CARDINAL HEALTH, INC.
ent_019f8aaa95d3ae2d58fdd1e43e627d77
Disclosures
5
State AG · 3 jurisdictions
Multi-filing incidents
1
incidents joining 2+ filings here
Max affected reported
56
nationwide · State AG IN
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- CARDINAL HEALTH, INC.
- Normalized
- cardinal health— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- CCU46N3GJMF4OK4N7U60
- SEC EDGAR CIK
- 0000721371
- Domain
- None on record
Disclosure history (5)newest first
- Indiana State AGas victim2025-04-30
Cardinal Health Inc reported a data breach to the Indiana Attorney General. The breach occurred on 2024-10-30 and was reported on 2025-04-30. 3 Indiana residents were affected. 56 individuals affected in total.
- Massachusetts State AGas victim2016-11-17
Cardinal Health, Inc. reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2016-11-17. 1 Massachusetts residents were affected. The report records the breach type as electronic.
- New Hampshire State AGas victim2010-10-08
Cardinal Health notified the NH AG of a security incident at its Grand Prairie, TX facility. An IT employee improperly disposed of/sold decommissioned computers. Investigation revealed 60 missing computers; 2 contained SSNs and employee numbers. 3 NH residents affected. Employee terminated. Remediation includes laptop encryption, policy revisions, and credit monitoring offered to affected individuals.
- Massachusetts State AGas victim2010-09-13
Cardinal Health reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2010-09-13. 3 Massachusetts residents were affected. The report records the breach type as electronic.
- New Hampshire State AGas victim2010-09-07
Cardinal Health notified the NH Attorney General of a data security event involving the loss of decommissioned computers. An IT employee admitted to selling a laptop on eBay, leading to an inventory audit that revealed 9 laptops and 2 desktops were missing. One missing laptop contained personal information (SSN, birth date, employee number) for current/former employees and job applicants. Approximately 4 New Hampshire residents were affected. The employee was terminated, and remediation steps included policy revisions, surveillance installation, and mandatory training. Credit monitoring was offered to affected individuals.
Subsidiary disclosures (newest 10)filed by group companies
◈ These filings were made by or about subsidiaries of CARDINAL HEALTH, INC. — not by CARDINAL HEALTH, INC. itself. Corporate relationships are mapped from GLEIF relationship records and SEC Exhibit 21 filings.
- Washington State AGvia MSCRIPTS2023-03-14
mscripts, LLC, a business associate of Safeway, disclosed a misconfiguration in cloud storage access settings that exposed patient data (names, DOB, prescription info) from Sept 2022 to Nov 2022. 1,394 Washington residents were notified in March 2023. No SSN or financial data was involved.
- Montana State AGvia MSCRIPTS2023-03-14
mscripts, a prescription management vendor, disclosed that unauthenticated internet access to its cloud storage exposed patient data (names, DOB, addresses, prescription details) from Sept 2016 to Nov 2022. The incident was discovered on Nov 18, 2022. Forensic investigators were engaged. No SSN or financial data was involved.
- California State AGvia MSCRIPTS2023-03-14
mscripts, LLC disclosed a misconfiguration of its cloud storage that left prescription management files accessible without authentication from September 30, 2016, to November 18, 2022. The exposed data included patient names, addresses, dates of birth, phone numbers, and prescription details (medication names, refill status). No SSNs or financial data were involved. mscripts engaged forensic investigators and changed access settings upon discovery.
- Oregon State AGvia MSCRIPTS2023-03-14
mscripts, LLC reported a data breach to the Oregon Attorney General. The breach was reported on 2023-03-14. The breach occurred during 9/30/2016 - 11/18/2022. The breach was discovered on 1/13/2023. 5,725 individuals were affected. Notice was sent on 3/14/2023.
- CALIFORNIAHHS OCRvia MSCRIPTS2023-01-17
mscripts®, LLC reported to HHS on 2023-01-17 a Unauthorized Access/Disclosure affecting 88,923 individuals. Breached information located on Network Server. The business associate reported that a cloud storage asset lacked appropriate security safeguards that could have allowed the unauthorized access to the protected health information (PHI) of 88,923 individuals. The PHI involved included names, dates of birth, addresses, medication information, and health insurance information.
- Illinois State AGvia MSCRIPTS2023-01-01
MSCRIPTS filed a data-breach notice with the Illinois Attorney General during 2023 (case 23-086). The register records the breach as discovered on September 30, 2016. Illinois does not publish the number of people affected — 815 ILCS 530/10 permits the Attorney General to publish only the entity name, the types of personal information and the date range.
- Illinois State AGvia MSCRIPTS2023-01-01
MSCRIPTS filed a data-breach notice with the Illinois Attorney General during 2023 (case 23-074). The register records the breach as discovered on September 30, 2016. Illinois does not publish the number of people affected — 815 ILCS 530/10 permits the Attorney General to publish only the entity name, the types of personal information and the date range.
- OHIOHHS OCRvia RGH Enterprises, Inc.2019-07-05
RGH Enterprises, Inc. d/b/a Edgepark Medical Supplies (OH) reported to HHS on 2019-07-05 a Hacking/IT Incident affecting 6,572 individuals. Breached ePHI was located on a Network Server and included names, dates of birth, addresses, health insurance information, and purchasing data. The CE implemented additional technical safeguards as mitigation and notified affected individuals, media, and posted a substitute notice on its website.
- Illinois State AGvia RGH Enterprises, Inc.2019-01-01
RGH ENTERPRISES, INC DBA. EDGEPARK MEDICAL SUPPLIES filed a data-breach notice with the Illinois Attorney General during 2019 (case 2019-248). The register records the breach as discovered on May 13, 2019. Illinois does not publish the number of people affected — 815 ILCS 530/10 permits the Attorney General to publish only the entity name, the types of personal information and the date range.
- OHIOHHS OCRvia RGH Enterprises, Inc.2018-01-22
RGH Enterprises, Inc. reported to HHS on January 22, 2018, that a spreadsheet formatting error led to mailings being sent to the wrong patients. This unauthorized disclosure of protected health information (PHI), including patient names, affected 4,586 individuals. The company has since implemented new quality assurance procedures, retrained the responsible employee, and notified those affected.