← Philips

2023 Philips Respironics — MOVEit Transfer compromise; downstream sleep-therapy partner notices

2023 457.2K records affected Share on X

Data compromised

Patient demographic, insurance, and device-setup metadata per HME and provider notification mirrors

Technical writeup

Philips Respironics joined the mid-2023 global Cl0p MOVEit Transfer wave, with partner substitute notices and HIPAA-oriented journalism describing therapy-device and Care Orchestrator–linked patient metadata—including demographics, insurance identifiers, and device serials—while financial card data was routinely described as out of scope. Population figures vary by partner notice batch; BreachHistory uses a widely cited aggregate band from specialty health reporting.

Root cause

Zero-day exploitation of Progress MOVEit managed file transfer instances

References