DataBreaches.Net

Menu
  • About
  • Breach Notification Laws
  • Privacy Policy
  • Transparency Report
Menu

RoxSan Pharmacy Notifies Patients of Breach That Occurred in 2015

Posted on February 13, 2018 by Dissent

There are a number of unanswered questions about an incident disclosed by RoxSan Pharmacy today.

See what you think, starting with their press release of today:

As part of its commitment to patient privacy, RoxSan Pharmacy (“RoxSan”) notified 1,049 patients of a potential breach of unsecured personal patient protected health information.  RoxSan is notifying affected individuals in as timely a manner as possible, in its efforts to reduce or eliminate potential harm. It was necessary to delay notification because of the protected nature of the forensic investigation, which is now complete.

The incident involved the transmission of a data file to a business associate on January 20, 2015. The data file containing the unsecured information was transmitted to only one individual, a business associate in the legal field, with which RoxSan maintains a Business Associate Agreement.  However, since the data file was transmitted for non-health-related reasons, the transmission is considered a breach.  The unsecured information includes records dated between April 2015 and August 2015, and includes prescription information, patient identification numbers, drug information, physician names, and insurance information. The data file did not contain patient names or addresses or other personal identification information, and RoxSan has not received any indication that the information has been accessed or used by any unauthorized individual.

As a measure of security, concerned individuals should take the steps below to protect their personal information:

  • Call any of the three major credit bureaus to place a fraud alert on your credit report. As soon as the credit bureau confirms your fraud alert, the other two credit bureaus will automatically be notified.
    • Equifax: 1-800-525-6285; www.equifax.com
    • Experian: 1-888-397-3742; www.experian.com
    • TransUnion: 1-800-680-7289; www.transunion.com
  • Order your credit reports. By establishing a fraud alert, you can receive a free copy of your credit report.
  • Continue to monitor your credit reports. Continue to monitor your credit reports to ensure an imposter has not opened an account with your personal information.

RoxSan has established a section on its website, www.roxsan.com, with more information about protecting your personal information.

RoxSan sincerely apologizes for the inconvenience and concern this incident may cause you and will continue to do everything it can to correct this situation and fortify its operational protections for you and others.

You may contact RoxSan with questions and concerns by sending a letter to RoxSan Pharmacy, 465 N. Roxbury Drive, Beverly Hills, CA 90210 or an e-mail to [email protected].

SOURCE RoxSan Pharmacy

You may have noticed that the press release says the breach occurred on January 20, 2015, when a file was sent to a business associate. But how did that file contain data from April 2015 – August 2015, then? Something’s wrong with their dates or their explanation.

But I hadn’t even noticed that yet when I sent them an email inquiry asking when RoxSan first discovered that what they had done was actually a breach, how they learned that it was a breach, and what they meant by it was necessary to delay notification because of the “protected nature of the forensic investigation.” I wrote to them, “Neither HIPAA nor HITECH have any exemption called, “protected nature of the forensic investigation.” Did law enforcement request, in writing, delay of notification, or not?

I received an autoresponse to my email inquiry, but it was not what I expected:

Roxsan Pharmacy is temporarily closed. We are working hard at restructuring and plan to open in the very near future. If you need your medication refilled, please contact your physician’s office and have them call your information to another pharmacy. We apologize for the inconvenience and look forward to working with in the future.

Thank you for your patronage.

Roxsan Pharmacy

Did this breach have anything to do with them being closed? Or did they discover the breach while addressing closing/restructuring? RoxSan Pharmacy is a wholly-owned subsidiary of Parallax Health Sciences. There is nothing on RoxSan’s web site that indicated that they have closed or are restructuring.

It would be nice to have some answers.

Related posts:

  • Will Beacon Health Solutions’ incident prompt OCR to start enforcing notification “without undue delay?”
  • Ugh. Amazon buckets with 1.8 million pharmacy-related files and 1.2 million telemarketing recordings about diabetic supplies found unsecured
Category: Breach IncidentsCommentaries and AnalysesExposureInsiderSubcontractor

Post navigation

← The strange case of the data breach that stayed online for a month
Education Department Toughens Tone on Cyber and Threatens to Pull Funding for Non-Compliance →

Now more than ever

"Stand with Ukraine:" above raised hands. The illustration is in blue and yellow, the colors of Ukraine's flag.

Search

Browse by Categories

Recent Posts

  • Hackers Using PDFs to Impersonate Microsoft, DocuSign, and More in Callback Phishing Campaigns
  • One in Five Law Firms Hit by Cyberattacks Over Past 12 Months
  • U.S. Sanctions Russian Bulletproof Hosting Provider for Supporting Cybercriminals Behind Ransomware
  • Senator Chides FBI for Weak Advice on Mobile Security
  • Cl0p cybercrime gang’s data exfiltration tool found vulnerable to RCE attacks
  • Kelly Benefits updates its 2024 data breach report: impacts 550,000 customers
  • Qantas customers involved in mammoth data breach
  • CMS Sending Letters to 103,000 Medicare beneficiaries whose info was involved in a Medicare.gov breach.
  • Esse Health provides update about April cyberattack and notifies 263,601 people
  • Terrible tales of opsec oversights: How cybercrooks get themselves caught

No, You Can’t Buy a Post or an Interview

This site does not accept sponsored posts or link-back arrangements. Inquiries about either are ignored.

And despite what some trolls may try to claim: DataBreaches has never accepted even one dime to interview or report on anyone. Nor will DataBreaches ever pay anyone for data or to interview them.

Want to Get Our RSS Feed?

Grab it here:

https://databreaches.net/feed/

RSS Recent Posts on PogoWasRight.org

  • Kids are making deepfakes of each other, and laws aren’t keeping up
  • The Trump administration is building a national citizenship data system
  • Supreme Court Decision on Age Verification Tramples Free Speech and Undermines Privacy
  • New Jersey Issues Draft Privacy Regulations: The New
  • Hacker helped kill FBI sources, witnesses in El Chapo case, according to watchdog report
  • Germany Wants Apple, Google to Remove DeepSeek From Their App Stores
  • Supreme Court upholds Texas law requiring age verification on porn sites

Have a News Tip?

Email: Tips[at]DataBreaches.net

Signal: +1 516-776-7756

Contact Me

Email: info[at]databreaches.net

Mastodon: Infosec.Exchange/@PogoWasRight

Signal: +1 516-776-7756

DMCA Concern: dmca[at]databreaches.net
© 2009 – 2025 DataBreaches.net and DataBreaches LLC. All rights reserved.