HackingStolen CredentialsCustomer Data InvolvedDelayed DiscoveryIDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASICFINANCIAL_ACCOUNTMediumContained
MailMyPrescriptions.com Pharmacy Corporation
bd_38e289bf26b500e1 · schema v1 · pii pii-v1
Full breach record for MailMyPrescriptions.com Pharmacy Corporation →MailMyPrescriptions.com Pharmacy Corporation disclosed a data breach involving unauthorized access to an employee email account between February 3, 2020, and November 24, 2020. The incident was discovered on January 15, 2021. Affected data included names, dates of birth, provider names, prescription/treatment information, and health insurance details. The company retained forensic investigators, reset passwords, and offered credit monitoring services.
California clockDiscovered Jan 15, 2021 → Notified Feb 17, 202133d ✓ CA 60-day OK12 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 5 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (4) · sorted by filing gap
- bd_cdc185ff443b6a8fMontana State AGfiled 2021-04-08Verified
- bd_f739db5fa25c78e5Oregon State AGfiled 2021-04-08Verified
- bd_f8c3020ea10ad6f3Maine State AGfiled 2021-04-08Verified
- bd_235fa3124b736c77HHS OCRfiled 2021-04-16(8d gap)Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-539840
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Apr 8, 2021
- Raw hash
- 798808024613746862641a5f1098ce9b1f8d92bf8ef2f3cbdc5439a97a10a13d
Reporting entity
- Name
- MailMyPrescriptions.com Pharmacy Corporationnorm: mailmyprescriptionscom pharmacy
- Domain
- mailmyprescriptions.com
Victim entity
- Name
- MailMyPrescriptions.com Pharmacy Corporationnorm: mailmyprescriptionscom pharmacy
- Domain
- mailmyprescriptions.com
Incident
- Discovered
- Jan 15, 2021
- Materiality determined
- —
- Notification sent
- Feb 17, 2021
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASICFINANCIAL_ACCOUNT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid Accounts
- Threat actor
- External
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 12 weeks(83 days from discovery to filing)
- Compliance flags
- CA 60-day OK · 33d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Jan 15, 2021→ Notified: Feb 17, 202133d 60 days (analyst band, pre-2026 discoveries) CA 60-day OK
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.