HackingData ExfiltratedCustomer Data InvolvedPHIHEALTH_BASICIDENTITY_BASICLowContained
Cencora
bd_6ba6ddcc6fd6c341 · schema v1 · pii pii-v1
Full breach record for Cencora →Cencora, Inc. notified California residents of a data breach involving personal health information. On February 21, 2024, Cencora learned that data from its information systems had been exfiltrated. The compromised data potentially included names, addresses, dates of birth, health diagnoses, and medications. Cencora engaged law enforcement and cybersecurity experts, took containment steps, and is offering two years of credit monitoring through Experian.
California clockDiscovered Feb 21, 2024 → Notified May 22, 202491d ✗ CA 60-day late13 weeks discovery → filing
This filing is one of 40 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (10) · sorted by filing gap
- bd_225434215343f740Vermont State AGfiled 2024-05-31(9d gap)Verified
- bd_2f627285f2f041f2California State AGfiled 2024-05-31(9d gap)Verified
- bd_b9a4dc86f510194fCalifornia State AGfiled 2024-06-03(12d gap)Verified
- bd_0d319f20684cf4c8California State AGfiled 2024-06-05(14d gap)Candidate
Show 6 more filings ↓Show fewer ↑up to 47d gap
- bd_963c68d0dad2686dVermont State AGfiled 2024-06-05(14d gap)Verified
- bd_9c16b27470822eb3Vermont State AGfiled 2024-06-05(14d gap)Candidate
- bd_9af1f290af4dcb0cCalifornia State AGfiled 2024-06-10(19d gap)Candidate
- bd_13b5600dd58fb13cCalifornia State AGfiled 2024-06-20(29d gap)Verified
- bd_1c074a8994b49b5fVermont State AGfiled 2024-06-20(29d gap)Verified
- bd_3fed8c71645b986bCalifornia State AGfiled 2024-07-08(47d gap)Candidate
Showing first 10 of 39 linked disclosures.
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-585783
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- May 22, 2024
- Raw hash
- 9e220070ee7f66f8fcb03816cfe7d305daf00eeec9a80ad8227e9ee4f64a5f86
Reporting entity
- Name
- Novartisnorm: novartis
- Domain
- novartis.com
Victim entity
- Name
- Cencoranorm: cencora
- Domain
- cencora.com
Incident
- Discovered
- Feb 21, 2024
- Materiality determined
- —
- Notification sent
- May 22, 2024
- Affected individuals
- Not disclosed
- Data types
- PHIHEALTH_BASICIDENTITY_BASIC
- Attack vector
- Unknown
- MITRE ATT&CK
- T1041 Exfiltration Over C2 Channel
- Threat actor
- External
- Regulator citations
- Assistance of law enforcement
Compliance
- Time to disclose
- 13 weeks(91 days from discovery to filing)
- Compliance flags
- CA 60-day late · 91d
- Discovery-date grounding
- letter-groundedThe discovery date is the detection date narrated in the notification letter — the defensible tier.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Feb 21, 2024→ Notified: May 22, 202491d 60 days (analyst band, pre-2026 discoveries) CA 60-day late
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.