CARDINAL HEALTH, INC.
ent_019f8aaa95d3ae2d58fdd1e43e627d77
Disclosures
1
State AG · 1 jurisdiction
Incidents
—
no linked incident in sample
Max affected reported
56
nationwide · State AG IN
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- CARDINAL HEALTH, INC.
- Normalized
- cardinal health— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- CCU46N3GJMF4OK4N7U60
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- None on record
Disclosure history (1)newest first
Subsidiary disclosures (7)filed by group companies
◈ These filings were made by or about subsidiaries of CARDINAL HEALTH, INC. — not by CARDINAL HEALTH, INC. itself. Corporate relationships are mapped from GLEIF relationship records and SEC Exhibit 21 filings.
- 🌲Washington State AGvia mscripts2023-03-14
mscripts, LLC, a health sector entity reported a theft or mistake incident to the Washington Attorney General. The organization became aware of the incident on 2022-11-18 and filed notice on 2023-03-14. 1,394 Washington residents were affected. 116 days elapsed between awareness and notification. 2240 days to identify the breach. 0 days to contain the breach.
- 🦬Montana State AGvia mscripts2023-03-14
mscripts reported a data breach to the Montana Attorney General. The breach was reported on 2023-03-14. The breach occurred from 9/30/2016 to 11/18/2022. 179 Montana residents were affected.
- 🐻California State AGvia mscripts2023-03-14
mscripts, LLC disclosed a misconfiguration of its cloud storage that left prescription management files accessible without authentication from September 30, 2016, to November 18, 2022. The exposed data included patient names, addresses, dates of birth, phone numbers, and prescription details (medication names, refill status). No SSNs or financial data were involved. mscripts engaged forensic investigators and changed access settings upon discovery.
- 🦫Oregon State AGvia mscripts2023-03-14
mscripts, LLC reported a data breach to the Oregon Attorney General. The breach was reported on 2023-03-14. The breach occurred during 9/30/2016 - 11/18/2022. The breach was discovered on 1/13/2023. 5,725 individuals were affected. Notice was sent on 3/14/2023.
- OHHHS OCRvia RGH Enterprises, Inc.2019-07-05
RGH Enterprises, Inc. d/b/a Edgepark Medical Supplies (OH) reported to HHS on 2019-07-05 a Hacking/IT Incident affecting 6,572 individuals. Breached ePHI was located on a Network Server and included names, dates of birth, addresses, health insurance information, and purchasing data. The CE implemented additional technical safeguards as mitigation and notified affected individuals, media, and posted a substitute notice on its website.
- FEDERALHHS OCRvia RGH Enterprises, Inc.2018-01-22
RGH Enterprises, Inc. reported to HHS on January 22, 2018, that a spreadsheet formatting error led to mailings being sent to the wrong patients. This unauthorized disclosure of protected health information (PHI), including patient names, affected 4,586 individuals. The company has since implemented new quality assurance procedures, retrained the responsible employee, and notified those affected.
- OHHHS OCRvia RGH Enterprises, Inc.2014-01-13
Computer hackers installed malware on the covered entity's website that intercepted ePHI of approximately 4,230 individuals, including names, DOBs, contact details, partial payment-card data, primary physicians, diagnoses, order histories, and health insurer information. The entity removed the malware from affected servers and migrated the website to non-compromised infrastructure. Reported to HHS OCR on 2014-01-13.