Skip to content

GenRx Pharmacy

Disclosed Dec 18, 20205 years ago137,110 affectedConfirmed

Official notice

The covered entity (CE), GenRX Pharmacy, reported that it was the victim of a ransomware attack that affected the electronic protected health information (ePHI) of 137,110 individuals. The ePHI involved included names, addresses, Social Security numbers, dates of birth, health insurance information, medication prescribed, and other treatment information. The CE notified HHS, affected individuals, and the media. In response to the breach, the CE revised its policy and procedures and implemented new technical safeguards. OCR obtained assurances that the CE implemented the corrective actions noted.

What is known

People affected137,110 (as reported to HHS)
DisclosedDec 18, 2020
HappenedSep 27, 2020
AttackHacking
Data exposedNames, Health
SectorHealthcare · US
StatusConfirmed

Sources

Source
California Attorney General breach notice: GenRx Pharmacyoag.ca.gov · Official notice
HHS OCR breach report (archive, resolved): GenRx Pharmacy (Healthcare Provider, AZ)ocrportal.hhs.gov · Official notice

Notices filed

WhereFiledPeople
California AGresidents of CADec 18, 2020
HHS archivetotalDec 18, 2020137,110
History of this record
  • 2026-09-25 · attack: unknown to hacking · backfill source
  • 2026-09-25 · data_types: [] to ["names","health"] · backfill source
  • 2026-09-25 · records_basis: empty to hhs · backfill source
  • 2026-09-25 · records: empty to 137110 · backfill source
  • 2026-09-25 · summary: empty to The covered entity (CE), GenRX Pharmacy, reported that it was the victim of a ransomware attack that affected the electronic protected health information (ePHI) of 137,110 individuals. The ePHI involved included names, addresses, Social Sec · backfill source
  • 2026-09-25 · added · backfill source

First seen 2026-09-25 (California AG), confirmed by California AG. Record counts are as reported. Not legal advice.

Everything about GenRx Pharmacy

New breaches by email

Wednesdays, only in weeks with newly disclosed breaches, the largest first.

Double opt-in. Unsubscribe any time.