Johnson and Johnson Health Care Systems, Inc.
ent_ffb670bf842255692d72442d
Disclosures
4
State AG · 3 jurisdictions
Incidents
1
filings grouped by incident
Max affected reported
10,296
as filed · State AG IN
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- Johnson and Johnson Health Care Systems, Inc.
- Normalized
- johnson and johnson health care— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- No match
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- None on record
Disclosure history (4)newest first
- 🏎️Indiana State AGas victim2024-05-28
Johnson & Johnson Services Inc reported a data breach to the Indiana Attorney General. The breach occurred on 2024-02-21 and was reported on 2024-05-28. 10,296 Indiana residents were affected.
- 💎Delaware State AGas victim2023-09-22
Johnson & Johnson Health Care Systems, Inc. (Janssen) experienced unauthorized access to a database supporting the Janssen CarePath patient support platform. The database was managed by third-party provider IBM. The incident involved a technical method allowing unauthorized access, identified on August 2, 2023. Affected data included names and potentially other personal information, though SSNs and financial account numbers were explicitly excluded. IBM and Janssen remediated the vulnerability and augmented security controls. Affected individuals were offered one year of credit monitoring. The notice covers residents of multiple states, including Delaware, New York, and Maryland.
- 💎Delaware State AGas victim2023-09-22
Johnson & Johnson Health Care Systems, Inc. (Janssen) notified IBM, its service provider, of unauthorized access to the Janssen CarePath database. IBM and a third-party database provider remediated the technical vulnerability and conducted an investigation. The incident, discovered on August 2, 2023, potentially exposed names and government identifiers (e.g., SSN) for approximately 10,000 Rhode Island residents. No financial account or SSN data was in the database. Affected individuals were offered one year of credit monitoring.
- 🍁Vermont State AGas victim2023-09-15
IBM notified Johnson & Johnson Health Care Systems, Inc. (Janssen) of unauthorized access to the Janssen CarePath database. Access was discovered on August 2, 2023. The scope of access is undetermined. Data potentially exposed includes names and other PII; SSNs and financial data were not in the database. IBM remediated the vulnerability and offered one year of credit monitoring.