HackingHealthcareHealthcareCapture Stored DataData ExfiltratedSupply Chain (3P Vendor)Customer Data InvolvedDelayed DiscoveryPIIPHIIDENTITY_BASICHEALTH_BASICLowContained
BRISTOL-MYERS SQUIBB COMPANY
bd_43fa729f230b98f7 · schema v1 · pii pii-v1
Full breach record for BRISTOL-MYERS SQUIBB COMPANY →Cencora, Inc. and its Lash Group affiliate reported that on February 21, 2024, data was exfiltrated from Cencora's information systems, including personal information of patients enrolled in Bristol Myers Squibb and BMS Patient Assistance Foundation programs. Potentially affected data included name, address, date of birth, health diagnosis, and medications/prescriptions. Cencora engaged cybersecurity experts, law enforcement, and outside counsel. Notification letters dated May 17, 2024 were sent to affected individuals with offers of 24-month Experian identity monitoring.
This filing is one of 4 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (3) · sorted by filing gap
- bd_269fcc165d95a33aVermont State AGfiled 2024-05-17Verified
- bd_87020ead768c9765Indiana State AGfiled 2024-05-17Verified
- bd_c1f57c93d6a4ce22Delaware State AGfiled 2024-05-17Candidate
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-585529
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- May 17, 2024
- Raw hash
- a7c923304ceafb203925ca3e58e1e202f647c04c0d12b23feb337ff0dd498bed
Reporting entity
- Name
- Cencoranorm: cencora
- Domain
- cencora.com
Victim entity
- Name
- BRISTOL-MYERS SQUIBB COMPANYnorm: bristol myers squibb
- Industry
- Healthcarellm
Incident
- Discovered
- —
- Materiality determined
- —
- Notification sent
- May 17, 2024
- Affected individuals
- Not disclosed
- Data types
- PIIPHIIDENTITY_BASICHEALTH_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1041 Exfiltration Over C2 ChannelT1119 Automated CollectionT1074 Data Staged
- Threat actor
- External
- Regulator citations
- Notified California Office of the Attorney General
- Third party
- via Cencora, Inc. / Lash Group
Compliance
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.