Johnson and Johnson Health Care Systems, Inc.
bd_26bd4196d7328107 · schema v1 · pii pii-v1
Full breach record for Johnson and Johnson Health Care Systems, Inc. →Johnson & Johnson Health Care Systems, Inc. (Janssen) experienced unauthorized access to a database supporting the Janssen CarePath patient support platform. The database was managed by third-party provider IBM. The incident involved a technical method allowing unauthorized access, identified on August 2, 2023. Affected data included names and potentially other personal information, though SSNs and financial account numbers were explicitly excluded. IBM and Janssen remediated the vulnerability and augmented security controls. Affected individuals were offered one year of credit monitoring. The notice covers residents of multiple states, including Delaware, New York, and Maryland.
Linked disclosures
Why this link?Regulatory filings (2) · sorted by filing gap
- bd_a41f825c6f6f07d1Delaware State AGfiled 2023-09-22Candidate
- bd_33114d6ef501acf4Vermont State AGfiled 2023-09-15(7d gap)Verified
Source provenance
- Source URL
- https://attorneygeneral.delaware.gov/wp-content/uploads/sites/50/2023/10/Johnson-and-Johnson-Sample-Individual-Notice-Letter.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Sep 22, 2023
- Raw hash
- 9d4010c1136f21b25c487054d759c95890c027b77e26811b4e1086d70b54d347
Reporting entity
- Name
- INTERNATIONAL BUSINESS MACHINES CORPnorm: international business machines
- Domain
- ibm.com
Victim entity
- Name
- Johnson and Johnson Health Care Systems, Inc.norm: johnson and johnson health care
Incident
- Discovered
- Aug 2, 2023
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing Application
- Threat actor
- External
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 7 weeks(51 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.