HackingCustomer Data InvolvedData ExfiltratedIDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASICPHIMediumContained
PharMerica Corporation
bd_c2b1450efa997e5b · schema v1 · pii pii-v1
Full breach record for PharMerica Corporation →PharMerica Corporation reported that an unknown third party accessed its computer systems from March 12-13, 2023. The company discovered suspicious activity on March 14, 2023. Affected data included names, addresses, dates of birth, Social Security numbers, medications, and health insurance information. PharMerica engaged cybersecurity advisors and is offering one year of identity monitoring through Kroll.
Leak gap clock⏱ Leak >30d14 weeks discovery → filing
This filing is one of 7 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (6) · sorted by filing gap
- bd_e9b259e070676bf3Maine State AGfiled 2023-06-09(10d gap)Verified
- bd_a43e9112bb1c5c48Delaware State AGfiled 2023-06-08(11d gap)Verified
- bd_b8a2948fa31c71f6Delaware State AGfiled 2023-06-08(11d gap)Verified
- bd_daca18683c969f62Montana State AGfiled 2023-06-08(11d gap)Verified
Show 2 more filings ↓Show fewer ↑up to 38d gap
- bd_226e2c119c013671Oregon State AGfiled 2023-05-12(38d gap)Candidate
- bd_64333830485a7e13HHS OCRfiled 2023-05-12(38d gap)Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-568177
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jun 19, 2023
- Raw hash
- de5cdc6a350867c2ff82b2faf1c494a310e2fd0feb84447758185798995f1263
Reporting entity
- Name
- PharMerica Corporationnorm: pharmerica
- Domain
- pharmerica.com
Victim entity
- Name
- PharMerica Corporationnorm: pharmerica
- Domain
- pharmerica.com
Incident
- Discovered
- Mar 14, 2023
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASICPHI
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid Accounts
- Threat actor
- External
Compliance
- Time to disclose
- 14 weeks(97 days from discovery to filing)
- Compliance flags
- Leak >30d
- Discovery-date grounding
- letter-groundedThe discovery date is the detection date narrated in the notification letter — the defensible tier.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.