Company Details
chiesi-usa
532
29,684
3254
chiesiusa.com
0
CHI_1473249
In-progress

Chiesi USA, Inc. Company CyberSecurity Posture
chiesiusa.comChiesi USA, Inc., headquartered in Cary, N.C., is a specialty pharmaceutical company focused on commercialization of products for the hospital, rare disease and target office-based specialties. Our employees take an entrepreneurial approach to meet the evolving needs of our customers. As a Public Benefit Corporation, Chiesi USA is committed to operating as a good corporate citizen; positively impacting communities in which we live and serve. Headquartered in Cary NC, we employ over 360 employees in the United States. Previously known as Cornerstone Therapeutics, the company was acquired by the Chiesi Group in 2014. Chiesi USA, Inc. is a wholly-owned subsidiary of Chiesi Farmaceutici S.p.A. Headquartered in Parma, Italy, Chiesi Farmaceutici is an international research-focused group with more than 80 years of experience in the pharmaceutical industry. The Group employs more than 5,300 people in 27 affiliates worldwide, selling products in more than 80 countries. Chiesi is recognized as a top 50 company in terms of revenue and R&D. Careers at Chiesi USA Inc: Email: [email protected] Business Development: Email: [email protected] All other inquiries: Email: [email protected]
Company Details
chiesi-usa
532
29,684
3254
chiesiusa.com
0
CHI_1473249
In-progress
Between 650 and 699

CUI Global Score (TPRM)XXXX

Description: **Chiesi USA Reports Data Breach Affecting 262 Massachusetts Residents** Chiesi USA, Inc., a specialty pharmaceutical company based in Cary, North Carolina, recently disclosed a data breach exposing sensitive personal and medical information of at least 262 Massachusetts residents. The incident, reported to the Massachusetts Attorney General’s office on December 22, 2025, involved unauthorized access to the company’s systems, compromising data including names, Social Security numbers, driver’s license details, financial account information, and medical records. While the exact method of the breach remains undisclosed, Chiesi USA has taken steps to mitigate the impact. The company partnered with cybersecurity experts to investigate the incident, secure its systems, and implement additional safeguards to prevent future breaches. Affected individuals are being notified by mail and offered 24 months of complimentary credit monitoring and identity restoration services through Experian. Chiesi USA has also established a dedicated call center (833-918-4088) for impacted individuals seeking further information. The breach underscores the ongoing risks to healthcare-related data and the need for robust cybersecurity measures in the pharmaceutical sector.


Chiesi USA, Inc. has 8.7% more incidents than the average of same-industry companies with at least one recorded incident.
Chiesi USA, Inc. has 28.21% more incidents than the average of all companies with at least one recorded incident.
Chiesi USA, Inc. reported 1 incidents this year: 0 cyber attacks, 0 ransomware, 0 vulnerabilities, 1 data breaches, compared to industry peers with at least 1 incident.
CUI cyber incidents detection timeline including parent company and subsidiaries

Chiesi USA, Inc., headquartered in Cary, N.C., is a specialty pharmaceutical company focused on commercialization of products for the hospital, rare disease and target office-based specialties. Our employees take an entrepreneurial approach to meet the evolving needs of our customers. As a Public Benefit Corporation, Chiesi USA is committed to operating as a good corporate citizen; positively impacting communities in which we live and serve. Headquartered in Cary NC, we employ over 360 employees in the United States. Previously known as Cornerstone Therapeutics, the company was acquired by the Chiesi Group in 2014. Chiesi USA, Inc. is a wholly-owned subsidiary of Chiesi Farmaceutici S.p.A. Headquartered in Parma, Italy, Chiesi Farmaceutici is an international research-focused group with more than 80 years of experience in the pharmaceutical industry. The Group employs more than 5,300 people in 27 affiliates worldwide, selling products in more than 80 countries. Chiesi is recognized as a top 50 company in terms of revenue and R&D. Careers at Chiesi USA Inc: Email: [email protected] Business Development: Email: [email protected] All other inquiries: Email: [email protected]


HPCC- Hyderabad pharmaceutical congress committee is an apex body representing Indian pharmacists working in various capacities, viz,pharmaceutical industry,research and development,quality control,quality assurance,academics,drug control departments,hospitals,community and clinical pharmacy,marketi

At Merck, known as MSD outside of the United States and Canada, we are unified around our purpose: We use the power of leading-edge science to save and improve lives around the world. For more than 130 years, we have brought hope to humanity through the development of important medicines and vaccine

A consumer-led global pharmaceutical company, creating healthy doses of life since 1949. When you operate in an industry like pharmaceuticals, your work goes way beyond creating ‘products for customers’. It is different from any other domain – there lies a higher sense of responsibiliti and a need

The Menarini Group is a leading international pharmaceutical and diagnostics company, present in 140 countries worldwide, with a turnover of 4,37 Billion euro and more than 17,000 employees. With 9 centers for Research & Development, Menarini’s products are present in the most important therapeutic

