 2023-10-03(53d gap)Verified
- bd_bc4561bd8522923fDelaware State AGfiled 2023-10-03(53d gap)Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-571694
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Aug 11, 2023
- Raw hash
- 5443c6bc9b131a179c5196817163be08b7a2c517b321893425ffab4f41f7fc17
Reporting entity
- Name
- Colorado Department of Health Care Policy and Financingnorm: colorado department of health care policy and financing
- Domain
- hcpf.colorado.gov
Victim entity
- Name
- Colorado Department of Health Care Policy and Financingnorm: colorado department of health care policy and financing
- Domain
- hcpf.colorado.gov
Incident
- Discovered
- Jun 13, 2023
- Materiality determined
- —
- Notification sent
- Aug 11, 2023
- Affected individuals
- Not disclosed
- Data types
- PHIIDENTITY_GOVERNMENTIDENTITY_BASICHEALTH_BASICFINANCIAL
- Attack vector
- Third-Party / Supply Chain
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1195 Supply Chain CompromiseT1041 Exfiltration Over C2 Channel
- Threat actor
- External
- Initial access
- supply_chain
Compliance
- Time to disclose
- 8 weeks(59 days from discovery to filing)
- Compliance flags
- CA 60-day OK · 59d
- Discovery-date grounding
- letter-groundedThe discovery date is the detection date narrated in the notification letter — the defensible tier.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Jun 13, 2023→ Notified: Aug 11, 202359d 60 days (analyst band, pre-2026 discoveries) CA 60-day OK
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.