Colorado Department of Health Care Policy and Financing
ent_2adc2dfcae91b9ceaf95e8be
Disclosures
21
State AG · HHS OCR · 8 jurisdictions
Incidents
2
filings grouped by incident
Max affected reported
4,662,668
as filed · State AG OR
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- Colorado Department of Health Care Policy and Financing
- Normalized
- colorado department of health care policy and financing— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- No match
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- hcpf.colorado.gov
Disclosure history (21)newest first
- ⛰️New Hampshire State AGas victim2024-02-20
Supplemental notice from Colorado HCPF regarding a third-party supply chain breach involving IBM's MOVEit Transfer application. Unauthorized access occurred on or about May 28, 2023, affecting PHI and PII of Health First Colorado and CHP+ members. Discovery was confirmed on June 13, 2023. Notices sent to NH residents began August 11, 2023.
- 🦞Maine State AGas victim2024-02-19
The Colorado Department of Health Care Policy & Financing reported a data breach affecting 933 Maine residents whose personal information, including names and Social Security numbers, was compromised. The breach occurred on May 28, 2023, and was discovered on June 13, 2023. The organization offered two years of credit monitoring services through Experian to those affected.
- 🦫Oregon State AGas victim2024-02-19
Colorado Department of Health Care Policy & Financing reported a data breach to the Oregon Attorney General. The breach was reported on 2024-02-19. The breach occurred during 5/28/2023 - 5/31/2023. The breach was discovered on 6/13/2023. 4,662,668 individuals were affected. Notice was sent on 2/19/2024.
- 🍁Vermont State AGas victim2024-02-19
Colorado Department of Health Care Policy & Financing (HCPF) notified consumers of a data breach involving its third-party vendor IBM's use of Progress Software's MOVEit Transfer application. Unauthorized access occurred on or about May 28, 2023, affecting files containing Health First Colorado and CHP+ applicant data, including names, SSNs, and insurance identifiers. HCPF offered two years of credit monitoring via Experian.
- 💎Delaware State AGas victim2024-02-19
Colorado Department of Health Care Policy & Financing (HCPF) issued a supplemental data breach notice regarding a third-party supply chain incident involving IBM and Progress Software's MOVEit Transfer application. Unauthorized access occurred on or about May 28, 2023, affecting files containing names, Social Security numbers, and insurance policy identifiers for Health First Colorado and CHP+ members. HCPF offered two years of credit monitoring via Experian. The filing was submitted to the Delaware Attorney General in February 2024.
- 🐻California State AGas victim2024-02-19
Colorado Department of Health Care Policy & Financing (HCPF) notified residents of a data breach involving Health First Colorado and CHP+ members. An unauthorized actor accessed files on IBM's MOVEit Transfer application (used by HCPF vendor IBM) between May 28-31, 2023. HCPF discovered the access on June 13, 2023. Affected data includes names, SSNs, Medicaid/Medicare IDs, DOB, addresses, and clinical/medical information. HCPF offered 2 years of credit monitoring via Experian. This is a supplemental notice.
- 🦞Maine State AGas victim2023-10-03
The Colorado Department of Health Care Policy & Financing reported a data breach affecting 51 Maine residents. The incident was discovered on June 13, 2023, having occurred on May 28, 2023. The compromised data included names and Social Security numbers. Affected individuals were notified on October 3, 2023, and offered two years of identity theft protection services through Experian.
- 🍁Vermont State AGas victim2023-10-03
Colorado Department of Health Care Policy and Financing (HCPF) notified consumers of a data breach involving its third-party vendor, IBM, which uses Progress Software's MOVEit Transfer application. An unauthorized actor accessed certain HCPF files on or about May 28, 2023, containing names, addresses, phone numbers, SSNs, and financial account information for Health First Colorado and CHP+ members/providers. HCPF offered two years of credit monitoring. No HCPF systems were directly compromised.
- 🐻California State AGas victim2023-10-03
Colorado Department of Health Care Policy & Financing (HCPF) disclosed a data breach involving personal information of Health First Colorado and CHP+ members and providers. The incident occurred on May 28, 2023, when an unauthorized actor accessed files on the MOVEit Transfer application used by third-party vendor IBM. HCPF discovered the issue on May 31, 2023. Affected data included full names, business mailing addresses, business phone numbers, and Social Security numbers (if used as taxpayer ID). No provider portal credentials or financial account information were involved. HCPF offered two years of credit monitoring and identity restoration via Experian.
- ⛰️New Hampshire State AGas victim2023-10-03
The Colorado Department of HealthCare Policy & Financing (HCPF) notified individuals of a breach involving its MOVEit Transfer system, used by third-party vendor IBM. Unauthorized access occurred on or about May 28, 2023, and was discovered by HCPF on June 13, 2023. The incident exposed personal information of Health First Colorado and CHP+ members and providers, including government IDs and financial account data. HCPF offered two years of credit monitoring via Experian. The notification was filed with the New Hampshire Attorney General on October 3, 2023.
