IBM notified Johnson & Johnson Health Care Systems, Inc. (Janssen) of unauthorized access to the Janssen CarePath database. Access was discovered on August 2, 2023. The scope of access is undetermined. Data potentially exposed includes names and other PII; SSNs and financial data were not in the database. IBM remediated the vulnerability and offered one year of credit monitoring.