Ransomware

PharMerica Pharmacy Network Money Message Ransomware β€” 5.8 Million Patient Records

πŸ“… 2023-03-12 🏒 PharMerica pharmacy benefits management systems 🦠 Money Message ransomware
Primary Source β†—

Incident Details

In March 2023, Money Message ransomware attacked PharMerica Corporation β€” one of the largest pharmacy benefit management companies in the US, providing pharmacy services to long-term care facilities including nursing homes and assisted living facilities across all 50 states. PharMerica disclosed the breach on 12 May 2023, notifying the HHS OCR that approximately 5.8 million patient records were compromised. Stolen data included names, dates of birth, Social Security numbers, medication lists, and health insurance information. Money Message listed PharMerica on its dark web leak site and published what it claimed was stolen data after PharMerica reportedly declined to pay the ransom. The data was subsequently searchable on the dark web. The breach is significant for the sensitivity of the data β€” pharmacy records from long-term care patients include medication regimens that can reveal serious medical conditions. PharMerica was acquired by BrightSpring Health Services in 2023, and the combined entity subsequently went public. Multiple class-action lawsuits were filed against PharMerica. HHS OCR opened a compliance review. The breach was one of the largest US healthcare data breaches of 2023.

Technical Details

Initial Attack Vector
Money Message ransomware group gained access to PharMerica's network via unknown initial access vector; the group exfiltrated patient data and deployed ransomware; PharMerica is a major pharmacy benefits management company operating in long-term care facilities
Vendor / Product
PharMerica pharmacy benefits management systems
Malware Family
Money Message ransomware

Timeline

  1. 2023-03-12 Breach occurred
  2. 2023-05-12 Publicly disclosed
  3. 2023-05-12 Customers notified