Johnson & Johnson Health Care Systems Inc.
bd_cffc699c0fbba4f6 · schema v1 · pii pii-v1
Full breach record for Johnson & Johnson Health Care Systems Inc. →Johnson & Johnson Health Care Systems Inc. (Janssen) notified Washington AG of unauthorized access to a third-party database managed by IBM supporting the Janssen CarePath patient platform. Discovered Aug 2, 2023, the breach affected ~53,970 WA residents. Data included names, contact info, DOB, health insurance, and medication data. No SSNs or financial accounts were involved. IBM remediated the vulnerability and offered credit monitoring.
J jump to incidentP pin to compareR raw source
Incident timeline
Aug 2, 2023
Discovered
Sep 5, 2023
Filed
vs. sector median
8 wks faster
Linked disclosures
Why this link?Regulatory filings (1) · sorted by filing gap
- Oregon State AGbd_651b9726a01941b22023-09-15 · +10dVerified by operator
Filing propagation · 2 filings · 2 states
View merged incident ↗Pattern: first filing Sep 5 (WA), last Sep 15 (OR) — a 10-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.