MSCRIPTS
ent_09208f486efb6ea0b5382b9e
Disclosures
7
State AG · HHS OCR · 5 jurisdictions
Multi-filing incidents
1
incidents joining 2+ filings here
Max affected reported
88,923
nationwide · HHS OCR CA
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- MSCRIPTS
- Normalized
- mscripts— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- No match
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- None on record
- Corporate parent
- CARDINAL HEALTH, INC.— per SEC Exhibit 21 filing
Disclosure history (7)newest first
- Washington State AGas reporting2023-03-14
mscripts, LLC, a business associate of Safeway, disclosed a misconfiguration in cloud storage access settings that exposed patient data (names, DOB, prescription info) from Sept 2022 to Nov 2022. 1,394 Washington residents were notified in March 2023. No SSN or financial data was involved.
- Montana State AGas victim2023-03-14
mscripts, a prescription management vendor, disclosed that unauthenticated internet access to its cloud storage exposed patient data (names, DOB, addresses, prescription details) from Sept 2016 to Nov 2022. The incident was discovered on Nov 18, 2022. Forensic investigators were engaged. No SSN or financial data was involved.
- California State AGas victim2023-03-14
mscripts, LLC disclosed a misconfiguration of its cloud storage that left prescription management files accessible without authentication from September 30, 2016, to November 18, 2022. The exposed data included patient names, addresses, dates of birth, phone numbers, and prescription details (medication names, refill status). No SSNs or financial data were involved. mscripts engaged forensic investigators and changed access settings upon discovery.
- Oregon State AGas victim2023-03-14
mscripts, LLC reported a data breach to the Oregon Attorney General. The breach was reported on 2023-03-14. The breach occurred during 9/30/2016 - 11/18/2022. The breach was discovered on 1/13/2023. 5,725 individuals were affected. Notice was sent on 3/14/2023.
- CALIFORNIAHHS OCRas victim2023-01-17
mscripts®, LLC reported to HHS on 2023-01-17 a Unauthorized Access/Disclosure affecting 88,923 individuals. Breached information located on Network Server. The business associate reported that a cloud storage asset lacked appropriate security safeguards that could have allowed the unauthorized access to the protected health information (PHI) of 88,923 individuals. The PHI involved included names, dates of birth, addresses, medication information, and health insurance information.
- Illinois State AGas victim2023-01-01
MSCRIPTS filed a data-breach notice with the Illinois Attorney General during 2023 (case 23-086). The register records the breach as discovered on September 30, 2016. Illinois does not publish the number of people affected — 815 ILCS 530/10 permits the Attorney General to publish only the entity name, the types of personal information and the date range.
- Illinois State AGas victim2023-01-01
MSCRIPTS filed a data-breach notice with the Illinois Attorney General during 2023 (case 23-074). The register records the breach as discovered on September 30, 2016. Illinois does not publish the number of people affected — 815 ILCS 530/10 permits the Attorney General to publish only the entity name, the types of personal information and the date range.