DisclosureLens
MisuseHealthcareProfessional ServicesHealthcarePrivilege AbuseTheftEmployee Data InvolvedTargetedGovernment IDPIIMediumContained

CARDINAL HEALTH, INC.

bd_182e4854d11b49e8 · schema v1 · pii pii-v1

Severity

Medium

Discovered

Aug 1, 2010

Filed

Oct 8, 2010

To disclose

10 weeks

Affected

3state residents only

Confidence

65%
Full breach record for CARDINAL HEALTH, INC.4 incidents on file

Cardinal Health notified the NH AG of a security incident at its Grand Prairie, TX facility. An IT employee improperly disposed of/sold decommissioned computers. Investigation revealed 60 missing computers; 2 contained SSNs and employee numbers. 3 NH residents affected. Employee terminated. Remediation includes laptop encryption, policy revisions, and credit monitoring offered to affected individuals.

Incident timeline

discovery → filing · 10 weeks / 68 days

Aug 1, 2010

Begins

Aug 1, 2010

Discovered

Oct 8, 2010

Filed

vs. sector median

1 wks faster

Tracked as a single-filing incident — the only disclosure on record for this event so far.Confirmed3 affectedView incident

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.