INJURED WORKERS PHARMACY, LLC
ent_019e616fe1f2482b186857af1af5e7d8
Disclosures
10
State AG · 8 jurisdictions
Multi-filing incidents
1
incidents joining 2+ filings here
Max affected reported
75,771
nationwide · State AG OR
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- INJURED WORKERS PHARMACY, LLC
- Normalized
- injured workers pharmacy— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- 549300QBEG66DN0Q2B05
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- None on record
Disclosure history (10)newest first
- New Hampshire State AGas victim2022-02-07
Injured Workers Pharmacy notified the NH AG of a data event affecting 143 NH residents. Unauthorized access to 7 email accounts occurred between Jan 16 and May 12, 2021. Data included names, addresses, and SSNs. IWP engaged forensic specialists, reset passwords, and offered 12 months of credit monitoring.
- Massachusetts State AGas victim2022-02-04
Injured Workers Pharmacy reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2022-02-04. 295 Massachusetts residents were affected. The report records the breach type as electronic.
- Oregon State AGas victim2022-02-03
Injured Workers Pharmacy reported a data breach to the Oregon Attorney General. The breach was reported on 2022-02-03. The breach occurred during 1/16/2021 - 5/12/2021. The breach was discovered on 12/14/2021. 75,771 individuals were affected. Notice was sent on 2/3/2022.
- Indiana State AGas victim2022-02-03
Injured Workers Pharmacy reported a data breach to the Indiana Attorney General. The breach occurred on 2021-01-16 and was reported on 2022-02-03. 16 Indiana residents were affected. 75,771 individuals affected in total.
- Montana State AGas victim2022-02-03
Injured Workers Pharmacy notified affected individuals of a data breach where an unknown actor accessed seven employee email accounts between Jan 16 and May 12, 2021. The actor likely used stolen credentials obtained via phishing. Patient PII, including names and government IDs, was contained in the compromised accounts. IWP reset passwords and enhanced security measures.
- Maine State AGas victim2022-02-03
Injured Workers Pharmacy experienced an external system breach on January 16, 2021, which was discovered on December 14, 2021. The breach affected 75,771 individuals, compromising names and Social Security numbers. The company provided written notification to affected parties and offered 12 months of credit monitoring and identity restoration services through Experian.
- Delaware State AGas victim2022-02-03
Injured Workers Pharmacy (IWP) disclosed a data breach affecting 503 Rhode Island residents. An unknown actor accessed seven IWP employee email accounts between January 16, 2021, and May 12, 2021, following suspicious activity detected on May 11, 2021. The compromised accounts contained patient information, including names and government identifiers. IWP reset passwords, enhanced security measures, and reported the incident to regulators.
- Illinois State AGas victim2022-01-01
INJURED WORKERS PHARMACY filed a data-breach notice with the Illinois Attorney General during 2022 (case 2022-073). The register records the breach as discovered on May 11, 2021. Illinois does not publish the number of people affected — 815 ILCS 530/10 permits the Attorney General to publish only the entity name, the types of personal information and the date range.
- Delaware State AGas victim2021-12-14
Injured Workers Pharmacy (IWP) notified Delaware regulators of a data event involving unauthorized access to seven employee email accounts between January 16, 2021, and May 12, 2021. The breach exposed patient information, including names and government identifiers (SSN, DOB, driver's license). IWP reset passwords, enhanced security measures, and reported the incident. Rhode Island residents (503 known) were also impacted.
- Illinois State AGas victim2021-01-01
INJURED WORKERS PHARMACY filed a data-breach notice with the Illinois Attorney General during 2021 (case 21-531). The register records the breach as discovered on May 11, 2021. Illinois does not publish the number of people affected — 815 ILCS 530/10 permits the Attorney General to publish only the entity name, the types of personal information and the date range.