Colorado health agency notified 4.1 million people after IBM MOVEit breach
- Organization
- Colorado Department of Health Care Policy and Financing
- Exploit
- Supply Chain Attack
- Industry
- Government Health Agency
The Colorado Department of Health Care Policy and Financing, the state agency that runs the Health First Colorado Medicaid programme and Child Health Plan Plus, disclosed in August 2023 that personal and health information on more than four million people had been taken in the MOVEit Transfer campaign. The agency put the figure at 4,091,794 individuals in a filing with the Maine attorney general and began mailing notifications on 11 August.
HCPF said its own systems were not compromised. The exposure occurred at IBM, a contractor that was moving agency files using Progress Software's MOVEit Transfer product. An unauthorised party accessed those files on 28 May 2023 through the zero-day flaw tracked as CVE-2023-34362, which the Clop extortion group exploited against hundreds of organisations that spring. IBM said it moved to isolate potentially affected systems once Progress notified it of the vulnerability.
According to the agency's notice, the files held names, addresses, dates of birth, Social Security numbers, Medicaid and Medicare identification numbers, demographic and income details, health insurance information and clinical records including diagnoses, conditions, lab results, medications and other treatment information.
HCPF offered affected members 24 months of free credit monitoring and identity restoration services through Experian and published guidance on monitoring accounts. The incident was one of the largest single notifications arising from the MOVEit campaign, which by mid-August 2023 had been linked to hundreds of organisations and tens of millions of records.
Updates
-
The Colorado Department of Health Care Policy and Financing revised the total to 4,662,668 people, up from the roughly 4.1 million reported in August 2023. It confirmed on 17 January 2024 that further individuals were in the accessed files and sent the last batch of notifications on 19 February 2024.