DataBreachCaseFile.com
All cases
investigating

NationalRx Pharmacy Network Reports Breach Affecting 620,000 in PA

NationalRx Pharmacy Network has filed notice of a cybersecurity incident with Pennsylvania authorities, impacting 620,000 customers. The breach, which occurred in May 2026, exposed Medical Records, Social Security Numbers, and Prescription History. An investigation into the incident is currently underway.

Compiled from official Attorney General recordsLast updated
State
Pennsylvania
Affected
620,000
Breach date
May 10, 2026
Reported
June 20, 2026

What may have been exposed

  • Medical Records
  • SSN
  • Prescription History

NationalRx Pharmacy Network officially reported a data breach to the Pennsylvania Attorney General, impacting 620,000 individuals. The cybersecurity incident took place on May 10, 2026, with the company filing its report on June 20, 2026.

The reported exposed data categories include Medical Records, Social Security Numbers (SSN), and Prescription History. This combination of highly sensitive personal information was accessed by unauthorized parties during the security failure.

The exposure of Medical Records and Prescription History can lead to medical identity theft, where criminals may attempt to obtain services or make fraudulent claims in a victim's name. The compromise of a Social Security Number significantly escalates the risk, potentially enabling broader financial fraud, opening new accounts, or accessing existing financial benefits.

Individuals who have received notification from NationalRx Pharmacy Network should take proactive steps to protect themselves. It is recommended to carefully review all financial and medical statements for any unusual or unauthorized activity. Additionally, consider placing a fraud alert or security freeze on your credit reports with the three major credit bureaus.

This documentation is based on the official filing submitted by NationalRx Pharmacy Network. The Pennsylvania Attorney General's office has initiated an investigation into the cybersecurity incident.

Source: Attorney General filing