HackingHealthcareTechnologyHealthcareCapture Stored DataData ExfiltratedSupply Chain (3P Vendor)Customer Data InvolvedDelayed DiscoveryIDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASICPIIMediumContained
CareDx, Inc.
bd_6f32468af1fe1054 · schema v1 · pii pii-v1
Full breach record for CareDx, Inc. →On February 21, 2024, Cencora, Inc. discovered that data from its information systems had been exfiltrated. The incident involved Lash Group, a Cencora affiliate that had held personal information through a prior partnership with CareDx, Inc. Affected data may include names, addresses, dates of birth, Social Security Numbers, and diagnostic test indicators. Cencora notified CareDx on May 22, 2024. Affected individuals were offered 24 months of Experian IdentityWorks credit monitoring.
Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-587245
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jun 20, 2024
- Raw hash
- a29e7fc0fe971afc422325ea84832ba7204d8ffe80c5136037374bd58e67c594
Reporting entity
- Name
- CareDx, Inc.norm: caredx
Victim entity
- Name
- CareDx, Inc.norm: caredx
- Industry
- HealthcarellmTechnologyllm
Incident
- Discovered
- —
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASICPII
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1041 Exfiltration Over C2 ChannelT1119 Automated CollectionT1074 Data Staged
- Threat actor
- External
- Third party
- via Cencora, Inc. / Lash Group
Compliance
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.