Johnson & Johnson Health Care Systems, commonly known as Janssen, suffered a significant data breach following a third-party data security incident involving IBM.
IBM is a service provider to Johnson & Johnson Health Care Systems, Inc. (“Janssen”) and manages the application and the third-party database that supports Janssen CarePath which helps patients access Janssen medications and avail discounts and cost-saving advice on eligible prescriptions. IBM also provides guidance on insurance coverage and serves drug refiling and administering alerts.
In a recent data security notice posted on its website, Janssen
said it identified a “technical method by which unauthorised access to the database could be obtained.” The company immediately notified IBM about this technical glitch, who began an investigation to determine any unauthorised access in the database.
“While IBM’s investigation identified, on August 2, 2023, that there was unauthorised access to personal information in the database, the investigation was unable to determine the scope of that access. As a result, IBM has begun notifying Janssen’s CarePath customers and users whose information was contained in the Janssen CarePath database out of an abundance of caution,” the notice reads.
IBM’s investigation revealed that the security incident affected individuals enrolled in services prior to July 2, 2023. The compromised information included patients’ names, contact information, dates of birth, health insurance information, and information about medications and associated conditions that were provided to the Janssen CarePath application.
Janssen has clarified that social security numbers and financial account information were not stored in the affected database and weren’t compromised in the security incident.
“After being informed of the issue by Janssen, IBM and the database provider promptly identified and implemented steps that disabled the technical method at issue. IBM also worked with the database provider to augment security controls to reduce the chance of a similar event occurring in the future,” Janssen added.
While IBM found no indication that the compromised information has been misused, the possibility of the same can’t be ruled out. IBM is offering a year of complimentary credit monitoring service to individuals whose information has been impacted in the data breach.
IBM has shared a similar statement with the media to confirm the data breach.
"After being informed of the issue by Janssen, IBM and the database provider promptly identified and implemented steps that disabled the technical method at issue. IBM also worked with the database provider to augment security controls to reduce the chance of a similar event occurring in the future," the company
said.
“Janssen CarePath users are encouraged to remain vigilant by regularly reviewing their account statements and explanations of benefits from their health insurer or care providers with respect to any unauthorised activity, and to promptly report any suspicious activity,” IBM added.