HackingHealthcareProfessional ServicesHealthcareCapture Stored DataData ExfiltratedCustomer Data InvolvedDelayed DiscoveryIDENTITY_BASICHEALTH_BASICPHILowContained
Cencora
bd_b9a4dc86f510194f · schema v1 · pii pii-v1
Full breach record for Cencora →Cencora, Inc. and its Lash Group affiliate discovered on February 21, 2024 that data had been exfiltrated from its information systems. Affected data includes patient names, addresses, dates of birth, health diagnoses, and medications/prescriptions. Cencora engaged law enforcement, cybersecurity experts, and outside counsel, and is offering 24-month Experian IdentityWorks credit monitoring to affected individuals.
This filing is one of 40 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (10) · sorted by filing gap
- bd_0d319f20684cf4c8California State AGfiled 2024-06-05(2d gap)Candidate
- bd_963c68d0dad2686dVermont State AGfiled 2024-06-05(2d gap)Verified
- bd_9c16b27470822eb3Vermont State AGfiled 2024-06-05(2d gap)Candidate
- bd_225434215343f740Vermont State AGfiled 2024-05-31(3d gap)Verified
Show 6 more filings ↓Show fewer ↑up to 35d gap
- bd_2f627285f2f041f2California State AGfiled 2024-05-31(3d gap)Verified
- bd_3e2ae0a57615759cCalifornia State AGfiled 2024-05-31(3d gap)Candidate
- bd_9af1f290af4dcb0cCalifornia State AGfiled 2024-06-10(7d gap)Candidate
- bd_13b5600dd58fb13cCalifornia State AGfiled 2024-06-20(17d gap)Verified
- bd_1c074a8994b49b5fVermont State AGfiled 2024-06-20(17d gap)Verified
- bd_3fed8c71645b986bCalifornia State AGfiled 2024-07-08(35d gap)Candidate
Showing first 10 of 39 linked disclosures.
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-586345
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jun 3, 2024
- Raw hash
- b9a03d43d9879c0997ee1ba899c616e05390002272ff448cd7342d00afc62352
Reporting entity
- Name
- HERON THERAPEUTICS, INC.norm: heron therapeutics
Victim entity
- Name
- Cencoranorm: cencora
- Domain
- cencora.com
- Industry
- HealthcarellmProfessional Servicesllm
Incident
- Discovered
- —
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICHEALTH_BASICPHI
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1041 Exfiltration Over C2 ChannelT1119 Automated Collection
- Threat actor
- External
- Regulator citations
- Notified California Office of the Attorney General
Compliance
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.