Philips Respironics
ent_402591067d2b0634da33c004
Disclosures
12
State AG · HHS OCR · 4 jurisdictions
Multi-filing incidents
2
incidents joining 2+ filings here
Max affected reported
457,152
nationwide · HHS OCR PA
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- Philips Respironics
- Normalized
- philips respironics— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- No match
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- None on record
Disclosure history (12)newest first
- Montana State AGas victim2024-06-28
Philips Respironics notified Montana residents that an unauthorized third party exploited a vulnerability in Progress Software's MOVEit Transfer software to access files on a server on May 31, 2023. The extracted files contained patient names, addresses, dates of birth, emails, phone numbers, and insurance policy numbers. Philips Respironics suspended the tool, secured systems, and offered 12 months of credit monitoring.
- Montana State AGas victim2024-06-03
Philips Respironics notified Montana residents of a security incident where an unauthorized third-party exploited a MOVEit Transfer software vulnerability to access patient data on May 31, 2023. The company discovered the incident on June 5, 2023. Extracted files included patient names, addresses, dates of birth, emails, phone numbers, insurance policy numbers, and device serial numbers. Philips Respironics suspended the tool and offered 12 months of credit monitoring via Experian.
- Oregon State AGas victim2024-06-03
Philips Respironics reported a data breach to the Oregon Attorney General. The breach was reported on 2024-06-03. 128,290 individuals were affected.
- Oregon State AGas victim2024-06-03
Philips Respironics, Inc. reported a data breach to the Oregon Attorney General. The breach was reported on 2024-06-03. 104,119 individuals were affected.
- California State AGas victim2024-06-03
Philips Respironics notified patients of a security breach involving Progress Software's MOVEit Transfer software. An unauthorized party exploited a vulnerability in the software to access and extract files containing patient personal information (name, address, DOB, email, phone, insurance policy number) from a Philips server on May 31, 2023. Philips informed healthcare providers on December 20, 2023, suspended the use of MOVEit, and offered one year of complimentary credit monitoring and identity restoration services through Experian.
- Montana State AGas reporting2024-05-15
Forward Healthcare LLC, a provider of therapy data for sleep and respiratory devices, notified Montana residents of a security incident involving Philips Respironics. An unauthorized party exploited a vulnerability in Progress Software's MOVEit Transfer software to access and extract files containing patient personal information (name, address, DOB, email, phone, insurance policy number, patient ID) from a Philips server on May 31, 2023. Philips Respironics discovered the breach on December 20, 2023, suspended the tool, and offered 12 months of credit monitoring.
- Montana State AGas reporting2024-04-29
Lincare Holding Inc. notified Montana residents of a data breach involving MOVEit Transfer software exploited by an unauthorized party. The incident, discovered Dec 21, 2023, involved data extracted on May 31, 2023, including names, addresses, DOBs, and insurance info. Philips Respironics, the vendor, suspended the tool and offered credit monitoring.
- PENNSYLVANIAHHS OCRas victim2024-04-16
Philips Respironics reported to HHS on 2024-04-16 a Hacking/IT Incident affecting 7539 individuals. Breached information located on Network Server. A software application used by the business associate exposed PHI including names, dates of birth, addresses, and treatment information. The BA provided complimentary credit monitoring and implemented additional safeguards.
- PENNSYLVANIAHHS OCRas victim2024-04-16
Philips Respironics reported to HHS on 2024-04-16 a Hacking/IT Incident affecting 1338 individuals. Breached information located on Network Server. A software application exposed PHI including names, DOB, addresses, and treatment info. BA provided credit monitoring and implemented safeguards.
- PENNSYLVANIAHHS OCRas victim2024-04-16
Philips Respironics reported to HHS on 2024-04-16 a Hacking/IT Incident affecting 5,576 individuals. Breached information located on Network Server. A software application exposed PHI including names, dates of birth, addresses, and treatment information.
- PENNSYLVANIAHHS OCRas victim2024-03-15
Philips Respironics reported to HHS on 2024-03-15 a Hacking/IT Incident affecting 1,125 individuals. Breached information located on Network Server. A software application exposed PHI including names, dates of birth, addresses, and treatment information. The BA provided credit monitoring and implemented safeguards.
- PENNSYLVANIAHHS OCRas victim2024-03-04
Philips Respironics, acting as a business associate, reported that a software application used by its own business associate exposed protected health information of 457,152 individuals. Exposed data included names, dates of birth, addresses, and treatment information. The company notified HHS, affected individuals, and the media, posted substitute notice, offered complimentary credit monitoring, and implemented additional administrative and technical safeguards.