INTERNATIONAL BUSINESS MACHINES CORPORATION
ent_019fa1fa7f94ab92d7c5af356a553dfe
Disclosures
9
HHS OCR · State AG · 8 jurisdictions
Multi-filing incidents
3
incidents joining 2+ filings here
Max affected reported
1,900,000
nationwide · HHS OCR NY
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- INTERNATIONAL BUSINESS MACHINES CORPORATION
- Normalized
- international business machines— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- VGRQXHF3J8VDLUA7XE92
- SEC EDGAR CIK
- 0000051143
- Domain
- ibm.com
Disclosure history (9)newest first
- NEW YORKHHS OCRas victim2023-09-29
International Business Machines Corporation reported to HHS on 2023-09-29 a Unauthorized Access/Disclosure affecting 630755 individuals. Breached information located on Other. Business associate present.
- Montana State AGas reporting2023-09-22
IBM notified Johnson & Johnson Health Care Systems, Inc. (Janssen) patients that unauthorized access occurred to the Janssen CarePath database. IBM, a service provider, identified the access on August 2, 2023. Personal information (names) was potentially accessed; SSNs and financial data were not. IBM remediated the vulnerability and offered one-year credit monitoring.
- Delaware State AGas reporting2023-09-22
Johnson & Johnson Health Care Systems, Inc. (Janssen) notified IBM, its service provider, of unauthorized access to the Janssen CarePath database. IBM and a third-party database provider remediated the technical vulnerability and conducted an investigation. The incident, discovered on August 2, 2023, potentially exposed names and government identifiers (e.g., SSN) for approximately 10,000 Rhode Island residents. No financial account or SSN data was in the database. Affected individuals were offered one year of credit monitoring.
- California State AGas victim2023-09-22
IBM disclosed unauthorized access to a database supporting the Janssen CarePath patient support platform. IBM identified the unauthorized access on August 2, 2023, after Janssen notified IBM of a technical method allowing access. IBM remediated the issue and augmented security controls. Affected data may include names and health-related information, but not SSNs or financial account data. IBM offered one year of credit monitoring.
- Vermont State AGas reporting2023-09-15
IBM notified Johnson & Johnson Health Care Systems, Inc. (Janssen) of unauthorized access to the Janssen CarePath database. Access was discovered on August 2, 2023. The scope of access is undetermined. Data potentially exposed includes names and other PII; SSNs and financial data were not in the database. IBM remediated the vulnerability and offered one year of credit monitoring.
- Washington State AGas reporting2023-09-05
Johnson & Johnson Health Care Systems Inc. (Janssen) notified Washington AG of unauthorized access to a third-party database managed by IBM supporting the Janssen CarePath patient platform. Discovered Aug 2, 2023, the breach affected ~53,970 WA residents. Data included names, contact info, DOB, health insurance, and medication data. No SSNs or financial accounts were involved. IBM remediated the vulnerability and offered credit monitoring.
- Illinois State AGas victim2023-01-01
INTERNATIONAL BUSINESS MACHINES CORP. filed a data-breach notice with the Illinois Attorney General during 2023 (case 23-652). The register records the breach as discovered on August 2, 2023. Additional entities named: JANSSEN CAREPATH PLATFORM. Illinois does not publish the number of people affected — 815 ILCS 530/10 permits the Attorney General to publish only the entity name, the types of personal information and the date range.
- NEW YORKHHS OCRas reporting2011-04-14
IBM reported to HHS on 2011-04-14 a breach of unknown type affecting 1,900,000 individuals. Breached information located on Other. Business associate present.
- New Hampshire State AGas reporting2007-04-26
IBM notified the NH Attorney General that data tapes containing archival employment information, including Social Security numbers, for current and former employees were lost during transport by a vendor on February 23, 2007. The incident affected 1,468 New Hampshire residents. IBM determined the loss was inadvertent with no indication of theft or unauthorized access. IBM offered one year of identity theft restoration and credit monitoring services through Kroll Inc. to affected individuals.