DataBreachCaseFile.com
MonitoringCalifornia AG filing · September 21, 2026

Ridgeway Pharmacy Ltd Discloses Data Breach Impacting Customer Records

In September 2026, Ridgeway Pharmacy Ltd of California reported a data security incident that occurred in June 2026. This breach may have exposed patient names, birth dates, Social Security numbers, prescription details, and other sensitive personal and health information, prompting individuals to take protective measures.

State
California
Breach date
June 7, 2026
Reported
September 21, 2026

What may have been exposed

  • Full Name
  • Date of Birth
  • Social Security Number
  • Prescription Information
  • Health Insurance ID Number
  • Medical Record Number
  • Billing and Payment Details
  • Home Address

Ridgeway Pharmacy Ltd, an established pharmacy provider operating in California, reported a data security incident to regulatory authorities on September 21, 2026. The company indicated that its network environment was compromised by unauthorized actors, with the breach initially occurring on or about June 7, 2026. The specific nature of the compromise was not detailed in public filings.

The breach exposed a comprehensive range of sensitive personal and health data. Categories of information potentially accessed include individuals' Full Name, Date of Birth, Social Security Number, Prescription Information, Health Insurance ID Number, Medical Record Number, Billing and Payment Details, and Home Address. This combination of highly identifying and health-related data presents a significant risk to affected individuals.

Exposure of such an extensive mosaic of sensitive information can lead to various forms of identity theft and financial fraud. For example, compromised Prescription Information, Health Insurance ID Number, and Medical Record Number could facilitate medical identity theft, enabling unauthorized individuals to obtain prescriptions or submit fraudulent claims. Similarly, the exposure of Full Name, Date of Birth, Social Security Number, and Billing and Payment Details significantly increases the risk of financial identity theft, unauthorized account access, or fraudulent credit applications.

Individuals who receive official notification about this incident are encouraged to exercise increased vigilance. It is advisable to regularly review financial account statements, explanation of benefits statements from health insurers, and personal credit reports for any unusual or unauthorized activity. Placing a fraud alert or security freeze on credit files with the three major credit bureaus (Equifax, Experian, TransUnion) can serve as an important preventative measure against unauthorized account openings.

Furthermore, reviewing any specific instructions or resources provided by Ridgeway Pharmacy Ltd, such as offers for credit monitoring services, is recommended. Maintaining strong, unique passwords for all online accounts and exercising caution with unsolicited communications that request personal information are general but vital cybersecurity practices to adopt following such an event.

What to do if you were affected

Based on the categories of information reported in this filing, these steps can help limit the risk of identity theft and fraud.

  • Freeze your credit

    Place a free credit freeze with Equifax, Experian, and TransUnion. A freeze blocks new accounts from being opened in your name and can be lifted anytime.

  • Watch your financial accounts

    Review bank and card statements for unfamiliar activity and turn on transaction alerts. Report anything you don't recognize to your bank right away.

  • Check for medical identity theft

    Review the Explanation of Benefits statements from your health insurer for services or claims you never received, which can signal misuse of your medical identity.

  • Stay alert to targeted scams

    Be cautious of calls, texts, or emails that reference this breach. Legitimate organizations won't ask you to confirm sensitive details through an unsolicited message.

  • Keep your notification letter

    Save the notice you received. It documents that your information was involved and is often needed to enroll in any credit monitoring offered or to join a related legal claim.

Source: California Attorney General filing

Related data breach cases