Johnson & Johnson Patient Assistance Foundation, Inc.
ent_27dc586b15a7ef3354e12b53
Disclosures
4
State AG · 4 jurisdictions
Multi-filing incidents
2
incidents joining 2+ filings here
Max affected reported
39,733
as filed · State AG IN
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- Johnson & Johnson Patient Assistance Foundation, Inc.
- Normalized
- johnson johnson patient assistance— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- No match
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- None on record
Disclosure history (4)newest first
- California State AGas reporting2024-05-28
On February 21, 2024, Cencora, Inc. discovered that data had been exfiltrated from its information systems. Affected data included personal and health information processed by its Lash Group affiliate in connection with patient support programs, including names, addresses, dates of birth, health diagnoses, and medications/prescriptions. Notifications were sent to affected individuals on May 28, 2024, and 24 months of Experian credit monitoring were offered.
- Washington State AGas reporting2024-05-28
Cencora, Inc. reported a cybersecurity incident on February 21, 2024, involving the exfiltration of personal information from its information systems. The breach affected patient support program data, including names, addresses, dates of birth, health diagnoses, and medications. Cencora engaged law enforcement and cybersecurity experts, contained the incident, and offered 24 months of credit monitoring to affected individuals.
- Indiana State AGas victim2024-05-28
Johnson & Johnson Patient Assistance Foundation Inc reported a data breach to the Indiana Attorney General. The breach occurred on 2024-02-21 and was reported on 2024-05-28. 39,733 Indiana residents were affected.
- Montana State AGas reporting2024-05-28
Cencora, Inc. notified Montana residents of a data security incident discovered on February 21, 2024, where data was exfiltrated from its information systems. The incident potentially exposed personal information including names, addresses, dates of birth, health diagnoses, and medications. Cencora engaged law enforcement and cybersecurity experts, contained the incident, and offered 24 months of credit monitoring.