[ad_1]
American pharmaceutical firm Cencora has announced a security breach that led to the theft of delicate personal and medical information of individuals, igniting a notification process to those impacted by the incident.
This week, Cencora started mailing out notifications to individuals whose information, including names, addresses, birth dates, health diagnoses, and medication details, were compromised from the company’s database.
Historically, Cencora had access to this data via its support programs, where it collaborated with pharmaceutical partners such as Abbvie, Acadia, Bayer, and Novartis, among others.
Details regarding the nature of the cyberattack, which started on February 21 and was subsequently reported to regulators on February 27, remain undisclosed by Cencora. Notably, the company, previously known as AmerisourceBergen until 2023, supplies about 20% of all pharmaceuticals in the U.S. market.
Mike Iorfino, a representative for Cencora, has expressed to TechCrunch that the company is not currently revealing the extent of individuals affected or how many have been notified thus far.
The cybersecurity incident at Cencora adds to the string of attacks targeting U.S. healthcare providers, including major breaches at Change Healthcare and Ascension’s network. However, Cencora has stated there is no linkage between these incidents and the breach in their systems.
Documentation sent to state authorities, seen by TechCrunch, discloses that around 500,000 individuals have been informed about the breach by Cencora since its detection. With Cencora having served at least 18 million patients, the full scope of this breach could be significantly larger.
Lack of address information for some of the affected parties has led Cencora to publish a notice on its website rather than sending direct notifications.
Although requests for comments from various partner drug makers have gone unanswered by TechCrunch, a Novartis spokesperson confirmed awareness of the incident but refrained from further commentary or disclosing affected patient counts. Novartis has not been informed about the precise number of their patients involved in the breach by Cencora.
In the past year, Cencora reported a revenue of $262 billion, a 10% increase from the year before, while their cybersecurity investment details remain undisclosed.
For inquiries, please reach out to the reporter through Signal or WhatsApp at +1 646-755-8849, or by email. Secured document submissions can be made via SecureDrop.
[ad_2]
FAQs about the Cencora Data Breach
- What information was stolen in the Cencora data breach?
- The breached data includes patient names, postal addresses, birth dates, health diagnoses, and information about medications.
- How many individuals have been affected by the Cencora data breach?
- While about 500,000 individuals have been notified so far, the exact number of affected persons remains undisclosed. Considering Cencora’s patient services reach, it is expected to be significantly higher.
- Were other pharmaceutical companies involved in the Cencora data breach?
- Yes, other pharmaceutical companies like Abbvie, Acadia, Bayer, and Novartis were involved due to Cencora’s partnership with them. However, the detailed impact on these companies’ patients is not fully known.
- Is there a link between this data breach and other recent cyberattacks on US healthcare facilities?
- Cencora states that there is no connection between this breach and other recent cyberattacks on US healthcare providers.
Conclusion
The breach at Cencora showcases the ever-present vulnerabilities in the digital systems of major healthcare entities and the potential risks to patient privacy. As the situation unfolds, Cencora’s handling of the incident will be critical in restoring trust and securing the personal health information of millions. The ramifications of this breach will likely continue to surface as more details emerge and the full extent of the impact becomes apparent. Stakeholders and patients are encouraged to stay informed and take necessary steps to protect their personal information.










































