Cencora Data Breach: The $40 Million Settlement and What Came After
Patient records reached Cencora through eleven drug makers' support programmes — most people affected had never heard of the company. The $40 million settlement closed to claims on January 19, 2026. Here is what happened and what is still possible.
Editorially Reviewed — Content reviewed for accuracy using published legal research, government data, and verified court records. See our methodology
Reviewed by Leonard Goldberg, Editor · Last updated
What Happened
Cencora — the pharmaceutical distributor formerly called AmerisourceBergen — detected a cyberattack on February 21, 2024 and completed its internal review on April 10, 2024. Notifications went out in waves from May through July 2024, affecting Cencora itself, AmerisourceBergen Specialty Group, TheraCom LLC and The Lash Group.
The part that surprised most people: the patient data did not come from Cencora directly. It arrived through drug manufacturers' patient support programmes — co-pay assistance, free trial offers, distribution services. Press reporting names Novartis, Bayer, AbbVie, Regeneron, Genentech, Incyte, Sumitomo Pharma America, Acadia, GSK, Endo and Dendreon among the affected partners, with Pfizer also linked to support programmes. That partner list comes from press coverage, not from the court record or the settlement site.
Case Details
Anaya, et al. v. Cencora Inc., No. 2:24-cv-02961-CMR, U.S. District Court for the Eastern District of Pennsylvania, before Judge Cynthia M. Rufe. Settlement administered by Kroll Settlement Administration LLC through CencoraIncidentSettlement.com. Final approval hearing was held February 5, 2026 in Philadelphia.
Where This Stands Now
The settlement provided up to $5,000 for documented losses, subject to a $5 million cap on that category, with the remainder distributed pro rata as cash payments. California residents were eligible for a doubled payment under that state's privacy statute.
The free credit monitoring offer — two years through Experian — carried enrolment deadlines tied to each individual notification letter, typically about 90 days after it was sent. For the first notification wave that deadline was August 30, 2024. Because letters went out only through mid-2024, those windows have almost certainly closed for everyone by now; check your own letter rather than a date you read online.
How Many People Were Actually Affected
This is a case where the official number and the real number diverge sharply, and it is worth being precise about which is which.
The federal HHS breach portal shows three separate filings totalling 270,512 people: AmerisourceBergen Specialty Group with 252,214 and a second filing of 3,102, plus The Lash Group with 15,196.
State attorney general filings tell a much larger story. Analysis of those filings by TechCrunch put the notified total at at least 1.43 million people, with Texas alone accounting for about 1.05 million. Cencora itself acknowledged in its breach notice that it could not reach every affected person because it lacked current addresses — so the true figure is probably higher still.
Exposed data included name, address, date of birth, Social Security number, medical diagnoses, prescriptions, and insurance and financial information.
What the Settlement Paid
We are not going to quote a per-person figure. Pro rata settlements cannot be calculated in advance, and now that the claim period has closed, any number you see quoted for this case is either a specific claimant's outcome or a guess.
Timeline
- 1
February 21, 2024 — attack detected
Cencora identifies unauthorized activity in its systems.
- 2
April 10, 2024 — review completed
The internal investigation concludes, establishing which data was involved and whose.
- 3
May to July 2024 — notifications in waves
Letters go out over several months. Because affected patients were customers of drug makers rather than of Cencora, many recipients had never heard of the company.
- 4
December 18, 2025 — opt-out deadline
Last day to exclude yourself from the class or file an objection.
- 5
January 19, 2026 — claim deadline
The final day to submit a claim, by postmark. This window cannot be reopened.
- 6
February 5, 2026 — final approval hearing
Held before Judge Rufe in Philadelphia, clearing the way for distribution to valid claimants.
What to Watch For Now
A closed settlement with Social Security numbers in the exposed data is exactly the combination that attracts follow-on fraud.
Any site still offering a Cencora claim form
The deadline was January 19, 2026. A page accepting Cencora claims today is collecting your details for something else entirely.
Calls referencing your medication or diagnosis
Because prescriptions and diagnoses were exposed, a caller may know genuinely private medical details. That knowledge proves nothing about who they are — it is precisely what was taken.
Confusing this with a different pharmacy breach
Several large healthcare breaches ran on similar timelines. Check the case name — this one is Anaya v. Cencora Inc. in the Eastern District of Pennsylvania.
Frequently Asked Questions
Can I still file a Cencora claim?
No. The claim deadline was January 19, 2026 and the final approval hearing was held on February 5, 2026. Claim periods in approved class settlements are not reopened.
Why did I get a letter from a company I have never used?
Because your data reached Cencora through your drug manufacturer's patient support programme — co-pay assistance, a free trial, or distribution services. Cencora handled that programme on the manufacturer's behalf, which is why your records were in its systems.
Was my Social Security number exposed?
Social Security numbers were among the data types involved, along with diagnoses, prescriptions, insurance and financial information. Your individual notification letter states what applied to you specifically.
How many people were affected — 270,000 or 1.4 million?
Both figures are real and measure different things. The federal HHS portal lists three filings totalling 270,512. State attorney general filings, analysed by TechCrunch, put notifications at at least 1.43 million, with Texas alone around 1.05 million. Cencora said it could not reach everyone, so the real total is likely higher.
Is the free credit monitoring still available?
Almost certainly not. The two-year Experian offer had enrolment deadlines tied to each letter, roughly 90 days after it was sent, and letters stopped going out in mid-2024. Your own letter carries the exact date.
I never received a letter but think I was affected.
Cencora acknowledged it could not reach everyone because of outdated addresses. With the claim period closed, there is no route back into this settlement. What is still worth doing is a free credit freeze with the three bureaus, since Social Security numbers were involved.
Can I sue on my own instead?
Only if you formally opted out by December 18, 2025. Class members who did not opt out are bound by the settlement's release, which is the standard trade-off in a class action.
Separate from this case: were you injured in the last 2 years?
Class-action payouts are fixed amounts through an administrator. A personal injury claim is a different case — and often worth far more. Free estimate, no obligation.