Johnson & Johnson Health Care Systems, Inc.
bd_5ff6b97317a260e1 · schema v1 · pii pii-v1
IBM notified Johnson & Johnson Health Care Systems, Inc. (Janssen) patients that unauthorized access occurred to the Janssen CarePath database. IBM, a service provider, identified the access on August 2, 2023. Personal information (names) was potentially accessed; SSNs and financial data were not. IBM remediated the vulnerability and offered one-year credit monitoring.
J jump to incidentP pin to compareR raw source
Incident timeline
Aug 2, 2023
Discovered
Sep 22, 2023
Filed
vs. sector median
5 wks faster
Linked disclosures
Why this link?Regulatory filings (3) · sorted by filing gap
- California State AGbd_b5d032662e10aadc2023-09-22Verified
- HHS OCRbd_149be387af0e45522023-09-29 · +7dVerified
- Illinois State AGbd_8fa79ddc2a3e8b9b2023-01-01 · +264dCandidate
Filing propagation · 4 filings · 4 states
View merged incident ↗Pattern: first filing Jan 1 (IL), last Sep 29 (NY) — a 271-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.