HackingStolen CredentialsCustomer Data InvolvedEmployee Data InvolvedPHIHEALTH_BASICIDENTITY_BASICLowContained
Ron's Pharmacy Services
bd_3d81df4bca21bb99 · schema v1 · pii pii-v1
Full breach record for Ron's Pharmacy Services →Ron's Pharmacy Services experienced unauthorized access to an employee email account on October 3, 2017, via password cracking. The incident exposed protected health information (PHI) including patient names, internal account numbers, prescription medication details, and payment adjustment information for long-term care patients. No SSN, health insurance, or financial account data was accessed. The company engaged forensic investigators, reset credentials, and is providing staff training.
Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-133503
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Feb 2, 2018
- Raw hash
- 8fdcdbac5d6280cf4f1d77b910730b81dabf3277ac785332704863bbad5d8ebd
Reporting entity
- Name
- Ron's Pharmacy Servicesnorm: ron s pharmacy
Victim entity
- Name
- Ron's Pharmacy Servicesnorm: ron s pharmacy
Incident
- Discovered
- Oct 3, 2017
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- PHIHEALTH_BASICIDENTITY_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid AccountsT1114 Email Collection
- Threat actor
- External
- Regulator citations
- Providing notice to the U.S. Department of Health and Human Services
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 17 weeks(122 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.