Skip to content

Postmeds

Disclosed Oct 30, 20232 years ago2,369,026 affectedConfirmed

Official notice

The covered entity (CE), Postmeds, Inc., reported that its business associate (BA) experienced a cybersecurity incident that affected the protected health information (PHI) of 2,369,026 individuals. The PHI involved included names, dates of birth, medications, and some Social Security numbers. The CE notified HHS, the affected individuals, the media, and provided substitute notice on its website. OCR provided the CE with technical assistance regarding the HIPAA Rules.

What is known

People affected2,369,026 (as reported to HHS)
DisclosedOct 30, 2023
DiscoveredAug 31, 2023
HappenedAug 30, 2023
AttackHacking
Data exposedNames, Health
SectorHealthcare · US
StatusConfirmed

Sources

Source
California Attorney General breach notice: Postmedsoag.ca.gov · Official notice
Washington Attorney General breach notice: Postmedsatg.wa.gov · Official notice
Oregon DOJ breach notice: Postmedsjustice.oregon.gov · Official notice
Vermont Attorney General: 2024-01-17 Postmeds Data Breach Notice to Consumersago.vermont.gov · Official notice
HHS OCR breach report (archive, resolved): Postmeds (Healthcare Provider, CA)ocrportal.hhs.gov · Official notice

Notices filed

WhereFiledPeople
California AGresidents of CAOct 30, 2023
Washington AGresidents of WAOct 30, 202348,861
Oregon DOJresidents of OROct 30, 2023
HHS archivetotalOct 30, 20232,369,026
Vermont AGresidents of VTJan 17, 2024
History of this record
  • 2026-09-25 · data_types: [] to ["names","health"] · backfill source
  • 2026-09-25 · records_basis: empty to hhs · backfill source
  • 2026-09-25 · records: empty to 2369026 · backfill source
  • 2026-09-25 · summary: empty to The covered entity (CE), Postmeds, Inc., reported that its business associate (BA) experienced a cybersecurity incident that affected the protected health information (PHI) of 2,369,026 individuals. The PHI involved included names, dates of · backfill source
  • 2026-09-25 · source: empty to https://ago.vermont.gov/document/2024-01-17-postmeds-data-breach-notice-consumers · backfill source
  • 2026-09-25 · sector: other to health · backfill source
  • 2026-09-25 · attack: unknown to hacking · backfill source
  • 2026-09-25 · discovered: empty to 2023-08-31 · backfill source
  • 2026-09-25 · added · backfill source

First seen 2026-09-25 (California AG), confirmed by California AG. Record counts are as reported. Not legal advice.

Everything about Postmeds

New breaches by email

Wednesdays, only in weeks with newly disclosed breaches, the largest first.

Double opt-in. Unsubscribe any time.