Postmeds, trading as “Truepill”, has begun notifying customers of a data breach affecting their sensitive personal information.

Truepill is a B2B pharmaceutical platform that uses APIs for order fulfillment and delivery services for direct-to-consumer (D2C) brands, digital health companies, and other healthcare organizations across all 50 states in the US.
The recent data breach affects 2,364,359 people, according to the breach portal of the U.S..
See also: Mr. Cooper: Institution says client data exposed in security breach
The notification letter, now being sent by Truepill, states that the company discovered unauthorized access to network its on August 31, 2023. The investigation revealed that the attackers had gained access a day earlier.
The data that was likely exposed includes:
- Full name
- Drug type
- Demographic information
- Name of the doctor who made the prescription
The above information can be used by hackers to carry out phishing and social engineering attacks. The alert clarifies that Social Security Numbers (SSN) were not included in the exposed data set.
It's worth noting that some of the people who received the data breach notifications were somewhat confused, claiming they had never heard of the company and weren't sure how their data ended up with Truepill.
Problems for Postmeds
The widespread impact of the incident could lead to legal consequences for Postmeds, as multiple class action lawsuits are reportedly being prepared across the country. The plaintiffs will argue that the data could have been prevented if Postmeds had maintained a better security posture.
Specifically, Postmeds is accused of not encrypting sensitive healthcare . stored on its servers, which made the attackers' job much easier
See also: McLaren Health Care: Data breach affected 2.2 million people
Additionally, the delay in notifying consumers may also be part of the potential lawsuits, as the company took more than two months to notify affected individuals.
It is said that, during this period, some people noticed suspicious activity in their Venmo and later confirmed that their personal data had been leaked to the dark web.
Additionally, many people are blaming Postmeds – Truepill for the way they were notified. The notification does not provide details on how the attackers gained access to the company’s systems. Furthermore, it does not provide protection advice protection services theft identity, as is usually the case in such cases.
Finally, one of the law firms that has taken legal action against Postmeds says that addresses, dates of birth, medical care information, diagnostic information, and health insurance information were also leaked. However, this information is not mentioned in the company's notice.

Measures to prevent a data breach
One way to reduce the risks of data breaches is to strengthen cybersecurity. This includes implementing advanced security technologies, such as detection and prevention systems leak, automating security processes, and training staff to address and respond to potential breaches.
See also: Kyocera AVX (KAVX): Ransomware attack led to data breach
Another way is to policy security of businesses and organizations. This includes developing and implementing strict security policies, monitoring and evaluating compliance with these policies, and assigning responsibilities for data security to qualified professionals.
Additionally, data encryption is an effective means of protecting information. Encryption ensures that data remains secure, even if it falls into the wrong hands. Using strong encryption algorithms and adhering to encryption best practices are critical to preventing data breaches.
Finally, staff training and awareness is an important means of reducing risks. Employees must be informed about threats and security, as well as trained in recognizing and responding to attacks. Training must be ongoing.
Source: www.bleepingcomputer.com
