Clustered 4 filings across 4 jurisdictions · filed May 17, 2024. View entity profile → Other incidents for this victim →
incident inc_812ba08681a34305 · merge_method deterministic · confidence 100%
Discovered → first regulatory filing
Range of discovered_at dates across filings
Identity (basic) · Government ID · Health (basic)
Time between earliest and latest filing
Not recorded for this incident
Leak precedence · Materiality delta · SEC filing delay — no leak-site claim in this cluster; no SEC 8-K in this cluster.
CA DE IN VT
all State AG
Earliest sighting first · deep chronology in Litigation Timeline
Feb 21, 2024
When the intrusion reportedly occurred, per the linked filings
Feb 21, 2024
Reported by VERMONT AG, DELAWARE AG filings
About this clustering
DisclosureLens links filings into incidents through layered matchers: deterministic rules (same source document, multistate filings of one breach, tight-window same-victim pairs), a weighted-similarity scorer for cross-source candidates, and an operator review queue for everything uncertain. Each link records its own method and confidence — shown per filing in the timeline below. The system defaults to NOT merging when uncertain, because a false merge (collapsing two unrelated breaches) is more harmful than a false split (showing related filings separately); uncertain pairs route to human review instead of auto-merging. Filing summaries shown in the timeline are AI-generated extracts — verify each against its linked source.
Cencora, Inc. notified Bristol Myers Squibb Company and the Bristol Myers Squibb Patient Assistance Foundation of a data security incident discovered on Feb 21, 2024. Personal information including names, addresses, DOBs, health diagnoses, and medications was exfiltrated from Cencora's systems. Cencora engaged law enforcement and cybersecurity experts, offered 24 months of credit monitoring, and is reinforcing security protocols.
Cencora, Inc. and its Lash Group affiliate reported that on February 21, 2024, data was exfiltrated from Cencora's information systems, including personal information of patients enrolled in Bristol Myers Squibb and BMS Patient Assistance Foundation programs. Potentially affected data included name, address, date of birth, health diagnosis, and medications/prescriptions. Cencora engaged cybersecurity experts, law enforcement, and outside counsel. Notification letters dated May 17, 2024 were sent to affected individuals with offers of 24-month Experian identity monitoring.
Bristol Myers Squibb Co and Bristol Myers Squibb Patient Assistance Foundation reported a data breach to the Indiana Attorney General. The breach occurred on 2024-02-21 and was reported on 2024-05-17. 78,516 Indiana residents were affected.
Affected (this filing): 78,516
Cencora, Inc. notified Bristol Myers Squibb Company patients that on February 21, 2024, data was exfiltrated from Cencora's information systems. The incident potentially affected personal information including names, addresses, dates of birth, health diagnoses, and medications. Cencora took containment steps, engaged law enforcement and cybersecurity experts, and is offering 24 months of credit monitoring through Experian. No evidence of misuse was found at the time of notification.