HackingCustomer Data InvolvedPHIHEALTH_BASICIDENTITY_BASICLowContained
Postmeds, Inc.
bd_b727b31473a15875 · schema v1 · pii pii-v1
Full breach record for Postmeds, Inc. →Postmeds, Inc. disclosed a cybersecurity incident where a bad actor accessed pharmacy management files between August 30 and September 1, 2023. The company discovered the breach on August 31, 2023. Affected data included names and prescription information (medication type, demographics, prescribing physician). Social Security numbers were not involved. Postmeds engaged cybersecurity professionals, secured its environment, and is enhancing security protocols and employee training.
This filing is one of 5 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (4) · sorted by filing gap
- bd_88b5f8421795a019HHS OCRfiled 2023-10-30Verified
- bd_8c3ca42ce890db77Montana State AGfiled 2023-10-30Verified
- bd_c1180337de38fb7bWashington State AGfiled 2023-10-30Verified
- bd_ffc5b8f5041d0d7cOregon State AGfiled 2023-10-30Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-575883
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Oct 30, 2023
- Raw hash
- 67a5808c7206992f6b5512972b04ae8bb748b3e0239ce9733a3a96323d390ef1
Reporting entity
- Name
- Postmeds, Inc.norm: postmeds
Victim entity
- Name
- Postmeds, Inc.norm: postmeds
Incident
- Discovered
- Aug 31, 2023
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- PHIHEALTH_BASICIDENTITY_BASIC
- Attack vector
- Unauthorized Access
- Threat actor
- External
Compliance
- Time to disclose
- 9 weeks(60 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.