Confirmed breach. discovered Aug 2, 2023 — the first regulatory filing landed 34 days later. 4,196,185 individuals reported across the linked filings.
incident inc_5f4843666c684a95 · merge_method human · confidence 100%
Litigation Timing
Notification delay
34days
Discovered → first regulatory filing
Filing span
10days
Time between earliest and latest filing
Not recorded for this incident
Discovery variance · Leak precedence · Materiality delta · SEC filing delay — no leak-site claim in this cluster; no SEC 8-K in this cluster; needs two dated filings.
Regulatory clocksWashington⏱ WA AG >30dFull clock table in Litigation Timeline
State AGConfirmedLifecycle stage 2 of 3: ConfirmedUnverified claimConfirmedEnforced
Affected (total reported)
4,196,185
Data types
—
Jurisdictions
2
OR WA
Linked filings
2
all State AG
Timeline
Earliest sighting first · deep chronology in Litigation Timeline
Johnson & Johnson Health Care Systems Inc. (“Janssen”), a health sector entity reported a unauthorized access incident to the Washington Attorney General. The organization became aware of the incident on 2023-08-02 and filed notice on 2023-09-05. 53,970 Washington residents were affected. 34 days elapsed between awareness and notification.
Affected (this filing): 53,970
WA AG >30d
🦫Oregon State AGMost recentlinked via operator-confirmed · 100%
Johnson & Johnson Health Care Systems Inc. (“Janssen”) reported a data breach to the Oregon Attorney General. The breach was reported on 2023-09-15. 4,142,215 individuals were affected.
Affected (this filing): 4,142,215
About this clustering
DisclosureLens links filings into incidents through layered matchers: deterministic rules (same source document, multistate filings of one breach, tight-window same-victim pairs), a weighted-similarity scorer for cross-source candidates, and an operator review queue for everything uncertain. Each link records its own method and confidence — shown per filing in the timeline below. The system defaults to NOT merging when uncertain, because a false merge (collapsing two unrelated breaches) is more harmful than a false split (showing related filings separately); uncertain pairs route to human review instead of auto-merging. Filing summaries shown in the timeline are AI-generated extracts — verify each against its linked source.