PillPack LLC
ent_735abf87a475ea9643f89de3
Disclosures
3
State AG · HHS OCR · 3 jurisdictions
Multi-filing incidents
1
incidents joining 2+ filings here
Max affected reported
19,032
nationwide · State AG MT
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- PillPack LLC
- Normalized
- pillpack— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- No match
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- None on record
Disclosure history (3)newest first
- Montana State AGas victim2023-05-19
PillPack LLC notified Montana residents of unauthorized access to 19,032 customer accounts between April 2-6, 2023. Attackers used stolen credentials (email/password) to access accounts. Data exposed included email addresses, prescription information, and prescribing provider contact details. No SSN or payment card data was involved. PillPack reset passwords and enabled MFA.
- NEW HAMPSHIREHHS OCRas victim2023-05-19
PillPack LLC reported to HHS on 2023-05-19 a Hacking/IT Incident affecting 19,032 individuals. Breached information located on Network Server. The PHI involved included names and medications. The CE implemented additional administrative, technical, and security safeguards to better protect its PHI.
- Illinois State AGas victim2023-01-01
PILLPACK, LLC filed a data-breach notice with the Illinois Attorney General during 2023 (case 23-321). The register records the breach as discovered on April 2, 2023. Illinois does not publish the number of people affected — 815 ILCS 530/10 permits the Attorney General to publish only the entity name, the types of personal information and the date range.