More than 5.81 million patients tied to PharMerica have been notified that their data was accessed and stolen during a March cyberattack. The long-term care pharmacy solution provider reported the breach to the Office of the Maine Attorney General on May 12.On March 14, PharMerica “learned of suspicious activity” on its network and worked to secure its systems, while launching an investigation with support from cybersecurity advisors.The forensics showed that threat actors accessed the provider’s systems for two days and exfiltrated patient data during the dwell time. The stolen data included patient names, contract information, Social Security numbers, prescriptions, and health insurance information.Notably missing from the breach notice to consumers is that the data was allegedly taken by the Money Message ransomware group. PharMerica appeared on its data leak website one month ago. The actors are a relatively new threat who previously claimed the cyberattack on Taiwanese PC parts maker MSI.Fortra GoAnywhere MFT instances.While each of the top 2022 healthcare data breaches last year affected over 1 million patients each, the majority were reported toward the end of the year and none of which reached the numbers seen in the PharMerica and GoAnywhere hacks.The largest incidents reported by single healthcare entities this year:PharMerica: 5.82M individuals Regal Medical Group: 3.3M patients Cerebral: 3.18M users NationsBenefits: 3.04M members NextGen: 1.05M patients Zoll Services: 997,097 individuals Brightline: 996,400 patients Community Health Services: 962,884 While data breaches may not impact patient care, they pose another serious business and financial risk: legal filings. As confirmed by recent data and BakerHostetler research last year, incidents impacting more than 50,000 or more patients increasingly lead to lawsuits.
Despite Money Message’s claims, PharMerica’s notice says they “have no reason to believe that anyone’s information has been misused for the purpose of committing fraud or identity theft.”PharMerica is a Fortune 1000 company that operates more than 180 facilities in all 50 states, and is the largest single-entity incident reported so far in 2023, which is on pace to become a record-breaking year for healthcare security incidents. The top eight data breaches affect over 950,000 patients each, though three of which are tied to the hack of vulnerable Ransomware, Breach, Incident Response
Data of 5.82M PharMerica patients stolen, accessed during cyberattack

PharMerica notified nearly 6 million patients that their data was stolen and accessed in a March cyberattack. (Adobe Stock Images)
An In-Depth Guide to Ransomware
Get essential knowledge and practical strategies to protect your organization from ransomware attacks.
Related Events
Get daily email updates
SC Media's daily must-read of the most current and pressing daily news
You can skip this ad in 5 seconds