News

Data Of 2.8 Million Sav-Rx Customers Compromised In Cyber Attack

Giulio Saggin
Giulio Saggin
Tuesday 28 May 2024
Data Of 2.8 Million Sav-Rx Customers Compromised In Cyber Attack
savrx.com

More than 2.8 million people have been alerted to the fact their personal data was compromised in a cyber attack on prescription service company Sav-Rx.

On October 8, 2023, the company announced an "interruption to our computer network", after the results of a forensic investigation showed that an unauthorized third party breached the company's system on or around October 3, 2023.

In a letter to those affected, Sav-Rx wrote: "We learned that an unauthorised third party was able to access certain non-clinical systems and obtained files that contained health information. After an extensive review ... we discovered that some of the data accessed or acquired may have contained your protected health information."

The compromised data in question included: full name, Social Security Number, email address, phone number, date of birth, street address, eligibility data, and insurance identification number.

Via an FAQ page linked to from the company's homepage, Sav_Rx explained why it took eight months to notify those affected.

"Immediately upon learning of an interruption to our computer network, we took steps to secure our systems and engaged cybersecurity experts. Our initial priority was restoring systems to minimise any interruption to patient care. After our systems were secured, we launched an investigation, aimed at determining the affected individuals, as well as the specific elements of each individual’s personal information affected by the incident. We received the results of that investigation on April 30, 2024, and promptly sent notifications to our health plan customers whose participant data was affected."

Sav_Rx says that, while they experienced an interruption to their network, the issue was fully resolved and their IT systems were restored within a day.

"We contained the incident and confirmed that any data acquired from our IT system was destroyed and has not been disseminated any further. We contained the incident and confirmed that any data acquired from our IT system was destroyed and has not been disseminated any further."

In light of the breach, the company has enhance their security protocols and controls, technology, policies, and training.

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2024 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203