Healthcare organization GenRx Pharmacy, based in Scottsdale, Arizona, has warned hundreds of thousands of patients about a potential data breachfollowing a ransomware earlier this year.

As it stated in a recent security alert: “On September 28, 2020, the company found evidence of ransomware on system and immediately began an investigation, including hiring independent information security and technology experts to assist in incident response and further investigation.”
“Together with experts, the company terminated access to its systems on the same day… and confirmed that an unauthorized third party deployed the ransomware just one day prior (September 27, 2020).”
Although the incident response team quickly stopped the unauthorized access, GenRx said it later discovered that malicious actors were able to remove a “small number of files” that included healthcare information that the company used to process and ship prescription products to patients.

GenRx said hackers gained access and were able to extract health information from “certain former GenRx patients,” including name, address, phone number, date of birth, gender, allergies, medication list, health plan information and prescriptions.
A listing on the U.S. Department of Health and Human Services' HIPAA breach portal shows that more than 137,000 GenRx patients were notified about the incident.
However, the company said that less than 5% of its customer base was affected by this breach.
"While the company is not aware of any harm to individuals as a result of the situation, it is providing potentially affected individuals with information via email regarding the measures that have been taken and what can be done to protect against potential harm.".
No further information has been released about the ransomware attack against GenRx Pharmacy so far.
