GenRx Pharmacy
bd_f34fb831b294b659 · schema v1 · pii pii-v1
Full breach record for GenRx Pharmacy →GenRx Pharmacy experienced a ransomware attack on September 27-28, 2020. The attacker deployed ransomware and exfiltrated a small number of files containing patient health information, including names, addresses, dates of birth, allergies, medication lists, and health plan information. Social security numbers and financial information were not involved. GenRx terminated access on September 28, 2020, and confirmed exfiltration on November 11, 2020. The company implemented MFA, upgraded firewalls, and installed intrusion detection software.
J jump to incidentP pin to compareR raw source
Incident timeline
Sep 27, 2020
Begins
Sep 28, 2020
Discovered
Dec 18, 2020
Filed
vs. sector median
1 wks faster
Linked disclosures
Why this link?Regulatory filings (2) · sorted by filing gap
- HHS OCRbd_3af2e661de9bb1d02020-12-18Candidate
- Illinois State AGbd_837de3e506adc7a52020-01-01 · +352dCandidate
Filing propagation · 3 filings · 3 states
View merged incident ↗Pattern: first filing Jan 1 (IL), last Dec 18 (CA) — a 352-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.