- 💎Delaware State AGas victim2023-10-03
Colorado Department of Health Care Policy & Financing (HCPF) disclosed a breach involving its third-party vendor, IBM, which used the Progress Software MOVEit Transfer application. An unauthorized actor accessed HCPF files containing member and provider information (names, addresses, SSNs) on or about May 28, 2023. HCPF offered two years of credit monitoring. The notification was filed in Delaware on October 3, 2023, as a supplemental notice.
- 🌴South Carolina State AGas victim2023-08-14
The Colorado Department of Health Care Policy and Financing (HCPF) reported a breach affecting 4,662,668 individuals. The incident involved the Clop hacking group exploiting a vulnerability in Progress Software's MOVEit Transfer application on May 31, 2023. Personal and health information of Medicaid and state healthcare program participants was compromised.
- 💎Delaware State AGas victim2023-08-11
Colorado Department of Health Care Policy & Financing (HCPF) notified Delaware residents of a data event involving approximately 324 individuals. The incident stemmed from a vulnerability in Progress Software's MOVEit Transfer application, exploited by an unauthorized actor who accessed files managed by third-party vendor IBM. The breach exposed names, Social Security numbers, Medicaid/Medicare IDs, dates of birth, and medical/insurance information. HCPF launched an investigation, engaged forensic review, and provided 24 months of credit monitoring via Experian to affected Delaware residents. The investigation was ongoing as of the notice date of August 11, 2023.
- 🍁Vermont State AGas victim2023-08-11
The Colorado Department of Health Care Policy and Financing (HCPF) disclosed a data breach involving its third-party vendor, IBM, which uses Progress Software's MOVEit Transfer application. An unauthorized actor accessed certain HCPF files on or about May 28, 2023. The incident exposed protected health information (PHI) and personal identifiers (SSN, Medicaid/Medicare IDs, DOB, addresses) of Health First Colorado and CHP+ members. HCPF offered two years of credit monitoring via Experian.
- 🦞Maine State AGas victim2023-08-11
The Colorado Department of Health Care Policy & Financing reported a data breach affecting 1,090 Maine residents. The incident was discovered on June 13, 2023, and occurred on May 28, 2023. The breach exposed individuals' names and Social Security numbers. Affected residents were notified on August 11, 2023, and offered two years of identity theft protection services through Experian.
- COHHS OCRas victim2023-08-11
Colorado Department of Health Care Policy & Financing reported to HHS on 2023-08-11 a Hacking/IT Incident affecting 4,091,794 individuals. Breached information located on Network Server. A business associate's software application exposed PHI including names, DOBs, SSNs, and health records. The entity provided credit monitoring and implemented additional safeguards.
- 🐻California State AGas victim2023-08-11
The Colorado Department of Health Care Policy & Financing (HCPF) notified individuals that their personal and protected health information may have been accessed by an unauthorized actor via a third-party vendor, IBM, which used the MOVEit Transfer application. The breach occurred on May 28, 2023, and was discovered on June 13, 2023. Affected data includes names, SSNs, Medicaid/Medicare IDs, dates of birth, addresses, and clinical information. HCPF is offering two years of credit monitoring.
- ⛰️New Hampshire State AGas victim2023-08-01
Colorado Department of Health Care Policy and Financing (HCPF) notified residents of a breach involving its third-party vendor IBM's MOVEit Transfer application. Unauthorized access occurred on or about May 28, 2023, affecting PHI and PII of Medicaid/CHP+ members. HCPF discovered the incident on June 13, 2023, and began notifying affected individuals on August 11, 2023. Credit monitoring was offered.
- COHHS OCRas victim2015-08-18
Between May 25, 2015 and July 5, 2015, the Governors' Office of Technology (a business associate) sent PHI-containing letters to the wrong Medical Assistance Program clients due to a technical error in their computer system. Affected data included names, addresses, state ID numbers, Medicaid case numbers, employer names, income amounts, Advanced Premium Tax Credit amounts, program approvals/denials, and dates of birth. Up to 3,537 individuals were impacted; 1,622 reported to HHS. Deloitte (subcontractor) fixed the Colorado Benefits Management System software and added mailing QC controls. OCR obtained written corrective-action assurances. Location of breached info: Paper/Films.
- COHHS OCRas victim2014-10-10
On July 30 and September 3, 2014, a business associate of Colorado Department of Health Care Policy & Financing mistakenly sent postcards to approximately 15,380 clients containing viewable PHI, including names, addresses, and references to each client's status as a public assistance client receiving behavioral health care services. Following the breach, the CE and BA ceased postcard communications, implemented new policies and procedures, and conducted privacy training. OCR obtained assurances of corrective action. Breach reported to HHS on 2014-10-10. Breached information located in: Other.
- COHHS OCRas victim2011-08-16
Colorado Department of Health Care Policy and Financing (CO state Health Plan) reported to HHS OCR on 2011-08-16 a Loss affecting 3,589 individuals. Breached information was located on 'Other' media. No business associate was present. No further details are available in the web description.