Postmeds, Inc.
ent_b93b013869005740cab00e8c
Disclosures
9
State AG · HHS OCR · 8 jurisdictions
Multi-filing incidents
1
incidents joining 2+ filings here
Max affected reported
2,369,026
nationwide · HHS OCR CA
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- Postmeds, Inc.
- Normalized
- postmeds— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- No match
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- None on record
Disclosure history (9)newest first
- Massachusetts State AGas victim2024-01-18
Postmeds, Inc. reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2024-01-18. 7 Massachusetts residents were affected.
- New Hampshire State AGas victim2024-01-18
Postmeds, Inc. notified the New Hampshire Attorney General of a security incident affecting one NH resident. Unauthorized access occurred between Aug 30 and Sep 1, 2023, discovered Aug 31, 2023. The breach involved pharmacy management files containing PHI and demographic data. Postmeds engaged cybersecurity professionals, secured the environment, and offered credit monitoring to the affected individual.
- Vermont State AGas victim2024-01-17
Postmeds, Inc. notified Vermont AG of a cybersecurity incident discovered August 31, 2023. A bad actor accessed files containing names, SSNs, and prescription data between Aug 30 and Sep 1, 2023. Postmeds engaged cybersecurity professionals, secured the environment, and provided one year of credit monitoring to affected individuals.
- CALIFORNIAHHS OCRas victim2023-10-30
Postmeds, Inc. (CA) reported to HHS on 2023-10-30 a Hacking/IT Incident affecting 2,369,026 individuals. The incident originated at a business associate who experienced a cybersecurity incident impacting PHI. Data involved included names, dates of birth, medications, and some Social Security numbers. Breached information was located on a Network Server. OCR provided the covered entity with technical assistance regarding the HIPAA Rules.
- Montana State AGas victim2023-10-30
Postmeds, Inc. disclosed a cybersecurity incident where a bad actor accessed pharmacy management files containing patient names, prescription info, and demographic data between Aug 30 and Sep 1, 2023. Discovered Aug 31, 2023. No SSNs involved. Postmeds engaged cybersecurity professionals and is enhancing security protocols.
- California State AGas victim2023-10-30
Postmeds, Inc. disclosed a cybersecurity incident where a bad actor accessed pharmacy management files between August 30 and September 1, 2023. The company discovered the breach on August 31, 2023. Affected data included names and prescription information (medication type, demographics, prescribing physician). Social Security numbers were not involved. Postmeds engaged cybersecurity professionals, secured its environment, and is enhancing security protocols and employee training.
- Washington State AGas victim2023-10-30
Postmeds, Inc. filed a supplemental notification with the Washington AG regarding a cybersecurity incident. A bad actor gained unauthorized access to pharmacy management files between August 30 and September 1, 2023. Postmeds discovered the breach on August 31, 2023. The incident affected 48,861 Washington residents, exposing names, prescription information, and Social Security numbers. Postmeds engaged forensic professionals, secured the environment, and provided credit monitoring services to affected individuals.
- Oregon State AGas victim2023-10-30
Postmeds, Inc. reported a data breach to the Oregon Attorney General. The breach was reported on 2023-10-30. The breach occurred during 8/30/2023 - 9/1/2023. The breach was discovered on 8/31/2023. Notice was sent on 10/30/2023.
- Illinois State AGas victim2023-01-01
POSTMEDS, INC. filed a data-breach notice with the Illinois Attorney General during 2023 (case 23-756). The register records the breach as discovered on August 30, 2023. Illinois does not publish the number of people affected — 815 ILCS 530/10 permits the Attorney General to publish only the entity name, the types of personal information and the date range.