GenRx Pharmacy
ent_ccb6dcdddbd1f4d8333d27f0
Disclosures
2
HHS OCR · State AG · 2 jurisdictions
Multi-filing incidents
1
incidents joining 2+ filings here
Max affected reported
137,110
as filed · HHS OCR AZ
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- GenRx Pharmacy
- Normalized
- genrx pharmacy— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- No match
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- None on record
Disclosure history (2)newest first
- AZHHS OCRas victim2020-12-18
GenRx Pharmacy (AZ), a healthcare provider, reported to HHS OCR a ransomware attack affecting ePHI of 137,110 individuals. Compromised data on a network server included names, addresses, Social Security numbers, dates of birth, health insurance information, prescribed medications, and other treatment information. The CE notified HHS, affected individuals, and the media. Remediation included revised policies/procedures and new technical safeguards; OCR obtained assurances of corrective action.
- 🐻California State AGas victim2020-12-18
GenRx Pharmacy experienced a ransomware attack on September 27-28, 2020. The attacker deployed ransomware but GenRx maintained access to backups. The attacker exfiltrated a small number of files containing patient health information (names, DOB, addresses, medication lists, health plan IDs) and prescription data. No SSN or financial data was affected. GenRx terminated access, engaged forensic experts, and implemented security upgrades including MFA and enhanced monitoring. Notifications were sent to affected individuals in California, Colorado, Illinois, and DC.