Lash Group (affiliate of Cencora, Inc.)
bd_43fa729f230b98f7 · schema v1 · pii pii-v1
Full breach record for Lash Group (affiliate of Cencora, Inc.) →2 incidents on fileCencora, Inc. and its Lash Group affiliate reported that on February 21, 2024, data was exfiltrated from Cencora's information systems, including personal information of patients enrolled in Bristol Myers Squibb and BMS Patient Assistance Foundation programs. Potentially affected data included name, address, date of birth, health diagnosis, and medications/prescriptions. Cencora engaged cybersecurity experts, law enforcement, and outside counsel. Notification letters dated May 17, 2024 were sent to affected individuals with offers of 24-month Experian identity monitoring.
J jump to incidentP pin to compareR raw source
Incident timeline
Feb 21, 2024
Begins
May 17, 2024
Filed
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.