Four million health records exposed in Colorado data breach

Share post:

The Colorado Department of Health Care Policy and Financing (HCPF) has suffered a data breach that impacted the personal and health information of four million individuals.

The breach was caused by a vulnerability in the MOVEit managed file transfer application, which is used by IBM to move data for HCPF.

The investigation into the breach determined that threat actors accessed sensitive data, including full names, Social Security numbers, Medicaid ID numbers, Medicare ID numbers, dates of birth, home addresses, and other contact information. However, financial information such as credit card numbers was not exposed.

HCPF is offering potentially impacted individuals two years of free credit monitoring and identity restoration services. The agency is also reviewing its cybersecurity policies and practices to prevent similar data breaches in the future.

This is the latest in a series of data breaches that have impacted Colorado organizations. In 2022, the Colorado Department of Higher Education suffered a ransomware attack that exposed the personal information of current and former students and educators. And in 2021, Colorado State University disclosed a data breach that exposed the personal information of students, faculty, and staff.

Previous victims of the MOVEit data breach include the U.S. Department of Energy, Schneider Electric, Siemens Energy, Shell, Louisiana’s Office of Motor Vehicles, Norton’s parent company Gen Digital, and German Banks Deutsche Bank AG, Commerzbank, and ING.

The sources for this piece include an article in CPOMAGAZINE.

SUBSCRIBE NOW

Related articles

North Korean hacker infiltrates US security vendor, loads malware

KnowBe4, a US-based security vendor, unknowingly hired a North Korean hacker who attempted to introduce malware into the...

CrowdStrike releases an update from initial Post Incident Review: Hashtag Trending Special Edition for Thursday July 25, 2024

Security vendor CrowdStrike released an update on from their initial Post Incident Review today. The first, and most surprising...

Security vendor CrowdStrike issues an update from their initial Post Incident Review

Security vendor CrowdStrike released an update from their initial Post Incident Review (PIR) today. The company's CEO has...

CrowdStrike CEO summoned by Homeland Security committee over software disaster

CrowdStrike CEO George Kurtz has been called to testify before the U.S. House Committee on Homeland Security following...

Become a member

New, Relevant Tech Stories. Our article selection is done by industry professionals. Our writers summarize them to give you the key takeaways