BRISTOL-MYERS SQUIBB COMPANY
bd_c1f57c93d6a4ce22 · schema v1 · pii pii-v1
Full breach record for BRISTOL-MYERS SQUIBB COMPANY →7 incidents on fileCencora, Inc. notified Bristol Myers Squibb Company patients that on February 21, 2024, data was exfiltrated from Cencora's information systems. The incident potentially affected personal information including names, addresses, dates of birth, health diagnoses, and medications. Cencora took containment steps, engaged law enforcement and cybersecurity experts, and is offering 24 months of credit monitoring through Experian. No evidence of misuse was found at the time of notification.
J jump to incidentP pin to compareR raw source
Incident timeline
Feb 21, 2024
Discovered
May 17, 2024
Filed
vs. sector median
on median
Linked disclosures
Why this link?Regulatory filings (2) · sorted by filing gap
- Vermont State AGbd_269fcc165d95a33a2024-05-17Verified
- Indiana State AGbd_87020ead768c97652024-05-17Verified
Filing propagation · 3 filings · 3 states
View merged incident ↗Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.