DisclosureLens
HackingHealthcareTechnologyHealthcareCustomer Data InvolvedTargetedIdentity (basic)Government IDPHIHealth (basic)HighContained

PharMerica Corporation

bd_daca18683c969f62 · schema v1 · pii pii-v1

Severity

High

Discovered

Mar 14, 2023

Filed

Jun 8, 2023

To disclose

12 weeks

Affected

10,567state residents only

Linked

11 filings

Confidence

66%
Full breach record for PharMerica Corporation

PharMerica Corporation notified affected individuals in Montana and other states of a cybersecurity incident. Unauthorized access occurred March 12-13, 2023. Data accessed included names, addresses, DOBs, SSNs, medications, and health insurance info. PharMerica engaged cybersecurity advisors, enhanced security measures, and offered one year of Kroll identity monitoring.

Incident timeline

undetected · 2 days
discovery → filing · 12 weeks / 86 days

Mar 12, 2023

Begins

Mar 14, 2023

Discovered

Jun 8, 2023

Filed

vs. sector median

on median

This filing is one of 11 about the same incident.View merged incident

Linked disclosures

Why this link?

Ransomware claims (1)

Regulatory filings (9) · sorted by filing gap

Show 5 more filingsup to 158d gap

Filing propagation · 10 filings · 10 states

View merged incident ↗

Pattern: first filing Jan 1 (IL), last Jun 19 (CA) — a 169-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.