Lash Group (affiliate of Cencora, Inc.)
ent_ab05e8fc7748fc5e5a5526ad
Disclosures
2
State AG · 1 jurisdiction
Multi-filing incidents
—
no multi-filing incident in sample
Max affected reported
—
no filed count in sample
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- Lash Group (affiliate of Cencora, Inc.)
- Normalized
- lash group affiliate of cencora— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- No match
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- None on record
Disclosure history (2)newest first
- California State AGas victim2024-06-20
On February 21, 2024, Cencora, Inc. discovered that data from its information systems had been exfiltrated. The incident involved Lash Group, a Cencora affiliate that had held personal information through a prior partnership with CareDx, Inc. Affected data may include names, addresses, dates of birth, Social Security Numbers, and diagnostic test indicators. Cencora notified CareDx on May 22, 2024. Affected individuals were offered 24 months of Experian IdentityWorks credit monitoring.
- California State AGas victim2024-05-17
Cencora, Inc. and its Lash Group affiliate reported that on February 21, 2024, data was exfiltrated from Cencora's information systems, including personal information of patients enrolled in Bristol Myers Squibb and BMS Patient Assistance Foundation programs. Potentially affected data included name, address, date of birth, health diagnosis, and medications/prescriptions. Cencora engaged cybersecurity experts, law enforcement, and outside counsel. Notification letters dated May 17, 2024 were sent to affected individuals with offers of 24-month Experian identity monitoring.