HackingVulnerability ExploitStolen CredentialsSupply Chain (3P Vendor)Data ExfiltratedCustomer Data InvolvedIDENTITY_BASICFINANCIAL_ACCOUNTLowContained
Philips Respironics
bd_ee7b44e45d9625e8 · schema v1 · pii pii-v1
Full breach record for Philips Respironics →Philips Respironics notified patients of a security breach involving Progress Software's MOVEit Transfer software. An unauthorized party exploited a vulnerability in the software to access and extract files containing patient personal information (name, address, DOB, email, phone, insurance policy number) from a Philips server on May 31, 2023. Philips informed healthcare providers on December 20, 2023, suspended the use of MOVEit, and offered one year of complimentary credit monitoring and identity restoration services through Experian.
This filing is one of 5 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (4) · sorted by filing gap
- bd_2d1ef38c4b27983dMontana State AGfiled 2024-06-03Candidate
- bd_46ad7cf5b7422ef0Oregon State AGfiled 2024-06-03Verified
- bd_58fd842d7618d4cdOregon State AGfiled 2024-06-03Verified
- bd_f309b71340f577b8Montana State AGfiled 2024-06-28(25d gap)Verified by operator
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-586333
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jun 3, 2024
- Raw hash
- 63c45793d676c83751fc5bf323ed90991874ad855227dd9ba23a34bbb1652335
Reporting entity
- Name
- Philips Respironicsnorm: philips respironics
Victim entity
- Name
- Philips Respironicsnorm: philips respironics
Incident
- Discovered
- Dec 20, 2023
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICFINANCIAL_ACCOUNT
- Attack vector
- Third-Party / Supply Chain
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1195 Supply Chain CompromiseT1041 Exfiltration Over C2 Channel
- Threat actor
- External
- Third party
- via Progress Software
- Initial access
- supply_chain
Compliance
- Time to disclose
- 24 weeks(166 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.