HackingEmployee Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTHEALTH_BASICEMPLOYMENTLOCATIONMediumActive
HENRY SCHEIN, INC.
bd_4b1727b048fdc855 · schema v1 · pii pii-v1
Full breach record for HENRY SCHEIN, INC. →Henry Schein, Inc. notified employees of a cybersecurity incident discovered on October 14, 2023. An unauthorized third party accessed systems containing employee personal information, including names, addresses, SSNs, financial data, and medical history. The company took systems offline, engaged forensic experts, and is offering 24 months of identity monitoring. The investigation is ongoing.
California clockDiscovered Oct 14, 2023 → Notified Nov 17, 202334d ✓ CA 60-day OK8 weeks discovery → filing
This filing is one of 8 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (7) · sorted by filing gap
- bd_817f39c882aae4e0Maine State AGfiled 2023-12-06Verified
- bd_e6ff33d71b709e98South Carolina State AGBlackCatfiled 2023-11-28(8d gap)Verified
- bd_6c3ca5d013cd7be2Montana State AGfiled 2023-11-17(19d gap)Verified
- bd_cc87b9a5cdf301c1Vermont State AGfiled 2023-11-17(19d gap)Verified
Show 3 more filings ↓Show fewer ↑up to 51d gap
- bd_838851b9407ab003SEC 8-Kfiled 2023-11-16(20d gap)Verified
- bd_ad54e6e188668b37New Hampshire State AGfiled 2023-11-16(20d gap)Verified
- bd_72816974130743b6Washington State AGfiled 2024-01-26(51d gap)Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-577534
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Dec 6, 2023
- Raw hash
- d12042df77179c4e9e1dcf047e4bcfc14fda32e9542d4b83ce16bb4ccdf1e1b3
Reporting entity
- Name
- HENRY SCHEIN, INC.norm: henry schein
- Domain
- henryschein.com
Victim entity
- Name
- HENRY SCHEIN, INC.norm: henry schein
- Domain
- henryschein.com
Incident
- Discovered
- Oct 14, 2023
- Materiality determined
- —
- Notification sent
- Nov 17, 2023
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTHEALTH_BASICEMPLOYMENTLOCATION
- Attack vector
- Unknown
- Threat actor
- External
Compliance
- Time to disclose
- 8 weeks(53 days from discovery to filing)
- Compliance flags
- CA 60-day OK · 34d
- Discovery-date grounding
- letter-groundedThe discovery date is the detection date narrated in the notification letter — the defensible tier.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Oct 14, 2023→ Notified: Nov 17, 202334d 60 days (analyst band, pre-2026 discoveries) CA 60-day OK
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.