Postmeds, Inc.
ent_b93b013869005740cab00e8c
Disclosures
7
State AG · HHS OCR · 6 jurisdictions
Incidents
2
filings grouped by incident
Max affected reported
2,369,026
as filed · HHS OCR CA
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- Postmeds, Inc.
- Normalized
- postmeds— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- No match
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- None on record
Disclosure history (7)newest first
- ⛰️New Hampshire State AGas victim2024-01-18
Postmeds, Inc. notified the New Hampshire Attorney General of a security incident affecting one NH resident. Unauthorized access occurred between Aug 30 and Sep 1, 2023, discovered Aug 31, 2023. The breach involved pharmacy management files containing PHI and demographic data. Postmeds engaged cybersecurity professionals, secured the environment, and offered credit monitoring to the affected individual.
- 🍁Vermont State AGas victim2024-01-17
Postmeds, Inc. notified Vermont AG of a cybersecurity incident discovered August 31, 2023. A bad actor accessed files containing names, SSNs, and prescription data between Aug 30 and Sep 1, 2023. Postmeds engaged cybersecurity professionals, secured the environment, and provided one year of credit monitoring to affected individuals.
- CALIFORNIAHHS OCRas victim2023-10-30
Postmeds, Inc. (CA) reported to HHS on 2023-10-30 a Hacking/IT Incident affecting 2,369,026 individuals. The incident originated at a business associate who experienced a cybersecurity incident impacting PHI. Data involved included names, dates of birth, medications, and some Social Security numbers. Breached information was located on a Network Server. OCR provided the covered entity with technical assistance regarding the HIPAA Rules.
- 🦬Montana State AGas victim2023-10-30
Postmeds, Inc reported a data breach to the Montana Attorney General. The breach was reported on 2023-10-30. The breach occurred on 8/31/2023. 6,703 Montana residents were affected.
- 🐻California State AGas victim2023-10-30
Postmeds, Inc. disclosed a cybersecurity incident where a bad actor accessed pharmacy management files between August 30 and September 1, 2023. The company discovered the breach on August 31, 2023. Affected data included names and prescription information (medication type, demographics, prescribing physician). Social Security numbers were not involved. Postmeds engaged cybersecurity professionals, secured its environment, and is enhancing security protocols and employee training.
- 🌲Washington State AGas victim2023-10-30
Postmeds, Inc., a health sector entity reported a unauthorized access incident to the Washington Attorney General. The organization became aware of the incident on 2023-08-31 and filed notice on 2023-10-30. 48,861 Washington residents were affected. 60 days elapsed between awareness and notification. 1 days to identify the breach. 1 days to contain the breach.
- 🦫Oregon State AGas victim2023-10-30
Postmeds, Inc. reported a data breach to the Oregon Attorney General. The breach was reported on 2023-10-30. The breach occurred during 8/30/2023 - 9/1/2023. The breach was discovered on 8/31/2023. Notice was sent on 10/30/2023.