HENRY SCHEIN, INC.
ent_019de602115dc52e6b37bb6ef9cdc778
Disclosures
15
State AG · SEC 10-K Item 1C · SEC 8-K · 9 jurisdictions
Multi-filing incidents
2
incidents joining 2+ filings here
Max affected reported
166,432
as filed · State AG OR
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- HENRY SCHEIN, INC.
- Normalized
- henry schein— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- VGO3WGL8H45T73F4RR92
- SEC EDGAR CIK
- 0001000228
- Domain
- henryschein.com
Disclosure history (15)newest first
- 🦫Oregon State AGas victim2024-10-23
Henry Schein, Inc. reported a data breach to the Oregon Attorney General. The breach was reported on 2024-10-23. The breach occurred during 9/27/2023 - 12/5/2023. The breach was discovered on 10/14/2023. 166,432 individuals were affected. Notice was sent on 11/17/202312/4/20231/11/20246/25/20249/5/202410/16/2024.
- 🦞Maine State AGas victim2024-10-23
Henry Schein, Inc. experienced a cybersecurity incident beginning September 27, 2023, discovered October 14, 2023. The company's manufacturing and distribution businesses were impacted. An unauthorized third party obtained personal information of approximately 166,432 individuals total, including 383 Maine residents. Affected individuals were notified in multiple waves beginning November 17, 2023. Experian IdentityWorks (24-month) was offered to those affected.
- 🐻California State AGas victim2024-10-23
Henry Schein, Inc. notified the California Attorney General of a cybersecurity incident affecting its manufacturing and distribution businesses. The company determined on October 14, 2023, that an unauthorized third party accessed personal information. The investigation, conducted with outside forensic experts, concluded that personal information was affected. Henry Schein took systems offline, notified law enforcement, and is offering 24 months of identity monitoring through Experian to affected individuals. The specific data types affected are not detailed in the notice beyond 'personal information', and no specific attack vector or malware was identified.
- 🦫Oregon State AGas victim2024-05-31
Henry Schein, Inc. reported a data breach to the Oregon Attorney General. The breach was reported on 2024-05-31. The breach occurred during 1/1/0001. 63,760 individuals were affected.
- FEDERALSEC 10-K Item 1Cas victim2024-02-28
10-K Item 1C cybersecurity risk management disclosure from a medical and dental supplies distributor. The filing describes the company's cybersecurity program, NIST CSF alignment, ISO27001 partial-scope certification, and the Office of Cybersecurity led by a CISO reporting to the CTO. No specific incident, breach, or attack is described in this excerpt.
- 🌲Washington State AGas victim2024-01-26
Henry Schein, Inc., a business sector entity reported a ransomware incident to the Washington Attorney General. The organization became aware of the incident on 2023-10-14 and filed notice on 2024-01-26. 1,953 Washington residents were affected. 104 days elapsed between awareness and notification. 17 days to identify the breach. 52 days to contain the breach.
- 🐻California State AGas victim2023-12-06
Henry Schein, Inc. notified employees of a cybersecurity incident discovered on October 14, 2023. An unauthorized third party accessed systems containing employee personal information, including names, addresses, SSNs, financial data, and medical history. The company took systems offline, engaged forensic experts, and is offering 24 months of identity monitoring. The investigation is ongoing.
- 🦞Maine State AGas victim2023-12-06
Henry Schein, Inc. reported an external system breach that occurred on September 27, 2023, and was discovered on October 14, 2023. The breach impacted 29,112 individuals, including 38 residents of Maine. The compromised data includes financial account numbers or credit/debit card numbers along with associated access codes or PINs. Affected individuals were notified starting on November 17, 2023, and were offered 24 months of identity theft and credit monitoring services from Experian.
- 🌴South Carolina State AGas victim2023-11-28
Henry Schein, Inc. filed a security breach notice with the South Carolina Department of Consumer Affairs on January 14, 2025, regarding a ransomware attack by the BlackCat group that occurred on October 14, 2023. The incident compromised the personal information of approximately 166,000 individuals, including employees and customers, affecting names, Social Security numbers, and financial account data. The company engaged forensic investigators, notified law enforcement, and sent notification letters to affected parties.
- 🦬Montana State AGas victim2023-11-17
Henry Schein, Inc reported a data breach to the Montana Attorney General. The breach was reported on 2023-11-17. The breach occurred on 10/14/2023. 445 Montana residents were affected.
- 🍁Vermont State AGas victim2023-11-17
Henry Schein, Inc. disclosed a cybersecurity incident affecting its manufacturing and distribution businesses, discovered on October 14, 2023. The breach involved unauthorized access to employee personal information, including names, SSNs, driver's licenses, financial data, and medical history. The company engaged forensic experts, notified law enforcement, and offered 24 months of Experian identity monitoring to affected employees.
