GenRx Pharmacy
bd_3af2e661de9bb1d0 · schema v1 · pii pii-v1
Full breach record for GenRx Pharmacy →GenRx Pharmacy (AZ), a healthcare provider, reported to HHS OCR a ransomware attack affecting ePHI of 137,110 individuals. Compromised data on a network server included names, addresses, Social Security numbers, dates of birth, health insurance information, prescribed medications, and other treatment information. The CE notified HHS, affected individuals, and the media. Remediation included revised policies/procedures and new technical safeguards; OCR obtained assurances of corrective action.
J jump to incidentP pin to compareR raw source
Incident timeline — partial
? — ?
Breach window unknown
Dec 18, 2020
Filed
—
Corroborated · see linked filings
Compliance clocks stay unassessable until a regulatory filing lands. Dashed segments fill in automatically when corroboration arrives.
Linked disclosures
Why this link?Regulatory filings (2) · sorted by filing gap
- California State AGbd_f34fb831b294b6592020-12-18Verified
- Illinois State AGbd_837de3e506adc7a52020-01-01 · +352dCandidate
Filing propagation · 3 filings · 3 states
View merged incident ↗Pattern: first filing Jan 1 (IL), last Dec 18 (AZ) — a 352-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.