Security

US pharma giant Cencora says Americans’ health information stolen in data breach

Comment

a photo of cencora's logo at the top of its headquarters in PA
Image Credits: JHVEPhoto / Getty Images

U.S. pharmaceutical giant Cencora says it is notifying affected individuals that their personal and highly sensitive medical information was stolen during a cyberattack and data breach earlier this year. 

In letters to affected individuals sent out this week, Cencora said that the data from its systems includes patient names, their postal address and date of birth, as well as information about their health diagnoses and medications.

The pharma giant said it had initially obtained patients’ data through partnerships with the drug makers it works with “in connection with its patient support programs.” That includes patients of AbbVie, Acadia, Bayer, Novartis, Regeneron, and other companies.

Cencora has not yet described the nature of the cyberattack, which began on February 21 and was not publicly disclosed until the company filed notice with government regulators a week later on February 27. The company, known as AmerisourceBergen until 2023, handles around 20% of the pharmaceuticals sold and distributed throughout the United States.

Cencora spokesperson Mike Iorfino told TechCrunch in an email that Cencora was unwilling to say if the company has determined how many individuals are affected by the breach and how many individuals the company has notified to date.

This is the latest security incident to hit the U.S. healthcare sector following a spate of cyberattacks in recent months, following the huge data breach and lasting outages at UnitedHealth-owned Change Healthcare and the recent and ongoing cyberattack that knocked much of Ascension’s hospital network offline.

Cencora’s spokesperson said there is “no connection” between the incident at Cencora and the cyberattacks at Change and Ascension.

According to the public data breach notifications filed by Cencora with U.S. state authorities, which TechCrunch has seen, Cencora has so far notified about half a million individuals since learning of the data breach. The number of individuals affected by the Cencora data breach is expected to be far higher. Cencora says on its website that it has served at least 18 million patients to date.

Cencora said it published a notice on its website explaining that the company “does not have address information to provide direct notice” for some individuals affected by the data breach.

Spokespeople for the affected drug makers AbbVie, Acadia, Bayer, and Regeneron did not return a request for comment from TechCrunch. 

Novartis spokesperson Michael Meo confirmed Novartis was “recently made aware of a cyber incident involving the patient services companies Cencora and its affiliate, Innomar Strategies in Canada, which have both provided services for Novartis,” but declined to comment further or say how many Novartis patients are affected by the data breach. The spokesperson declined to say whether Cencora has told Novartis how many of its patients are affected.

Cencora made $262 billion in revenue during 2023, up 10% on the previous year, according to its latest financials. The company did not say how much it spends on cybersecurity.

Updated at 10:15 a.m. to amend the headline.


To contact this reporter, get in touch on Signal and WhatsApp at +1 646-755-8849, or by email. You can also send files and documents via SecureDrop.

More TechCrunch

WhatsApp’s massive 500 million users in India have supercharged Meta’s AI ambitions. Meta CFO Susan Li said Wednesday that India is the largest market in terms of Meta AI usage,…

Meta says India is the largest market for Meta AI usage

While venture capitalists and the rest of the technorati are off on holiday or attending the Paris Olympics, the U.S. Securities and Exchange Commission and its staff attorneys are keeping…

Founder behind social media app IRL charged with fraud

The serious, long-term negative impact of the bankruptcy of banking-as-a-service (BaaS) fintech Synapse will be significant “on all of fintech, especially consumer-facing services,” one observer has said. In the wake…

Fintech Execs from Synctera, Unit, and Treasury Prime discuss the future of BaaS at TechCrunch Disrupt 2024 

Google has released a trio of new, “open” generative AI models that it’s calling “safer,” “smaller” and “more transparent” than most — a bold claim, to be sure. They’re additions…

Google releases new ‘open’ AI models with a focus on safety

Look, we’ve all been there. You’re on a road trip and you pull off the highway for some food or fuel. And then Google Maps starts (rudely) yelling at you…

Google Maps announces new features and somehow none of them are ‘pause navigation’

AI lobbying at the U.S. federal level is intensifying in the midst of a continued generative AI boom and an election year that could influence future AI regulation. New data…

AI startups ramp up federal lobbying efforts

Bungie, the gaming company that created sci-fi hits such as Halo, Destiny, and Marathon, has laid off 220 employees, roughly a 17% reduction to its workforce, the company announced Wednesday.…

Bungie employees say they were caught off-guard by 17% staff reduction

The U.S. Copyright Office has issued the first part of a report on how AI may affect its domain, and its first recommendation out of the gate is: we need…

Copyright Office tells Congress: ‘Urgent need’ to outlaw AI-powered impersonation

