Truepill breach exposed prescription records of about 2.3 million patients

Organization
Truepill (Postmeds Inc.)
Exploit
Hacking
Industry
Pharmacy

Truepill, the mail order and digital pharmacy operated by Postmeds Inc., disclosed in late 2023 that intruders had reached files it used for pharmacy management and prescription fulfillment. The company said the unauthorized access ran from August 30 to September 1, 2023, and that it detected the activity on August 31.

The affected files held patient names, demographic details, the type of medication dispensed and, for some people, the name of the prescribing physician. Postmeds said Social Security numbers were not exposed because it does not receive them. Truepill fills prescriptions on behalf of other healthcare companies, so many of those affected were customers of its partners rather than of Truepill directly.

Notification letters were dated October 30, 2023, and the company filed notice with a state attorney general the following day. The figure reported to the U.S. Department of Health and Human Services Office for Civil Rights was 2,364,359 individuals, which outlets variously described as 2.3 million or nearly 2.4 million.

Truepill said it was enhancing security protocols and expanding staff security training, but did not explain how its systems were compromised. Multiple proposed federal class actions were filed within weeks and were later consolidated in the Northern District of California, where Postmeds eventually agreed to a $7.5 million settlement while admitting no wrongdoing.

Sources