Eleven drug companies disclose patient data loss from Cencora breach

Organization
Cencora
Exploit
Hacking
Industry
Pharmaceutical Services

Eleven pharmaceutical companies filed breach notifications with the California Attorney General's office in May 2024, disclosing that patient information they had entrusted to drug distributor Cencora had been taken in an intrusion earlier that year.

Cencora said it detected unauthorized activity in its information systems on 21 February 2024 and disclosed the event in a filing with the U.S. Securities and Exchange Commission a week later, adding that the incident had not had a material effect on its operations. Data was exfiltrated from the company's network. Investigators concluded their work in mid-April 2024, and on 18 April the Lash Group, Cencora's patient support affiliate, told the drugmakers whose records were involved.

The notifications said the exposed information could include a patient's first and last name, postal address, date of birth, health diagnosis, and medications or prescriptions. Cyber Daily identified the eleven companies as Bayer, Novartis, Regeneron, AbbVie, Incyte, Genentech, Sumitomo Pharma America, GlaxoSmithKline, Acadia, Endo and Dendreon.

Cencora said it took containment steps immediately and opened an investigation with law enforcement, outside cybersecurity experts and external counsel, and stated there was no evidence the information had been publicly disclosed or misused. Affected individuals were offered 24 months of credit monitoring and remediation services through Experian. Class action filings were being prepared as the notifications became public.

Sources