Intas is one of the leading multinational pharmaceutical formulation development, manufacturing, and marketing organization in the world. It has been growing at 19% CAGR and crossed the $2.5 billion mark in the past financial year. The company has set up a network of subsidiaries, under the name Acc

Aurobindo Pharma Limited (NSE: AUROPHARMA, BSE: 524804, Reuters: ARBN.NS, Bloomberg: ARBP IN) is an integrated global pharmaceutical company headquartered in Hyderabad, India. The Company develops, manufactures, and markets a wide range of generic pharmaceuticals, branded specialty drugs, and active

This channel is not intended for U.S. and Canadian visitors. Merck operates in the U.S. and Canada as EMD Serono in Healthcare, MilliporeSigma in Life Science and EMD Electronics in Electronics. An unaffiliated and unrelated company, Merck & Co., Inc., Kenilworth, NJ, US holds the rights in the trad

Glenmark Pharmaceuticals Limited is a research-led, global organization committed to enriching lives. Innovation is deeply embedded in Glenmark’s culture; it is how we differentiate ourselves in our key markets and create greater value for our stakeholders. In our journey of innovation over the pa
At Bristol Myers Squibb, we work every day to transform patients’ lives through science. That work inspires some of the most interesting, meaningful, and life-changing careers you’ll experience. Join us and pursue innovative ideas alongside some of the brightest minds in biopharma, collaborating wit
.png)
Drugmaker Chiesi USA, Inc. failed to convince a federal judge that the Medicaid agency acted unlawfully when it determined what “new...
CARY, N.C., March 29, 2021 (GLOBE NEWSWIRE) — Chiesi USA (key-ay-zee), the U.S. affiliate of Chiesi Farmaceutici S.p.A., an international...

Explore insights on cybersecurity incidents, risk posture, and Rankiteo's assessments.
The official website of Chiesi USA, Inc. is http://chiesiusa.com/.
According to Rankiteo, Chiesi USA, Inc.’s AI-generated cybersecurity score is 682, reflecting their Weak security posture.
According to Rankiteo, Chiesi USA, Inc. currently holds 0 security badges, indicating that no recognized compliance certifications are currently verified for the organization.
According to Rankiteo, Chiesi USA, Inc. is not certified under SOC 2 Type 1.
According to Rankiteo, Chiesi USA, Inc. does not hold a SOC 2 Type 2 certification.
According to Rankiteo, Chiesi USA, Inc. is not listed as GDPR compliant.
According to Rankiteo, Chiesi USA, Inc. does not currently maintain PCI DSS compliance.
According to Rankiteo, Chiesi USA, Inc. is not compliant with HIPAA regulations.
According to Rankiteo,Chiesi USA, Inc. is not certified under ISO 27001, indicating the absence of a formally recognized information security management framework.
Chiesi USA, Inc. operates primarily in the Pharmaceutical Manufacturing industry.
Chiesi USA, Inc. employs approximately 532 people worldwide.
Chiesi USA, Inc. presently has no subsidiaries across any sectors.
Chiesi USA, Inc.’s official LinkedIn profile has approximately 29,684 followers.
Chiesi USA, Inc. is classified under the NAICS code 3254, which corresponds to Pharmaceutical and Medicine Manufacturing.
No, Chiesi USA, Inc. does not have a profile on Crunchbase.
Yes, Chiesi USA, Inc. maintains an official LinkedIn profile, which is actively utilized for branding and talent engagement, which can be accessed here: https://www.linkedin.com/company/chiesi-usa.
As of December 23, 2025, Rankiteo reports that Chiesi USA, Inc. has experienced 1 cybersecurity incidents.
Chiesi USA, Inc. has an estimated 5,459 peer or competitor companies worldwide.
Incident Types: The types of cybersecurity incidents that have occurred include Breach.
Detection and Response: The company detects and responds to cybersecurity incidents through an third party assistance with cybersecurity experts, and containment measures with secured systems, and remediation measures with implemented additional technical safeguards, and communication strategy with notified impacted individuals by mail; set up a call center..
Title: Chiesi USA Data Breach
Description: Chiesi USA, Inc. reported a significant data breach exposing both personally identifiable information (PII) and protected health information (PHI) of at least 262 Massachusetts residents. The breach involved unauthorized access to its systems, compromising sensitive personal and medical information.
Date Publicly Disclosed: 2025-12-22
Type: Data Breach
Common Attack Types: The most common types of attacks the company has faced is Breach.

Data Compromised: Personally identifiable information (PII) and protected health information (PHI)
Identity Theft Risk: High
Payment Information Risk: High
Commonly Compromised Data Types: The types of data most commonly compromised in incidents are Personally Identifiable Information (Pii), Protected Health Information (Phi) and .

Entity Name: Chiesi USA, Inc.
Entity Type: Pharmaceutical Company
Industry: Healthcare/Pharmaceutical
Location: Cary, North Carolina, USA
Customers Affected: 262 Massachusetts residents

Third Party Assistance: Cybersecurity experts
Containment Measures: Secured systems
Remediation Measures: Implemented additional technical safeguards
Communication Strategy: Notified impacted individuals by mail; set up a call center
Third-Party Assistance: The company involves third-party assistance in incident response through Cybersecurity experts.

