BRISTOL-MYERS SQUIBB COMPANY
ent_019e87892f2660949d976488e81bee72
Disclosures
7
State AG · 7 jurisdictions
Multi-filing incidents
2
incidents joining 2+ filings here
Max affected reported
78,516
as filed · State AG IN
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- BRISTOL-MYERS SQUIBB COMPANY
- Normalized
- bristol myers squibb— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- HLYYNH7UQUORYSJQCN42
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- None on record
Disclosure history (7)newest first
- 🍁Vermont State AGas victim2024-05-17
Cencora, Inc. notified Bristol Myers Squibb Company and the Bristol Myers Squibb Patient Assistance Foundation of a data security incident discovered on Feb 21, 2024. Personal information including names, addresses, DOBs, health diagnoses, and medications was exfiltrated from Cencora's systems. Cencora engaged law enforcement and cybersecurity experts, offered 24 months of credit monitoring, and is reinforcing security protocols.
- 🐻California State AGas victim2024-05-17
Cencora, Inc. and its Lash Group affiliate reported that on February 21, 2024, data was exfiltrated from Cencora's information systems, including personal information of patients enrolled in Bristol Myers Squibb and BMS Patient Assistance Foundation programs. Potentially affected data included name, address, date of birth, health diagnosis, and medications/prescriptions. Cencora engaged cybersecurity experts, law enforcement, and outside counsel. Notification letters dated May 17, 2024 were sent to affected individuals with offers of 24-month Experian identity monitoring.
- 🏎️Indiana State AGas victim2024-05-17
Bristol Myers Squibb Co and Bristol Myers Squibb Patient Assistance Foundation reported a data breach to the Indiana Attorney General. The breach occurred on 2024-02-21 and was reported on 2024-05-17. 78,516 Indiana residents were affected.
- 💎Delaware State AGas victim2024-05-17
Cencora, Inc. notified Bristol Myers Squibb Company patients that on February 21, 2024, data was exfiltrated from Cencora's information systems. The incident potentially affected personal information including names, addresses, dates of birth, health diagnoses, and medications. Cencora took containment steps, engaged law enforcement and cybersecurity experts, and is offering 24 months of credit monitoring through Experian. No evidence of misuse was found at the time of notification.
- ⛰️New Hampshire State AGas victim2023-07-03
Bristol Myers Squibb notified New Hampshire AG of a MOVEit vulnerability exploitation. Unauthorized access occurred as early as May 27, 2023. Data of 5 NH residents, including SSNs and names, was exfiltrated. BMS engaged law enforcement, patched the vulnerability, and offered 24 months of credit monitoring.
- 🌲Washington State AGas victim2023-06-30
Bristol Myers Squibb, a health sector entity reported a malware incident to the Washington Attorney General. The organization became aware of the incident on 2023-05-31 and filed notice on 2023-06-30. 2,231 Washington residents were affected. 30 days elapsed between awareness and notification. 4 days to identify the breach.
- 🦬Montana State AGas victim2023-06-29
Bristol Myers Squibb reported a data breach to the Montana Attorney General. The breach was reported on 2023-06-29. The breach occurred from 5/27/2023 to 6/1/2023. 1 Montana residents were affected.
Subsidiary disclosures (0)filed by group companies
◈ These filings were made by or about subsidiaries of BRISTOL-MYERS SQUIBB COMPANY — not by BRISTOL-MYERS SQUIBB COMPANY itself. Corporate relationships are mapped from GLEIF relationship records and SEC Exhibit 21 filings.
No disclosures on record for BRISTOL-MYERS SQUIBB COMPANY’s tracked subsidiaries yet.