Sensitive medical and health data on about 4.1 million Americans has been stolen, the result of a breach announced by the Colorado Department of Health Care Policy and Financing (HCPF). HCPF confirmed the breach was part of a massive MOVEit hack. It said IBM, one of the state’s vendors, “uses the MOVEit application to move HCPF data files in the normal course of business”.
HCPF, which oversees Health First Colorado (Colorado’s Medicaid program), Child Health Plan Plus (CHP+), and other health care programs, said that the compromised personal information may have included one or more of the following: full name, social security number, medicaid ID number, medicare ID number, date of birth, home address and other contact information, demographic or income information, clinical and medical information (such as diagnosis/condition, lab results, medication, or other treatment information), and health insurance information.
In a letter to the affected patients, HCPF said that “certain HCPF files on the MOVEit application used by IBM were accessed by the unauthorized actor,” and the HCPF urged those affected to be cautious.
Identity theft and fraud
“We encourage you to remain vigilant against identity theft and fraud by reviewing your bank and credit card accounts and monitoring your free credit reports to detect suspicious activity and errors,” Jane Wilson, Privacy Officer, said.
After discovering the breach, HCPF moved quickly to investigate the incident, and confirmed that no other HCPF systems were affected. HCPF and its vendors are also reviewing their policies, procedures and cybersecurity measures to further protect their systems.
Many organizations around the world have been affected by the MOVEit hack, and at the time of writing, over 70 institutions globally have announced breaches.
The Missouri Department of Social Services, another State Department, also announced it had been affected by the breach. Individual’s names, department client numbers, dates of birth, possible benefit eligibility status or coverage, and medical claims information were accessed. The DDS also encouraged Missourians to monitor and protect their identity after the third-party cyber-attack. The number of individuals affected has not been released.
“Certain HCPF files on the MOVEit application used by IBM were accessed by the unauthorized actor.”
Colorado Department of Health Care Policy and Financing
According to TechCrunch, neither Colorado’s HCPF nor Missouri’s DSS have been listed on the dark web leak site of the Clop ransomware gang, a Russia-linked group which is said to behind the mass hacks. The news site also says that Clop has written “We don’t have any government data” on their website.
Colorado State University breach
Another Colorado institution, the Colorado State University, also reported a breach earlier this summer. It said it had suffered a MOVEit-related data breach that affected tens of thousands of students and academic staff.
“While this incident is still part of an ongoing criminal and internal investigation, CDHE knows that an unauthorized actor(s) accessed CDHE systems between June 11 and June 19, 2023, and that certain data was copied from CDHE systems during this time,” the University said. It believes that data dating as far back as 2004 was breached.
To date, these institutions have reportedly been affected by the MOVEit hack:
- The US Department of Energy
- Shell company
- First National Bankers Bank
- Putnam Investments
- Datasite
- Swizz Insurance company ‘OKK’
- Leggett & Platt
- Multinational firm PricewaterhouseCoopers (Pwc)
- Ernst & Young
- Health Services Ireland
- BBC
- British Airways
- Boots Retail
- Medibank
- Rochester Hospital
- GreenShield Canada
- Datasite
- National Student Clearinghouse
- United Healthcare Student Resources
- University System of Georgia
- German brand Heidelberg
- Aer Lingus
- Government of Nova Scatia
- Johns Hopkins University
- Ofcom
- Transport for London (TfL)
- Ernst and Young
- Gen Digital, the parent company of Avast, Norton, AVG, Avira and LifeLock
- New York City Department of Education attack impacted about 45k students
- Siemens Energy
- Schneider Electric
- Dublin Airport Staff
- Shutterfly.com
- Allegiant Air
- American Airlines
- Irelands commission of Communications Regulation
- Estee Lauder
- Sierra Wireless
- Bluefin Payment System
- TJX Companies
- Ventiv Technology
- Vitality Group International
- University of Alaska
- University of Colorado
- University of Dayton
- University of Delaware
- University of Idaho
- University of Illinois
- University of Loyola
- University of Missouri
- University of Oklahoma
- University of Rochester
- University of Southern Illinois
- University of Utah
- University of Wake Forest
- University of Washington State
- Webster University
- PBI Research Service
- Teachers Insurance and Annuity Association
- Honeywell
- American Multi Cinema Inc aka AMC Theatres
- Warner Bros
- Discovery
- Raddison Americas
- Crowe
- ING Bank
- Deutsche Bank
- Postbank
- Maximus
- Serco Inc
- Aristocrat
- Clorox (yet to be confirmed officially),
- Colorado Department of Health Care Policy & Financing (HCPF)
- UMass Chan Medical School of Massachusetts health