Type of Data Compromised: Personally identifiable information (pii), Protected health information (phi)
Number of Records Exposed: 262
Sensitivity of Data: High
Personally Identifiable Information: First and last namesSocial Security numbersDriver’s license detailsFinancial account informationMedical records
Prevention of Data Exfiltration: The company takes the following measures to prevent data exfiltration: Implemented additional technical safeguards.
Handling of PII Incidents: The company handles incidents involving personally identifiable information (PII) through by secured systems.

Regulatory Notifications: Massachusetts Attorney General’s office

Recommendations: Sign up for free Experian identity theft protection services, Monitor credit reports and financial accounts for unusual activity, Be alert for phishing emails or phone calls, Consider placing a fraud alert or credit freeze with major credit bureausSign up for free Experian identity theft protection services, Monitor credit reports and financial accounts for unusual activity, Be alert for phishing emails or phone calls, Consider placing a fraud alert or credit freeze with major credit bureausSign up for free Experian identity theft protection services, Monitor credit reports and financial accounts for unusual activity, Be alert for phishing emails or phone calls, Consider placing a fraud alert or credit freeze with major credit bureausSign up for free Experian identity theft protection services, Monitor credit reports and financial accounts for unusual activity, Be alert for phishing emails or phone calls, Consider placing a fraud alert or credit freeze with major credit bureaus

Source: Massachusetts Attorney General’s office
Additional Resources: Stakeholders can find additional resources on cybersecurity best practices at and Source: Massachusetts Attorney General’s office.

Investigation Status: Ongoing
Communication of Investigation Status: The company communicates the status of incident investigations to stakeholders through Notified impacted individuals by mail; set up a call center.

Customer Advisories: Notified impacted individuals by mail; offered 24 months of complimentary credit monitoring and identity restoration services through Experian
Advisories Provided: The company provides the following advisories to stakeholders and customers following an incident: was Notified impacted individuals by mail; offered 24 months of complimentary credit monitoring and identity restoration services through Experian.
Post-Incident Analysis Process: The company's process for conducting post-incident analysis is described as Cybersecurity experts.
Most Recent Incident Publicly Disclosed: The most recent incident publicly disclosed was on 2025-12-22.
Most Significant Data Compromised: The most significant data compromised in an incident was Personally identifiable information (PII) and protected health information (PHI).
Third-Party Assistance in Most Recent Incident: The third-party assistance involved in the most recent incident was Cybersecurity experts.
Containment Measures in Most Recent Incident: The containment measures taken in the most recent incident was Secured systems.
Most Sensitive Data Compromised: The most sensitive data compromised in a breach was Personally identifiable information (PII) and protected health information (PHI).
Number of Records Exposed in Most Significant Breach: The number of records exposed in the most significant breach was 262.0.
Most Significant Recommendation Implemented: The most significant recommendation implemented to improve cybersecurity was Consider placing a fraud alert or credit freeze with major credit bureaus, Monitor credit reports and financial accounts for unusual activity, Sign up for free Experian identity theft protection services and Be alert for phishing emails or phone calls.
Most Recent Source: The most recent source of information about an incident is Massachusetts Attorney General’s office.
Current Status of Most Recent Investigation: The current status of the most recent investigation is Ongoing.
Most Recent Customer Advisory: The most recent customer advisory issued was an Notified impacted individuals by mail; offered 24 months of complimentary credit monitoring and identity restoration services through Experian.
.png)
A vulnerability has been found in SeaCMS up to 13.3. The affected element is an unknown function of the file js/player/dmplayer/dmku/class/mysqli.class.php. Such manipulation of the argument page/limit leads to sql injection. The attack can be executed remotely. The exploit has been disclosed to the public and may be used.
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in HappyDevs TempTool allows Stored XSS.This issue affects TempTool: from n/a through 1.3.1.
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Tormorten WP Microdata allows Stored XSS.This issue affects WP Microdata: from n/a through 1.0.
Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in HappyDevs TempTool allows Retrieve Embedded Sensitive Data.This issue affects TempTool: from n/a through 1.3.1.
A vulnerability has been found in Tenda FH1201 1.2.0.14(408). Affected is the function sprintf of the file /goform/SetIpBind. Such manipulation of the argument page leads to stack-based buffer overflow. The attack may be performed from remote. The exploit has been disclosed to the public and may be used.

Get company history
Every week, Rankiteo analyzes billions of signals to give organizations a sharper, faster view of emerging risks. With deeper, more actionable intelligence at their fingertips, security teams can outpace threat actors, respond instantly to Zero-Day attacks, and dramatically shrink their risk exposure window.
Identify exposed access points, detect misconfigured SSL certificates, and uncover vulnerabilities across the network infrastructure.
Gain visibility into the software components used within an organization to detect vulnerabilities, manage risk, and ensure supply chain security.
Monitor and manage all IT assets and their configurations to ensure accurate, real-time visibility across the company's technology environment.
Leverage real-time insights on active threats, malware campaigns, and emerging vulnerabilities to proactively defend against evolving cyberattacks.