Clustered 11 filings across 7 jurisdictions · filing window Aug 1, 2023 → Oct 3, 2023. View entity profile → Other incidents for this victim →
incident inc_046df6a8bc49460c · merge_method deterministic · confidence 100%
Discovered → first regulatory filing
Range of discovered_at dates across filings
Time between earliest and latest filing
Not recorded for this incident
Leak precedence · Materiality delta · SEC filing delay — no leak-site claim in this cluster; no SEC 8-K in this cluster.
Identity (basic) · Government ID · Health (basic)
CA CO DE ME NH SC VT
HHS OCR · State AG
per-filing reported counts
State AGs report only their own residents; bars show per-filing counts.
Earliest sighting first · deep chronology in Litigation Timeline
11 filings across 7 jurisdictions · Aug 1, 2023 – Oct 3, 2023 · 3 milestones
May 28, 2023
When the intrusion reportedly occurred, per the linked filings
May 31, 2023
Reported by DELAWARE AG, SOUTH CAROLINA AG, CALIFORNIA AG filings
Jun 13, 2023
Reported by NEW HAMPSHIRE AG, CALIFORNIA AG, VERMONT AG, MAINE AG filings
Colorado Department of Health Care Policy & Financing reported to HHS on 2023-08-11 a Hacking/IT Incident affecting 4,091,794 individuals. Breached information located on Network Server. A business associate's software application exposed PHI including names, DOBs, SSNs, and health records. The entity provided credit monitoring and implemented additional safeguards.
Affected (this filing): 4,091,794
The Colorado Department of Health Care Policy & Financing (HCPF) notified individuals that their personal and protected health information may have been accessed by an unauthorized actor via a third-party vendor, IBM, which used the MOVEit Transfer application. The breach occurred on May 28, 2023, and was discovered on June 13, 2023. Affected data includes names, SSNs, Medicaid/Medicare IDs, dates of birth, addresses, and clinical information. HCPF is offering two years of credit monitoring.
The Colorado Department of Health Care Policy and Financing (HCPF) reported a breach affecting 4,662,668 individuals. The incident involved the Clop hacking group exploiting a vulnerability in Progress Software's MOVEit Transfer application on May 31, 2023. Personal and health information of Medicaid and state healthcare program participants was compromised.
Affected (this filing): 4,662,668
About this clustering
DisclosureLens links filings into incidents through layered matchers: deterministic rules (same source document, multistate filings of one breach, tight-window same-victim pairs), a weighted-similarity scorer for cross-source candidates, and an operator review queue for everything uncertain. Each link records its own method and confidence — shown per filing in the timeline below. The system defaults to NOT merging when uncertain, because a false merge (collapsing two unrelated breaches) is more harmful than a false split (showing related filings separately); uncertain pairs route to human review instead of auto-merging. Filing summaries shown in the timeline are AI-generated extracts — verify each against its linked source.
Colorado Department of Health Care Policy and Financing (HCPF) notified residents of a breach involving its third-party vendor IBM's MOVEit Transfer application. Unauthorized access occurred on or about May 28, 2023, affecting PHI and PII of Medicaid/CHP+ members. HCPF discovered the incident on June 13, 2023, and began notifying affected individuals on August 11, 2023. Credit monitoring was offered.
Affected (this filing): 726
Colorado Department of Health Care Policy & Financing (HCPF) notified Delaware residents of a data event involving approximately 324 individuals. The incident stemmed from a vulnerability in Progress Software's MOVEit Transfer application, exploited by an unauthorized actor who accessed files managed by third-party vendor IBM. The breach exposed names, Social Security numbers, Medicaid/Medicare IDs, dates of birth, and medical/insurance information. HCPF launched an investigation, engaged forensic review, and provided 24 months of credit monitoring via Experian to affected Delaware residents. The investigation was ongoing as of the notice date of August 11, 2023.
Affected (this filing): 324
The Colorado Department of Health Care Policy and Financing (HCPF) disclosed a data breach involving its third-party vendor, IBM, which uses Progress Software's MOVEit Transfer application. An unauthorized actor accessed certain HCPF files on or about May 28, 2023. The incident exposed protected health information (PHI) and personal identifiers (SSN, Medicaid/Medicare IDs, DOB, addresses) of Health First Colorado and CHP+ members. HCPF offered two years of credit monitoring via Experian.
The Colorado Department of Health Care Policy & Financing reported a data breach affecting 1,090 Maine residents. The incident was discovered on June 13, 2023, and occurred on May 28, 2023. The breach exposed individuals' names and Social Security numbers. Affected residents were notified on August 11, 2023, and offered two years of identity theft protection services through Experian.
Affected (this filing): 1,090
The Colorado Department of Health Care Policy & Financing reported a data breach affecting 51 Maine residents. The incident was discovered on June 13, 2023, having occurred on May 28, 2023. The compromised data included names and Social Security numbers. Affected individuals were notified on October 3, 2023, and offered two years of identity theft protection services through Experian.
Affected (this filing): 51
Colorado Department of Health Care Policy and Financing (HCPF) notified consumers of a data breach involving its third-party vendor, IBM, which uses Progress Software's MOVEit Transfer application. An unauthorized actor accessed certain HCPF files on or about May 28, 2023, containing names, addresses, phone numbers, SSNs, and financial account information for Health First Colorado and CHP+ members/providers. HCPF offered two years of credit monitoring. No HCPF systems were directly compromised.
Colorado Department of Health Care Policy & Financing (HCPF) disclosed a data breach involving personal information of Health First Colorado and CHP+ members and providers. The incident occurred on May 28, 2023, when an unauthorized actor accessed files on the MOVEit Transfer application used by third-party vendor IBM. HCPF discovered the issue on May 31, 2023. Affected data included full names, business mailing addresses, business phone numbers, and Social Security numbers (if used as taxpayer ID). No provider portal credentials or financial account information were involved. HCPF offered two years of credit monitoring and identity restoration via Experian.
Colorado Department of Health Care Policy & Financing (HCPF) disclosed a breach involving its third-party vendor, IBM, which used the Progress Software MOVEit Transfer application. An unauthorized actor accessed HCPF files containing member and provider information (names, addresses, SSNs) on or about May 28, 2023. HCPF offered two years of credit monitoring. The notification was filed in Delaware on October 3, 2023, as a supplemental notice.