Kroger's Postal Prescription Service exposed 82,466 customers' details

Organization
Postal Prescription Service (Healthy Options Inc., Kroger)
Exploit
Human Error
Industry
Pharmacy

Healthy Options Inc., which trades as Postal Prescription Service and is the mail order pharmacy arm of the US grocery chain Kroger, reported an incident affecting 82,466 people to the Department of Health and Human Services Office for Civil Rights on 15 March 2023.

The company said the cause was an internal error rather than an intrusion. Customers who created an online Postal Prescription Service account between July 2014 and 13 January 2023 had their first name, last name and email address passed to Kroger's grocery business, where the details were used to create grocery accounts without the customers' agreement. Kroger said no financial or clinical information was involved and that it had received no indication the information was misused.

Postal Prescription Service discovered the problem on 10 January 2023 and corrected the website behaviour on 13 January. Notification letters were sent to affected individuals, and Kroger said it was reviewing its procedures to reduce the likelihood of a repeat. The company set up a dedicated telephone line and directed queries to Kroger's HIPAA privacy office in Cincinnati.

Although the matter was logged with federal regulators under the heading of unauthorised access or disclosure of protected health information, Kroger was explicit that it was not caused by or related to a security incident.

Sources