Kroger's Postal Prescription Service exposed 82,466 customers' details
- Organization
- Postal Prescription Service (Healthy Options Inc., Kroger)
- Exploit
- Human Error
- Industry
- Pharmacy
Healthy Options Inc., which trades as Postal Prescription Service and is the mail order pharmacy arm of the US grocery chain Kroger, reported an incident affecting 82,466 people to the Department of Health and Human Services Office for Civil Rights on 15 March 2023.
The company said the cause was an internal error rather than an intrusion. Customers who created an online Postal Prescription Service account between July 2014 and 13 January 2023 had their first name, last name and email address passed to Kroger's grocery business, where the details were used to create grocery accounts without the customers' agreement. Kroger said no financial or clinical information was involved and that it had received no indication the information was misused.
Postal Prescription Service discovered the problem on 10 January 2023 and corrected the website behaviour on 13 January. Notification letters were sent to affected individuals, and Kroger said it was reviewing its procedures to reduce the likelihood of a repeat. The company set up a dedicated telephone line and directed queries to Kroger's HIPAA privacy office in Cincinnati.
Although the matter was logged with federal regulators under the heading of unauthorised access or disclosure of protected health information, Kroger was explicit that it was not caused by or related to a security incident.
Sources
- The Kroger Co., Postal Prescription Service Reports Incident Involving Prescription Mail Order Accounts
- TechTarget HealthTech Security, 82K Kroger Customers Impacted By Healthcare Data Breach
- JD Supra (Console and Associates), Kroger Postal Prescription Services Files Notice of Data Breach Impacting 82,466 Consumers