Featured Article

A comprehensive list of 2024 tech layoffs

The tech layoff wave is still going strong in 2024. Following significant workforce reductions in 2022 and 2023, this year has already seen 60,000 job cuts across 254 companies, according to independent layoffs tracker Layoffs.fyi. Companies like Tesla, Amazon, Google, TikTok, Snap and Microsoft have conducted sizable layoffs in the…

A comprehensive list of 2024 tech layoffs

ChatGPT, OpenAI’s text-generating AI chatbot, has taken the world by storm since its launch in November 2022. What started as a tool to hyper-charge productivity through writing essays and code…

ChatGPT: Everything you need to know about the AI-powered chatbot

If you are on the developer beta, you can only use Apple Intelligence features if your language is set to U.S. English and region is set to U.S.

How to enable Apple Intelligence on your iPhone

Hiya, folks, welcome to TechCrunch’s regular AI newsletter. This week in AI, Gartner released a report suggesting that around a third of generative AI projects in the enterprise will be…

This Week in AI: Companies are growing skeptical of AI’s ROI

More than 100 VCs, including Reid Hoffman, Vinod Khosla and Mark Cuban have pledged to vote for Vice President Kamala Harris in the upcoming U.S. presidential election. Mobilizing under the…

Over 100 VCs pledge support for Kamala Harris

Match Group announced Tuesday that it has discontinued livestreaming services in its dating apps, resulting in a 6% reduction in workforce. The news was delivered during the dating app giant’s second-quarter…

Match Group cuts 6% of staff as it shuts down livestreaming in dating apps

This week’s video shows 4NE-1 doing a lot; in some sense, it’s doing more than we’ve seen from other humanoids in the space.

Neura shows off humanoid robot 4NE-1

Bending Spoons said that it will continue reserving 30% of WeTransfer’s advertising space to give back campaigns and editorial content.

Bending Spoons acquires file transfer service WeTransfer

AI agents are all the rage right now, and Tezi, an early-stage startup, is working on one to help HR teams find the perfect candidates for a job opening. The…

Tezi is building an AI agent for hiring managers

Sybill, a startup that has built an AI assistant specifically for sales reps, has raised $11 million in a Series A round led by Greycroft.

Sybill raises $11M for its AI assistant that helps salespeople reduce administrative burden

Date Like Goblins is geared toward the gaming community and allows users to connect through voice chat while playing video games.

Date Like Goblins, a new dating platform, allows users to virtually date and play video games

Farms produce a lot of data. From machines to irrigation systems, farms generate a lot of information that could be helpful to both them and the companies that serve them.…

Leaf helps farms decipher the troves of data they generate

The startup has raised $21.5 million to build more of its machines and deploy them throughout the U.S.

Applied Carbon’s farm robot turns plant waste into biochar to capture CO2

You can even upload a screenshot of a ticket, or a list of cities you are visiting and ask Mindtrip’s assistant to suggest places to visit, bars and restaurants.

Travel startup Mindtrip’s new feature lets you build an itinerary from a screenshot, YouTube or TikTok video

Checkly helps devs get signals about an app’s performance and downtime, offering a set of subscription-based synthetic monitoring tools.

Checkly tests software by mimicking the way people use it

Lightrun also on Wednesday disclosed an $18 million SAFE round it raised last year, bringing Lightrun’s total funding to date to $45 million.

Lightrun launches its AI debugger to help developers fix their production code

Threads users in the U.S. can now see a label that highlights related trending topics above posts.

Threads now highlights relevant trending topics above posts

Badoo, Bumble, Grindr, happn, Hinge and Hily all had the same flaw that could have helped a malicious user identify the near-exact location of another user.

Bumble and Hinge allowed stalkers to pinpoint users’ locations down to 2 meters, researchers say

Alex Cook, a partner at Tiger Global who oversaw some of its largest fintech investments and India deals, is departing the firm after a tenure of nearly seven years, three…

Tiger Global partner Alex Cook to leave firm, sources say

A lot of AI bills are flying around Congress these days, and OpenAI is throwing its weight behind some of them. OpenAI endorsed three Senate bills on Tuesday which could…

OpenAI endorses Senate bills that could shape America’s AI policy

The software supply chain faces threats from all sides. A 2024 report by the Ponemon Institute found that over half of organizations have experienced a software supply chain attack, with…

Lineaje raises $20M to help organizations combat software supply chain threats

The founder of once-hyped crypto startup BitClout is facing trouble. On Tuesday, the SEC charged him with fraud and other offenses.

SEC charges BitClout founder Nader Al-Naji with fraud; says proceeds paid for L.A. mansion, gifts