PharMerica breach exposed data of 5.8 million patients
- Organization
- PharMerica
- Exploit
- Ransomware
- Industry
- Healthcare
PharMerica, a United States institutional pharmacy services provider, began notifying people on May 12, 2023 that a March intrusion had exposed their personal and health information. The company said unauthorized access occurred on March 12, that it detected the activity on March 14, and that its investigation confirmed on March 21 that data had been taken.
Breach notifications put the number of affected individuals at 5,815,591. The exposed information included full names, addresses, dates of birth, Social Security numbers, medication details and health insurance information.
The Money Message ransomware group claimed the attack and began publishing stolen files in late March, with the full release following in April once the extortion deadline passed. The gang said it had taken 4.7 terabytes of data. According to BleepingComputer, the leaked material was subsequently reposted on clear web hacking forums, putting it beyond the reach of any takedown.
PharMerica offered affected individuals a year of identity protection and fraud monitoring. The interval between detection in mid-March and notification in mid-May, close to two months, drew criticism, and the company later faced consolidated class action litigation that it agreed to settle for about $5.28 million.