HENRY SCHEIN, INC.
ent_019de602115dc52e6b37bb6ef9cdc778
Disclosures
17
State AG · SEC 8-K · 10 jurisdictions
Multi-filing incidents
3
incidents joining 2+ filings here
Max affected reported
166,432
nationwide · State AG OR
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- HENRY SCHEIN, INC.
- Normalized
- henry schein— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- VGO3WGL8H45T73F4RR92
- SEC EDGAR CIK
- 0001000228
- Domain
- henryschein.com
Disclosure history (17)newest first
- Oregon State AGas victim2024-10-23
Henry Schein, Inc. reported a data breach to the Oregon Attorney General. The breach was reported on 2024-10-23. The breach occurred during 9/27/2023 - 12/5/2023. The breach was discovered on 10/14/2023. 166,432 individuals were affected. Notice was sent on 11/17/202312/4/20231/11/20246/25/20249/5/202410/16/2024.
- Maine State AGas victim2024-10-23
Henry Schein, Inc. reported an external system breach (hacking) occurring on September 27, 2023, discovered on October 14, 2023. The incident affected 166,432 individuals nationwide, including 383 Maine residents. Personal information, including names and government identifiers, was accessed. The company engaged forensic experts, notified law enforcement, and provided 24 months of credit monitoring via Experian.
- California State AGas victim2024-10-23
Henry Schein, Inc. notified the California Attorney General of a cybersecurity incident affecting its manufacturing and distribution businesses. The company determined on October 14, 2023, that an unauthorized third party accessed personal information. The investigation, conducted with outside forensic experts, concluded that personal information was affected. Henry Schein took systems offline, notified law enforcement, and is offering 24 months of identity monitoring through Experian to affected individuals. The specific data types affected are not detailed in the notice beyond 'personal information', and no specific attack vector or malware was identified.
- Oregon State AGas victim2024-05-31
Henry Schein, Inc. reported a data breach to the Oregon Attorney General. The breach was reported on 2024-05-31. The breach occurred during 1/1/0001. 63,760 individuals were affected.
- Washington State AGas victim2024-01-26
Henry Schein, Inc. filed a supplemental notice with the Washington AG regarding a ransomware incident. The breach impacted 1,953 Washington residents, including employee PII (SSNs, DOBs, financial/medical data). Incident occurred Sept-Dec 2023; discovered Oct 14, 2023. Notices sent starting Nov 17, 2023. Remediation included forensic investigation and credit monitoring offers.
- California State AGas victim2023-12-06
Henry Schein, Inc. notified employees of a cybersecurity incident discovered on October 14, 2023. An unauthorized third party accessed systems containing employee personal information, including names, addresses, SSNs, financial data, and medical history. The company took systems offline, engaged forensic experts, and is offering 24 months of identity monitoring. The investigation is ongoing.
- Maine State AGas victim2023-12-06
Henry Schein, Inc. reported an external system breach that occurred on September 27, 2023, and was discovered on October 14, 2023. The breach impacted 29,112 individuals, including 38 residents of Maine. The compromised data includes financial account numbers or credit/debit card numbers along with associated access codes or PINs. Affected individuals were notified starting on November 17, 2023, and were offered 24 months of identity theft and credit monitoring services from Experian.
- Massachusetts State AGas victim2023-12-06
Henry Schein, Inc reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2023-12-06. 408 Massachusetts residents were affected. The report records the breach type as electronic.
- South Carolina State AGas victim2023-11-28
Henry Schein, Inc. notified South Carolina employees of a cybersecurity incident discovered on October 14, 2023. Unauthorized third-party access to employee personal information (including SSN, DOB, financial, and medical data) was confirmed. The company engaged forensic experts, notified law enforcement, and is offering 24 months of Experian identity monitoring. Investigation is ongoing.
- Montana State AGas victim2023-11-17
Henry Schein, Inc. notified Montana employees of a cybersecurity incident discovered on October 14, 2023, involving unauthorized access to employee personal information. Impacted data included names, SSNs, financial, and health data. The company engaged forensic experts, notified law enforcement, and provided 24 months of Experian IdentityWorks monitoring. Investigation was ongoing at the time of notification.
- Vermont State AGas victim2023-11-17
Henry Schein, Inc. disclosed a cybersecurity incident affecting its manufacturing and distribution businesses, discovered on October 14, 2023. The breach involved unauthorized access to employee personal information, including names, SSNs, driver's licenses, financial data, and medical history. The company engaged forensic experts, notified law enforcement, and offered 24 months of Experian identity monitoring to affected employees.
- FEDERALSEC 8-Kas victim2023-11-16
Henry Schein, Inc. filed an 8-K (Item 3.01) on Nov 16, 2023, reporting a Nasdaq delisting notice due to late 10-Q filing. The delay was caused by a cybersecurity incident on Oct 14, 2023, which forced the company to shut down operations and take down applications. This filing supplements the initial Oct 16, 2023 disclosure of the incident.
- New Hampshire State AGas victim2023-11-16
Henry Schein, Inc. notified New Hampshire AG that a cybersecurity incident occurred on or about October 14, 2023, affecting employee personal information. Approximately 104 NH residents were notified. The breach involved unauthorized access to manufacturing and distribution business systems. Response included taking systems offline, engaging forensic experts, notifying law enforcement, and offering credit monitoring.
