Novartis
ent_0e670227cce91044822ee3b6
Massachusetts publishes one register entry per notified resident. Novartis filed 2 breach notifications with the Massachusetts OCA, 2 of them covering a single resident. The register records who filed and how many residents — not where the breach occurred.
Disclosures
6
State AG · 5 jurisdictions
Multi-filing incidents
2
incidents joining 2+ filings here
Max affected reported
1
as filed · State AG MA
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- Novartis
- Normalized
- novartis— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- No match
- SEC EDGAR CIK
- 0001114448
- Domain
- novartis.com
Disclosure history (6)newest first
- Delaware State AGas victim2024-05-22
Cencora, Inc. notified Novartis Pharmaceuticals Corporation patients of a data security incident where personal and health information was exfiltrated from Cencora's systems. The breach, discovered on February 21, 2024, impacted patient support program data including names, addresses, DOB, and prescriptions. Cencora engaged law enforcement and cybersecurity experts, contained the incident, and offered two years of credit monitoring via Experian.
- Vermont State AGas victim2024-05-22
Cencora, Inc., a service provider for Novartis Pharmaceuticals Corporation, notified consumers of a data security incident where personal and health information was exfiltrated from its systems. The incident was discovered on February 21, 2024. Affected data included names, addresses, dates of birth, health diagnoses, and medications. Cencora engaged law enforcement and cybersecurity experts, and is offering two years of free credit monitoring via Experian.
- California State AGas victim2024-05-22
Cencora, Inc. notified California residents of a data breach involving personal health information. On February 21, 2024, Cencora learned that data from its information systems had been exfiltrated. The compromised data potentially included names, addresses, dates of birth, health diagnoses, and medications. Cencora engaged law enforcement and cybersecurity experts, took containment steps, and is offering two years of credit monitoring through Experian.
- Massachusetts State AGas victim2013-08-12
Novartis reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2013-08-12. 1 Massachusetts residents were affected. The report records the breach type as electronic.
- New Hampshire State AGas victim2013-08-05
Novartis Corporation reported the loss of a media storage device (thumb drive) from a limited access area on or about March 4, 2013. The incident affected one New Hampshire resident. Novartis determined through review of archived materials that personal information was involved. The company provided credit monitoring and account review instructions to the affected individual and conducted additional security training for the involved department.
- Massachusetts State AGas victim2010-05-24
Novartis Vaccines and Diagnostics, Inc. reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2010-05-24. 1 Massachusetts residents were affected. The report records the breach type as electronic.
Supply-chain cascadesreviewed and confirmed
- Novartis’s filing is one of at least 8 in the CENCORA, INC. supply-chain incident (2024).