IBM breach exposed Johnson & Johnson's Janssen CarePath patient data

Organization
Johnson & Johnson
Exploit
Third-Party Data Breach
Industry
Pharmaceuticals

Johnson & Johnson Health Care Systems disclosed in September 2023 that Janssen CarePath, its patient support program for prescription medicines, had been affected by a security incident at IBM, the vendor that manages the program's database.

According to IBM, Janssen became aware of a technical method that could be used to reach the CarePath database without authorization and immediately notified IBM. IBM did not give a date for that alert. It said its investigation identified on August 2, 2023 that unauthorized access to personal information in the database had occurred. IBM said it worked with the database provider to disable that method and to add further security controls.

The database held patient names together with contact details, dates of birth, health insurance details, and information about medications and the conditions they treated. IBM said Social Security numbers and financial account information were not stored there and were not affected, and that it had no indication the information had been misused. IBM also said it could not determine whether data had actually been extracted.

IBM published a notice on September 6, 2023 and began sending letters to affected CarePath users and healthcare providers, offering twelve months of complimentary credit monitoring and opening two dedicated telephone lines, one for providers and one for individuals. Neither company gave a total number of affected people at the time. The HIPAA Journal noted that roughly 1.16 million patients had used CarePath during 2022.

A proposed class action naming both IBM and Johnson & Johnson Health Care Systems was filed in the Southern District of New York on September 22, 2023.

Sources