PharMerica, a long-term care pharmacy provider, reported that an unauthorised party accessed its systems on 12 and 13 March 2023, with the incident noticed on 14 March. Notification of affected individuals began on 12 May, and the breach was reported as affecting 5,815,591 people.
Reported data includes names, dates of birth, social security numbers, medication lists and health insurance information. A subsequent class action settled for a reported $5.2 million, with commitments to change information security practices.
Two Days In, Two Months To Tell People
The access window is among the shortest in this database and the notification gap is unremarkable. Both facts are ordinary, and together they describe how these incidents actually work.
Detection took a day, which is better than most files here. Establishing whose records were involved took two months, which is the scoping work recorded at 23-1218 and 23-1117. The corpus notes at 26-0403 that disclosure clocks and investigations run on incompatible timescales.
The Population Includes People Who Cannot Act
Long-term care pharmacy serves an elderly and often frail population, and reporting characterised a substantial share of the affected records as belonging to people who had since died. This desk cannot verify the proportion and does not assert one.
The point stands regardless of the exact figure. Every remedy this corpus records — credit monitoring, freezing a file, watching for fraudulent accounts — requires a living person to take an action. These mechanisms assume an adult who can act; this is the other end of the same gap.
The Settlement Bought Practice Changes
The reported settlement included commitments to change information security practices, not only money. That is more than most of the settlements the corpus records at 25-1031 and 25-0703, where compensation ran to single-digit dollars per person.
It is also the only mechanism in this database that reliably produces a security improvement, which is an uncomfortable thing for a regulatory regime to be outperformed at by litigation.
Built on contemporaneous reporting of PharMerica’s breach notification and on reporting of the subsequent settlement. The 12–13 March access, 14 March detection, 12 May notification start, the 5,815,591 figure and the data categories are as reported from the company’s notifications and regulator filings. The characterisation that many affected individuals were deceased appears in reporting; this desk has not established the proportion and does not assert one. The ransomware group’s claimed 4.7 terabyte volume is an operator claim and is not carried in the record. The settlement figure and its practice-change commitments are as reported. Graded high. Corrections: corrections@forensicpost.com.