- FEDERALSEC 8-Kas victim2023-10-24
Henry Schein, Inc. filed an Item 7.01 Regulation FD update on October 24, 2023 regarding the status of order processing following a previously announced cybersecurity incident that affected a portion of its manufacturing and distribution businesses. U.S., Canadian, European, Australian, New Zealand, Asian, and Brazilian distribution operations are reported operational. Henry Schein One practice management business and most manufacturing operations were unaffected. No new technical details, attacker attribution, or affected-individual counts disclosed.
- Massachusetts State AGas victim2009-07-16
Henry Schein, Inc. reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2009-07-16. 16 Massachusetts residents were affected. The report records the breach type as electronic.
- New Hampshire State AGas victim2009-07-16
Henry Schein, Inc. notified the New Hampshire Attorney General on July 16, 2009, of a breach involving one NH resident. On July 8, 2009, HSI learned a laptop containing customer names and credit card numbers was stolen from an employee. Notifications began mailing July 15, 2009, offering one year of credit monitoring.
- New Hampshire State AGas victim2007-04-17
Henry Schein Financial Services, Inc. reported the theft of an unencrypted laptop containing customer names and SSNs from a hotel in Chicago. The incident was discovered on Feb 23, 2007. Approximately 340 customers were potentially affected, including 1 NH resident. The company notified the NH AG and offered one year of credit monitoring.
Subsidiary disclosures (newest 10)filed by group companies
◈ These filings were made by or about subsidiaries of HENRY SCHEIN, INC. — not by HENRY SCHEIN, INC. itself. Corporate relationships are mapped from GLEIF relationship records and SEC Exhibit 21 filings.
- California State AGvia ACE Surgical Supply Co., Inc.2021-11-19
ACE Surgical Supply Co., Inc. disclosed a cyberattack where unauthorized access occurred between June 29 and July 8, 2021. The company discovered the incident on June 29, 2021. Affected data included names, contact information, DEA numbers, and physician state license numbers. The company secured systems, contacted law enforcement, and offered 24 months of identity monitoring.
- Maine State AGvia ACE Surgical Supply Co., Inc.2021-11-19
ACE Surgical Supply Co., Inc. experienced an external system breach on June 29, 2021, which was also the date of discovery. The breach compromised financial account numbers or credit/debit card numbers along with personal identifiers. A total of 67 Maine residents were affected. The company began notifying consumers on July 26, 2021, and offered 24 months of complimentary identity theft protection services through Experian's IdentityWorks.
- Maine State AGvia ACE Surgical Supply Co., Inc.2021-10-12
On June 29, 2021, ACE Surgical Supply Co., Inc. discovered it was the victim of a ransomware cyberattack in which company files were accessed without authorization. The company secured its systems, contacted the FBI, and began an investigation. An initial notification was sent on July 28, 2021, to three affected Maine residents. In September 2021, the investigation identified an additional 25 affected customers who are Maine residents. The compromised customer information included names, contact information, and DEA and physician state license numbers. A second round of written notifications, including an offer for credit monitoring services, was sent to affected Maine residents on October 6, 2021. The investigation is ongoing, and there is no evidence that the compromised information has been made public or used for identity theft.
- New Hampshire State AGvia ACE Surgical Supply Co., Inc.2021-10-12
ACE Surgical Supply Co., Inc. filed a supplemental data breach notification with the New Hampshire Attorney General regarding a ransomware attack discovered on June 29, 2021. The incident affected 58 New Hampshire residents, exposing names, contact info, and DEA/physician license numbers. Notifications were sent on October 6, 2021, offering 24 months of credit monitoring. The investigation is ongoing.
- Montana State AGvia ACE Surgical Supply Co., Inc.2021-10-06
ACE Surgical Supply Company, Inc. disclosed a cyberattack discovered on June 29, 2021, where unauthorized parties accessed company files. The breach potentially exposed Assessment Questionnaire Practitioner Forms containing names, contact info, DEA numbers, and state license numbers. The company secured systems, engaged forensic investigators, and notified law enforcement. Affected individuals were offered 24 months of Experian IdentityWorks.
- Indiana State AGvia ACE Surgical Supply Co., Inc.2021-08-25
ACE Surgical Supply Co reported a data breach to the Indiana Attorney General. The breach occurred on 2021-06-29 and was reported on 2021-08-25. 130 Indiana residents were affected. 12,122 individuals affected in total.
- Maine State AGvia ACE Surgical Supply Co., Inc.2021-07-28
ACE Surgical Supply Co., Inc. reported an external system breach (hacking) occurring on June 29, 2021. The incident compromised the names and Social Security Numbers of 284 individuals, including 3 Maine residents. The company notified affected consumers in writing on July 26, 2021, and provided 24 months of complimentary identity protection services through Experian.
- New Hampshire State AGvia ACE Surgical Supply Co., Inc.2021-07-28
ACE Surgical Supply Co., Inc. notified the New Hampshire Attorney General on July 28, 2021, of a ransomware incident discovered on June 29, 2021. The breach affected 3 New Hampshire residents, exposing employee and dependent PII including SSNs, DOBs, and bank account details. ACE engaged the FBI and forensic investigators, secured systems, and provided 24 months of credit monitoring.
- Massachusetts State AGvia ACE Surgical Supply Co., Inc.2021-07-08
ACE Surgical Supply Co., Inc. reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2021-07-08. 1,217 Massachusetts residents were affected. The report records the breach type as electronic.
- New Hampshire State AGvia ACE Surgical Supply Co., Inc.2015-09-15
ACE Surgical Supply Co., Inc. notified the NH Attorney General that an information security incident possibly involved 13 NH residents. Suspicious files were discovered during a routine server review. Credit card info and/or account passwords were compromised. Notifications were mailed on Sept 4, 2015, with 1 year of identity monitoring offered.