Nuance Communications, Inc
ent_019e2172c76ac85b029a0094b0176711
Nuance Communications is a technology company specializing in speech recognition and artificial intelligence software, including the Dragon speech recognition platform. The company was acquired by Microsoft in 2022 and operates as part of the Microsoft organization.
AI-summarized from indexed web sources · Burlington, Massachusetts · 2026-08-04 · source
Disclosures
15
State AG · HHS OCR · Leak Site · 10 jurisdictions
Multi-filing incidents
2
incidents joining 2+ filings here
Max affected reported
1,225,054
nationwide · State AG OR
Leak-site claims
2
unverified actor claims
Identity resolution
- Canonical name
- Nuance Communications, Inc
- Normalized
- nuance communications— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- 549300K2IJ84JKLDX085
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- nuance.com
Disclosure history (15)newest first
- Oregon State AGas victim2023-09-19
Nuance Communications Inc reported a data breach to the Oregon Attorney General. The breach was reported on 2023-09-19. The breach occurred during 5/28/2023 - 5/29/2023. The breach was discovered on 7/10/2023. 1,225,054 individuals were affected. Notice was sent on 9/18/2023.
- Delaware State AGas victim2023-09-18
Nuance Communications, Inc. disclosed a security incident involving its third-party vendor, Progress Software's MOVEit Transfer software. An unauthorized third party exploited a previously unknown vulnerability (zero-day) between May 28-29, 2023, to exfiltrate data. Nuance confirmed the breach on July 11, 2023, and notified affected individuals starting August 1, 2023. Affected data included names, dates of birth, medical record numbers, gender, and radiology study details. Nuance secured servers, engaged cybersecurity experts, and notified law enforcement.
- Maine State AGas victim2023-09-15
Nuance Communications, Inc. disclosed a data breach affecting one Maine resident, which occurred from May 28 to May 29, 2023. The breach was discovered on July 10, 2023, and was attributed to a zero-day vulnerability. The compromised data includes Social Security Numbers. Affected individuals were notified on September 22, 2023, and offered a 24-month membership to Equifax’s Credit Watch Gold for identity theft protection.
- New Hampshire State AGas victim2023-09-15
Nuance Communications, Inc. notified the New Hampshire Attorney General of a security incident involving a zero-day vulnerability in Progress Software's MOVEit Transfer application. The attack occurred on May 28-29, 2023, and was discovered by Nuance on May 31, 2023. The breach impacted approximately 1,259 New Hampshire residents, exposing medical and healthcare information. Nuance took immediate response actions, including securing servers, engaging Microsoft and legal counsel, and notifying the FBI. Remediation included offering credit monitoring services to affected individuals.
- California State AGas victim2023-09-15
Nuance Communications, Inc. disclosed a data breach resulting from a previously unknown vulnerability in MOVEit Transfer software provided by third-party vendor Progress Software Corporation. An unauthorized third party exfiltrated data between May 28 and May 29, 2023. Nuance was notified of the vulnerability on May 31, 2023. Affected data included names, dates of birth, medical record numbers, gender, and details about radiology studies (provider, facility, date of service, study identifiers, and study reports). Social Security numbers and financial information were not involved. Nuance secured systems, engaged forensic experts, notified law enforcement, and sent notices to affected individuals starting August 1, 2023.
- Washington State AGas victim2023-09-15
Nuance Communications reported a cyberattack on May 28-29, 2023, exploiting a zero-day vulnerability in Progress Software's MOVEit Transfer application. The incident impacted approximately 7,993 Washington residents, exposing names and radiology study details. Nuance secured servers, engaged Microsoft and legal counsel, notified the FBI and HHS OCR, and began notifying individuals on September 18, 2023.
- MASSACHUSETTSHHS OCRas victim2023-09-15
Nuance Communications, Inc. reported to HHS on 2023-09-15 a Hacking/IT Incident affecting 1,225,054 individuals. Breached information located on Network Server. The cyber-attack compromised PHI including names, addresses, DOBs, diagnoses, medications, and SSNs.
- Montana State AGas victim2023-09-15
Nuance Communications, Inc. disclosed a third-party vendor breach involving Progress Software's MOVEit Transfer software. An unauthorized party exploited a previously unknown vulnerability to exfiltrate data between May 28-29, 2023. Nuance was notified by Progress on May 31, 2023. Affected data included names, radiology study details, dates of service, and potentially medical record numbers. No SSNs or financial data were involved. Nuance secured systems, engaged experts, and notified law enforcement.
- GLOBALLeak Siteas victim2023-06-16
Nuance - Conversational AI for Healthcare and Customer Engagement - Nuance
- Illinois State AGas victim2023-01-01
NUANCE COMMUNICATIONS, INC filed a data-breach notice with the Illinois Attorney General during 2023 (case 23-640). The register records the breach as discovered on May 28, 2023. Additional entities named: MOVEIT. Illinois does not publish the number of people affected — 815 ILCS 530/10 permits the Attorney General to publish only the entity name, the types of personal information and the date range.
- Illinois State AGas victim2023-01-01
NUANCE COMMUNICATIONS, INC filed a data-breach notice with the Illinois Attorney General during 2023 (case 23-680). The register records the breach as discovered on May 28, 2023. Additional entities named: MOVEIT. Illinois does not publish the number of people affected — 815 ILCS 530/10 permits the Attorney General to publish only the entity name, the types of personal information and the date range.
- MASSACHUSETTSHHS OCRas victim2022-11-18
Nuance Communications, Inc. reported to HHS on 2022-11-18 an Unauthorized Access/Disclosure affecting 4,830 individuals. Breached information located on Electronic Medical Record. An employee impermissibly accessed PHI including names, addresses, medications, diagnoses, lab results, driver’s license numbers, dates of birth, financial information, and claims information.
- GLOBALLeak Siteas victim2022-06-23
nuance.com
- New Hampshire State AGas reporting2015-10-28
Nuance Communications notified the NH AG that Excellus Blue Cross, a downstream subcontractor, suffered a cyber-attack starting August 5, 2015. 2 NH residents were impacted. Data included PII, SSN, and PHI. Nuance emailed participants on Oct 19, 2015.
- New Hampshire State AGas reporting2015-05-04
Premera, Inc., a downstream subcontractor to BCBSMA, suffered a cyber-attack starting May 5, 2014, discovered Jan 9, 2015. Nuance Communications, Inc. reports 717 impacted plan participants, including 1 in NH. Data accessed included PII, SSN, PHI, and financial data. Notices sent April 2015.
Supply-chain cascadesreviewed and confirmed
- Nuance Communications, Inc’s filing is one of at least 97 in the Progress Software Corporation supply-chain incident (2023).