GenRx Pharmacy
ent_ccb6dcdddbd1f4d8333d27f0
Disclosures
3
HHS OCR · State AG · 3 jurisdictions
Multi-filing incidents
1
incidents joining 2+ filings here
Max affected reported
137,110
nationwide · HHS OCR AZ
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- GenRx Pharmacy
- Normalized
- genrx pharmacy— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- No match
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- None on record
Disclosure history (3)newest first
- ARIZONAHHS OCRas victim2020-12-18
GenRx Pharmacy (AZ), a healthcare provider, reported to HHS OCR a ransomware attack affecting ePHI of 137,110 individuals. Compromised data on a network server included names, addresses, Social Security numbers, dates of birth, health insurance information, prescribed medications, and other treatment information. The CE notified HHS, affected individuals, and the media. Remediation included revised policies/procedures and new technical safeguards; OCR obtained assurances of corrective action.
- California State AGas victim2020-12-18
GenRx Pharmacy experienced a ransomware attack on September 27-28, 2020. The attacker deployed ransomware and exfiltrated a small number of files containing patient health information, including names, addresses, dates of birth, allergies, medication lists, and health plan information. Social security numbers and financial information were not involved. GenRx terminated access on September 28, 2020, and confirmed exfiltration on November 11, 2020. The company implemented MFA, upgraded firewalls, and installed intrusion detection software.
- Illinois State AGas victim2020-01-01
GENRX PHARMACY filed a data-breach notice with the Illinois Attorney General during 2020 (case 20-532). The register records the breach as discovered on September 28, 2020. Illinois does not publish the number of people affected — 815 ILCS 530/10 permits the Attorney General to publish only the entity name, the types of personal information and the date range.