The Tool Desk
Outbyte PC Repair FREERepair Windows errors before they cause bigger problemsFix Now →Outbyte Driver Updater FREEFix the driver behind crashes, sound loss and screen glitchesFind Drivers →Cencora, formerly AmerisourceBergen, disclosed that unauthorized parties took (“exfiltrated”) data from its systems on or before February 21, 2024. The company later confirmed that the stolen material included personally identifiable information (PII) and protected health information (PHI), much of it handled by its Lash Group patient-support business. Depending on the person and program, records may have included names, addresses, birth dates, Social Security numbers, diagnoses, medications, prescriptions, insurance details or evidence that a diagnostic test was performed.
A related federal class-action settlement received final approval by July 23, 2026. The settlement website says it created a $40 million fund and expected distributions to begin in August 2026, subject to claim processing. Eligibility and payment amounts are governed by the official settlement terms.
What happened at Cencora?
Cencora said it learned on February 21, 2024 that data had been exfiltrated from its information systems. “Exfiltrated” means unauthorized parties copied or removed data from systems; it does not, by itself, identify the attacker, malware or whether the data was published.
Cencora filed an initial Form 8-K with the U.S. Securities and Exchange Commission on February 27, 2024. That filing did not initially describe the full data categories or affected population. After further investigation, an amendment filed July 31, 2024 said personally identifiable and protected health information was included in most of the reviewed exfiltrated data. The filings are available at Cencora’s February SEC disclosure and July SEC amendment.
Free tools Windows power users keep installed
One-click scans. No signup required.
#1 Best Overall
Why could a patient’s information have been in Cencora’s systems?
Cencora is a pharmaceutical wholesaler and healthcare-services company. Its Lash Group and related businesses administer patient-support, therapy-access, copay, adherence and specialty-pharmacy programs for pharmaceutical manufacturers, pharmacies and healthcare providers. Manufacturers or providers may have supplied information to those programs, so a person could be affected without ever knowingly contacting Cencora or Lash Group.
The company’s incident notice explains the patient-support connection and the company’s response.
What information may have been stolen?
Not every person’s record contained every element. Notices describe information that may have included:
| Data category | Examples and qualification |
|---|---|
| Identity and contact | First and last name, postal address and date of birth. |
| Government identifier | Social Security number for some individuals, not everyone. |
| Health information | Diagnosis, medications, prescriptions, health or insurance information. |
| Testing-related information | An indication that a diagnostic test may have been performed. Lash Group said there was no evidence that diagnostic-test results were involved. |
| Other categories in settlement materials | Potential financial, transactional, demographic, electronic-identifier or biometric information; the applicable categories depend on the person and record. |
These descriptions do not mean complete medical records were taken or that every listed item applied to every individual. A sample state notice is available from Massachusetts (2024-989), and another from Massachusetts (2024-1180).
How many people were affected?
There is no single publicly confirmed total that cleanly covers Cencora, Lash Group and every pharmaceutical-partner notice.
- More than 250,000: This figure appears in an HHS breach listing associated with an AmerisourceBergen Specialty Group entity. It should not automatically be treated as the final Cencora-wide count.
- Partner notices: Secondary reporting identified roughly 40 related partner disclosures, but those notices may cover different programs, entities and reporting periods.
- “Millions” claims: Some commentary extrapolated from Cencora’s overall patient reach. That is not a confirmed breach count and should not be presented as fact.
The HHS OCR portal is at ocrportal.hhs.gov. Secondary context appears in SecurityWeek’s report.
Which patients or company programs might be connected?
Reporting and state filings have associated notices with programs involving companies such as AbbVie, Bayer, Genentech, GSK, Novartis, Regeneron, Incyte, Acadia, Endo, Dendreon and Sumitomo Pharma. This is an illustrative list, not a verified master list of every affected person or program.
Strong indicators that you may be in a notified population include a letter or email naming Cencora, Lash Group, AmerisourceBergen Specialty Group or a drug-manufacturer patient-support program; participation in assistance, copay, free-trial, adherence or therapy-support services; or a settlement notice. Merely taking a medicine distributed by Cencora is not enough to establish that your record was involved.
Was this ransomware, and was the data published?
Public primary disclosures reviewed here do not identify a threat actor, malware family or attack method. They also do not establish that Cencora paid a ransom or that attackers deleted the data. The most accurate description is a cyberattack involving unauthorized access and data exfiltration.
Cencora and Lash Group said they had no evidence that the information had been publicly disclosed or used fraudulently. That describes the company’s investigation at the time; it is not a guarantee that misuse is impossible. Health and identity data can support later phishing, account takeover, identity theft or medical-identity theft.
