Phreesia, Inc., a healthcare patient check-in technology company, was impacted by a zero-day vulnerability in third-party software Salesloft Drift, which allowed an unknown threat actor to access Salesforce environments of hundreds of organizations on August 17, 2025. Service tickets containing limited patient information were exposed. 18 Rhode Island residents were identified as affected. Phreesia stopped use of the tool, engaged external cybersecurity experts, and offered two-year Kroll identity monitoring to affected individuals.
Affected (this filing): 18