Desk live·
ForensicPost
Breaches/Healthcare/File 23-0512b

PharMerica Notified 5.8 Million People After a Two-Day Intrusion in March

The attackers were inside for about two days and the notification came two months later. The population is a long-term care pharmacy’s — which means a substantial share of the people whose social security numbers were taken were beyond any remedy the system offers.

Constructed geometry · not a chart of case data
JurisdictionUSAthe affected organisation’s jurisdiction, not the actor’s suspected origin
TargetPharMerica
ActorMoney Message
S. Rosler10 min readConfidence: high2 sources reviewed

PharMerica, a long-term care pharmacy provider, reported that an unauthorised party accessed its systems on 12 and 13 March 2023, with the incident noticed on 14 March. Notification of affected individuals began on 12 May, and the breach was reported as affecting 5,815,591 people.

Reported data includes names, dates of birth, social security numbers, medication lists and health insurance information. A subsequent class action settled for a reported $5.2 million, with commitments to change information security practices.

Two Days In, Two Months To Tell People

The access window is among the shortest in this database and the notification gap is unremarkable. Both facts are ordinary, and together they describe how these incidents actually work.

Detection took a day, which is better than most files here. Establishing whose records were involved took two months, which is the scoping work recorded at 23-1218 and 23-1117. The corpus notes at 26-0403 that disclosure clocks and investigations run on incompatible timescales.

The Population Includes People Who Cannot Act

Long-term care pharmacy serves an elderly and often frail population, and reporting characterised a substantial share of the affected records as belonging to people who had since died. This desk cannot verify the proportion and does not assert one.

The point stands regardless of the exact figure. Every remedy this corpus records — credit monitoring, freezing a file, watching for fraudulent accounts — requires a living person to take an action. These mechanisms assume an adult who can act; this is the other end of the same gap.

The Settlement Bought Practice Changes

The reported settlement included commitments to change information security practices, not only money. That is more than most of the settlements the corpus records at 25-1031 and 25-0703, where compensation ran to single-digit dollars per person.

It is also the only mechanism in this database that reliably produces a security improvement, which is an uncomfortable thing for a regulatory regime to be outperformed at by litigation.

How we reported this

Built on contemporaneous reporting of PharMerica’s breach notification and on reporting of the subsequent settlement. The 12–13 March access, 14 March detection, 12 May notification start, the 5,815,591 figure and the data categories are as reported from the company’s notifications and regulator filings. The characterisation that many affected individuals were deceased appears in reporting; this desk has not established the proportion and does not assert one. The ransomware group’s claimed 4.7 terabyte volume is an operator claim and is not carried in the record. The settlement figure and its practice-change commitments are as reported. Graded high. Corrections: corrections@forensicpost.com.

Sources
  1. PharMerica Pays Over $5.2 Million to Settle Class Action Data Breach LawsuitHIPAA Journal
  2. PharMerica Reports Breach Affecting Nearly 6 Million PeopleBankInfoSecurity
S. Rosler
Covers extortion groups and leak-site economics. Verifies our sample sets.
// the chain of custody — tuesdays

Get the next file first.

One incident a week, taken apart properly. Logs, timelines, and what the filing left out.

PGP-signed edition · no tracking pixels · one-click unsubscribe
© 2026 ForensicPost Media · the desk · newsletter · searchGlossary