Sav-Rx breach exposed data of 2.8 million prescription plan members
- Organization
- Sav-Rx (A&A Services)
- Exploit
- Hacking
- Industry
- Pharmacy Benefits
A&A Services, the pharmacy benefit manager that trades as Sav-Rx, told regulators in late May 2024 that 2,812,336 people had personal information taken in a cyberattack the previous autumn. Those affected were mainly members of health plans the company serves, along with current and former employees.
According to the company's notification, an intruder reached its network on 3 October 2023, and Sav-Rx identified an interruption to its computer systems on 8 October. The exposed data varied by person but could include names, home addresses, dates of birth, email addresses, telephone numbers, Social Security numbers, insurance identification numbers and prescription eligibility data. Sav-Rx said clinical and financial information was not involved.
The company said it contained the incident and restored its systems by the next business day, that prescriptions shipped on time and without delay, and that pharmacy claims processing continued uninterrupted. It engaged outside cybersecurity specialists, who the company said confirmed the stolen data had been destroyed and not disseminated further.
Sav-Rx said it had first prioritised minimising interruption to patient care before investigating the impact of the incident, and then did not rush the review, which finished on 30 April 2024. It gave those two reasons for notification taking roughly seven months. It offered affected individuals two years of credit monitoring and identity theft restoration, and said it had since added round-the-clock security monitoring, multifactor authentication on critical accounts, network segmentation, geo-blocking, disk encryption and upgraded firewalls.