Timeline
| Date | Event |
|---|---|
| February 21, 2024 | Cencora learned data had been exfiltrated. |
| February 27, 2024 | Initial SEC Form 8-K filed. |
| April 10, 2024 | Sample individual notices said some personal information was confirmed affected. |
| May 8, 2024 | Lash Group substitute notice published for some people without usable mailing addresses. |
| June 2024 | State notices identified categories including names, addresses, birth dates, diagnoses, medications and prescriptions. |
| July 31, 2024 | SEC amendment confirmed PII and PHI in most reviewed exfiltrated data. |
| July 23, 2026 | Settlement received final court approval, according to the settlement website. |
| August 2026 | Administrator expected to begin distributions after processing claims. |
What Cencora offered affected people
Cencora notices offered affected individuals 24 months of Experian IdentityWorks credit monitoring and identity-remediation services at no charge. Cencora also said it notified people where it had usable addresses, used substitute website notice in some cases, investigated with outside cybersecurity experts and law enforcement, and implemented security measures.
Use the enrollment instructions in your individual notice. Do not trust an unsolicited message merely because it displays Cencora or Experian branding. The official Experian information page is experian.com/consumer-information/identity-theft-and-credit-fraud.html.
What to do if you received a notice
- Verify the notice through Cencora’s official notice page or the telephone and address printed in the mailed notice.
- Enroll in the offered monitoring service before the deadline stated in your notice, if enrollment remains open, and save the confirmation.
- Obtain your credit reports at AnnualCreditReport.com and look for unfamiliar accounts, inquiries or addresses.
- Consider a free credit freeze with Equifax, Experian and TransUnion. A freeze can delay a legitimate credit application until you temporarily lift it.
- Review health-insurance explanations of benefits, pharmacy accounts, bills, prescriptions and provider portals for unfamiliar activity.
- Ask your insurer or provider to investigate unknown claims, diagnoses, prescriptions, tests or account changes.
- Be cautious with messages requesting Social Security, insurance or payment information. Independently dial an official number before responding.
- Report suspected identity theft at IdentityTheft.gov and notify the relevant insurer, provider, pharmacy or financial institution.
What if you did not receive a notice?
Do not assume you were affected solely because you used a drug distributed by Cencora. Contact the relevant patient-support program or manufacturer through an independently verified official number. Never provide sensitive information to an inbound caller until you have confirmed the organization and reason for contact.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Settlement status and possible compensation
The official settlement concerns Anaya et al. v. Cencora, Inc. et al., No. 2:24-cv-02961-CMR, in the U.S. District Court for the Eastern District of Pennsylvania. The settlement website reports:
- Final approval by July 23, 2026.
- A $40 million settlement fund.
- Expected distribution beginning in August 2026, subject to claims processing.
Eligibility, documentation requirements, benefit limits and payment amounts depend on the court-approved terms. The website’s FAQ and current notices control; do not assume every affected person receives money or that claims remain open. If you experienced fraud or out-of-pocket loss, preserve notices, disputed claims, expenses, lost time and mitigation records. Individual legal advice may be appropriate for questions about your circumstances.
Medical-identity-theft checks that are easy to miss
- Compare every explanation of benefits with appointments and treatment you actually received.
- Check prescription histories and specialty-pharmacy accounts for medicine you did not order.
- Ask providers to review unfamiliar diagnoses, test orders or demographic changes in your chart.
- Change passwords on patient, insurer and pharmacy portals, enable multifactor authentication where available, and avoid reusing passwords.
Frequently Asked Questions
Does using a Cencora-distributed medicine mean my information was stolen?
No. Cencora’s wholesale role alone does not establish that your personal record was in the affected data. A notice, a patient-support-program connection or confirmation from the relevant manufacturer is stronger evidence.
Outdated Drivers Are Slowing You Down
One free scan finds every outdated or missing driver and matches the right update for your exact hardware.Free scan · exact hardware matchPC Slower Than It Used to Be?
A free scan shows the junk files, broken settings and background clutter dragging Windows down - then fixes them in one click.Free scan · Windows 10 & 11Best Value
Could my diagnosis or prescription information have been exposed?
Possibly. Notices identified diagnoses, medications and prescriptions for some people, but data elements varied and no single category applied to everyone.
Can I still file a settlement claim?
Check the current deadlines and claim status at https://www.cencoraincidentsettlement.com/. The settlement website, not the existence of the lawsuit, determines whether claims or appeals remain available.
What should I do if I find a fraudulent medical claim?
Contact the insurer and provider using independently verified numbers, request an investigation and correction, preserve all records, and report identity theft through https://www.identitytheft.gov/.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.