- FEDERALSEC 8-Kas victim2023-11-16
Henry Schein, Inc. filed an 8-K (Item 3.01) on Nov 16, 2023, reporting a Nasdaq delisting notice due to late 10-Q filing. The delay was caused by a cybersecurity incident on Oct 14, 2023, which forced the company to shut down operations and take down applications. This filing supplements the initial Oct 16, 2023 disclosure of the incident.
- ⛰️New Hampshire State AGas victim2023-11-16
Henry Schein, Inc. notified New Hampshire AG that a cybersecurity incident occurred on or about October 14, 2023, affecting employee personal information. Approximately 104 NH residents were notified. The breach involved unauthorized access to manufacturing and distribution business systems. Response included taking systems offline, engaging forensic experts, notifying law enforcement, and offering credit monitoring.
- FEDERALSEC 8-Kas victim2023-10-24
Henry Schein, Inc. filed an Item 7.01 Regulation FD update on October 24, 2023 regarding the status of order processing following a previously announced cybersecurity incident that affected a portion of its manufacturing and distribution businesses. U.S., Canadian, European, Australian, New Zealand, Asian, and Brazilian distribution operations are reported operational. Henry Schein One practice management business and most manufacturing operations were unaffected. No new technical details, attacker attribution, or affected-individual counts disclosed.
- ⛰️New Hampshire State AGas victim2007-04-17
Henry Schein, Inc. filed a security breach notification with the New Hampshire Attorney General on April 17, 2007, regarding unauthorized access to personal information of New Hampshire residents. The specific nature of the breach, affected count, and dates of occurrence/discovery are not detailed in the provided filing metadata.
Subsidiary disclosures (6)filed by group companies
◈ These filings were made by or about subsidiaries of HENRY SCHEIN, INC. — not by HENRY SCHEIN, INC. itself. Corporate relationships are mapped from GLEIF relationship records and SEC Exhibit 21 filings.
- 🐻California State AGvia ACE Surgical Supply Co., Inc.2021-11-19
ACE Surgical Supply Co., Inc. disclosed a cyberattack where unauthorized access occurred between June 29 and July 8, 2021. The company discovered the incident on June 29, 2021. Affected data included names, contact information, DEA numbers, and physician state license numbers. The company secured systems, contacted law enforcement, and offered 24 months of identity monitoring.
- 🦞Maine State AGvia ACE Surgical Supply Co., Inc.2021-11-19
ACE Surgical Supply Co., Inc. experienced an external system breach on June 29, 2021, which was also the date of discovery. The breach compromised financial account numbers or credit/debit card numbers along with personal identifiers. A total of 67 Maine residents were affected. The company began notifying consumers on July 26, 2021, and offered 24 months of complimentary identity theft protection services through Experian's IdentityWorks.
- 🦞Maine State AGvia ACE Surgical Supply Co., Inc.2021-10-12
On June 29, 2021, ACE Surgical Supply Co., Inc. discovered it was the victim of a ransomware cyberattack in which company files were accessed without authorization. The company secured its systems, contacted the FBI, and began an investigation. An initial notification was sent on July 28, 2021, to three affected Maine residents. In September 2021, the investigation identified an additional 25 affected customers who are Maine residents. The compromised customer information included names, contact information, and DEA and physician state license numbers. A second round of written notifications, including an offer for credit monitoring services, was sent to affected Maine residents on October 6, 2021. The investigation is ongoing, and there is no evidence that the compromised information has been made public or used for identity theft.
- ⛰️New Hampshire State AGvia ACE Surgical Supply Co., Inc.2021-10-12
ACE Surgical Supply Co., Inc. filed a supplemental data breach notification with the New Hampshire Attorney General regarding a ransomware attack discovered on June 29, 2021. The incident affected 58 New Hampshire residents, exposing names, contact info, and DEA/physician license numbers. Notifications were sent on October 6, 2021, offering 24 months of credit monitoring. The investigation is ongoing.
- 🦬Montana State AGvia ACE Surgical Supply Co., Inc.2021-10-06
ACE Surgical Supply Co reported a data breach to the Montana Attorney General. The breach was reported on 2021-10-06. The breach occurred on 6/29/2021. 42 Montana residents were affected.
- 🦞Maine State AGvia ACE Surgical Supply Co., Inc.2021-07-28
ACE Surgical Supply Co., Inc. reported an external system breach (hacking) occurring on June 29, 2021. The incident compromised the names and Social Security Numbers of 284 individuals, including 3 Maine residents. The company notified affected consumers in writing on July 26, 2021, and provided 24 months of complimentary identity protection services through Experian.