DataBreaches.Net

Menu
  • About
  • Breach Notification Laws
  • Privacy Policy
  • Transparency Report
Menu

RoxSan Pharmacy Notifies Patients of Breach That Occurred in 2015

Posted on February 13, 2018 by Dissent

There are a number of unanswered questions about an incident disclosed by RoxSan Pharmacy today.

See what you think, starting with their press release of today:

As part of its commitment to patient privacy, RoxSan Pharmacy (“RoxSan”) notified 1,049 patients of a potential breach of unsecured personal patient protected health information.  RoxSan is notifying affected individuals in as timely a manner as possible, in its efforts to reduce or eliminate potential harm. It was necessary to delay notification because of the protected nature of the forensic investigation, which is now complete.

The incident involved the transmission of a data file to a business associate on January 20, 2015. The data file containing the unsecured information was transmitted to only one individual, a business associate in the legal field, with which RoxSan maintains a Business Associate Agreement.  However, since the data file was transmitted for non-health-related reasons, the transmission is considered a breach.  The unsecured information includes records dated between April 2015 and August 2015, and includes prescription information, patient identification numbers, drug information, physician names, and insurance information. The data file did not contain patient names or addresses or other personal identification information, and RoxSan has not received any indication that the information has been accessed or used by any unauthorized individual.

As a measure of security, concerned individuals should take the steps below to protect their personal information:

  • Call any of the three major credit bureaus to place a fraud alert on your credit report. As soon as the credit bureau confirms your fraud alert, the other two credit bureaus will automatically be notified.
    • Equifax: 1-800-525-6285; www.equifax.com
    • Experian: 1-888-397-3742; www.experian.com
    • TransUnion: 1-800-680-7289; www.transunion.com
  • Order your credit reports. By establishing a fraud alert, you can receive a free copy of your credit report.
  • Continue to monitor your credit reports. Continue to monitor your credit reports to ensure an imposter has not opened an account with your personal information.

RoxSan has established a section on its website, www.roxsan.com, with more information about protecting your personal information.

RoxSan sincerely apologizes for the inconvenience and concern this incident may cause you and will continue to do everything it can to correct this situation and fortify its operational protections for you and others.

You may contact RoxSan with questions and concerns by sending a letter to RoxSan Pharmacy, 465 N. Roxbury Drive, Beverly Hills, CA 90210 or an e-mail to [email protected].

SOURCE RoxSan Pharmacy

You may have noticed that the press release says the breach occurred on January 20, 2015, when a file was sent to a business associate. But how did that file contain data from April 2015 – August 2015, then? Something’s wrong with their dates or their explanation.

But I hadn’t even noticed that yet when I sent them an email inquiry asking when RoxSan first discovered that what they had done was actually a breach, how they learned that it was a breach, and what they meant by it was necessary to delay notification because of the “protected nature of the forensic investigation.” I wrote to them, “Neither HIPAA nor HITECH have any exemption called, “protected nature of the forensic investigation.” Did law enforcement request, in writing, delay of notification, or not?

I received an autoresponse to my email inquiry, but it was not what I expected:

Roxsan Pharmacy is temporarily closed. We are working hard at restructuring and plan to open in the very near future. If you need your medication refilled, please contact your physician’s office and have them call your information to another pharmacy. We apologize for the inconvenience and look forward to working with in the future.

Thank you for your patronage.

Roxsan Pharmacy

Did this breach have anything to do with them being closed? Or did they discover the breach while addressing closing/restructuring? RoxSan Pharmacy is a wholly-owned subsidiary of Parallax Health Sciences. There is nothing on RoxSan’s web site that indicated that they have closed or are restructuring.

It would be nice to have some answers.


Related:

  • Some lower-tier ransomware gangs have formed a new RaaS alliance -- or have they? (1)
  • Uncovering Qilin attack methods exposed through multiple cases
  • Predatory Sparrow Strikes: Coordinated Cyberattacks Seek to Cripple Iran's Critical Infrastructure
  • Ex-CISA head thinks AI might fix code so fast we won't need security teams
  • ModMed revealed they were victims of a cyberattack in July. Then some data showed up for sale.
  • Gatineau gymnastics centre warns members of possible data breach
Category: Breach IncidentsCommentaries and AnalysesExposureInsiderSubcontractor

Post navigation

← The strange case of the data breach that stayed online for a month
Education Department Toughens Tone on Cyber and Threatens to Pull Funding for Non-Compliance →

Now more than ever

"Stand with Ukraine:" above raised hands. The illustration is in blue and yellow, the colors of Ukraine's flag.

Search

Browse by Categories

Recent Posts

  • Suspected Russian hacker reportedly detained in Thailand, faces possible US extradition
  • Did you hear the one about the ransom victim who made a ransom installment payment after they were told that it wouldn’t be accepted?
  • District of Massachusetts Allows Higher-Ed Student Data Breach Claims to Survive
  • End of the game for cybercrime infrastructure: 1025 servers taken down
  • Doctor Alliance Data Breach: 353GB of Patient Files Allegedly Compromised, Ransom Demanded
  • St. Thomas Brushed Off Red Flags Before Dark-Web Data Dump Rocks Houston
  • A Wiltshire police breach posed possible safety concerns for violent crime victims as well as prison officers
  • Amendment 13 is gamechanger on data security enforcement in Israel
  • Almost two years later, Alpha Omega Winery notifies those affected by a data breach.
  • Court of Appeal reaffirms MFSA liability in data leak case, orders regulator to shoulder costs

No, You Can’t Buy a Post or an Interview

This site does not accept sponsored posts or link-back arrangements. Inquiries about either are ignored.

And despite what some trolls may try to claim: DataBreaches has never accepted even one dime to interview or report on anyone. Nor will DataBreaches ever pay anyone for data or to interview them.

Want to Get Our RSS Feed?

Grab it here:

https://databreaches.net/feed/

RSS Recent Posts on PogoWasRight.org

  • Lawmakers Warn Governors About Sharing Drivers’ Data with Federal Government
  • As shoplifting surges, British retailers roll out ‘invasive’ facial recognition tools
  • Data broker Kochava agrees to change business practices to settle lawsuit
  • Amendment 13 is gamechanger on data security enforcement in Israel
  • Changes in the Rules for Disclosure for Substance Use Disorder Treatment Records: 42 CFR Part 2: What Changed, Why It Matters, and How It Aligns with HIPAAs

Have a News Tip?

Email: Tips[at]DataBreaches.net

Signal: +1 516-776-7756

Contact Me

Email: info[at]databreaches.net
Security Issue: security[at]databreaches.net
Mastodon: Infosec.Exchange/@PogoWasRight
Signal: +1 516-776-7756
DMCA Concern: dmca[at]databreaches.net
© 2009 – 2025 DataBreaches.net and DataBreaches LLC. All rights reserved.