Update as of July 13, 2021: The total number impacted has been updated by NEC Networks to 2,420,141.
For the past two months, DataBreaches.net has been tracking reports involving NEC Networks, LLC d/b/a CaptureRx. CaptureRx is a specialty pharmacy benefits manager whose services include prescription claims processing, patient assistance program administration, and public health service 340B drug program administration. CaptureRx provides these services for pharmacies and healthcare providers across the United States.
In February, CaptureRx became aware of a compromise of their system(s). Although their statements have not labeled it as a “ransomware” incident, at least one of their covered entities has described it that way and most of the media coverage reports it as a ransomware incident. DataBreaches.net notes, however, that CaptureRx has not actually called it a ransomware incident, the threat actors have not been named, and there has been no disclosure as to whether there was any ransom demand, and if so, whether it was paid. The incident has not shown up on any dedicated leak site associated with almost two dozen ransomware groups, which can mean that: (1) the compromise was not by any of those groups, (2) the compromise was by one of those groups but the victim paid the ransom to keep the data from being publicly dumped, or (3) it wasn’t a ransomware incident but perhaps something like a hack with data exfiltrated — with or without an extortion demand. We just don’t know for sure at this point because CaptureRx’s disclosures haven’t been specific or detailed on those points.
This week, in its newest filing with a state regulator, we have learned that a total of 1,919,938 individuals (presumably patients) have been impacted by the incident. UPDATED AGAIN in JUNE: NEC Networks issued a second supplemental report (embedded below). Now the number impacted is listed as 2,420,141 .
Here is an incomplete list of covered entities that have already been reported to have been impacted by a ransomware incident CaptureRx experienced. Where the number of affected patients is known, it is indicated in parentheses. We are obviously missing alot of reports.
- Ascension St. Joseph Hospital (5807).
- Ascension Standish Hospital (1705)
- Bayhealth (575)
- Brownsville Community Health Center (4258)
- Catholic Health (Mount St. Mary’s and Sisters of Charity hospitals, NY)
- Faxton St. Lukes (17655)
- Gifford Health (6777)
- Lourdes Hospital (1745)
- Thrifty Drug (3958)
- UPMC Cole and UPMC Wellsboro (7376)
- Walmart (16044)
- Jordan Valley Community Health Center (12000)
- Hildalgo Medical Services (2179)
- Adirondack Medical Center dba Adirondack Health (800)
- Kaleida Health (600)
- Trinity Health System (9579)
- Altru Health System
- HopeHealth (963)
- Massena Hospital (St. Lawrence Health System) (1897)
- MetroHealth
- TidalHealth
- BayHealth
- Tiburcio Vasquez Health Center
- Washington County entities: Calais Regional Hospital (2,700); Eastport Health Care Inc. (667); Regional Medical Center at Lubec (384); and St. Croix Regional Family Health Center and East Grand Health Center (1,850)
- NYC Health & Hospitals (43000)
- North Country Healthcare
CaptureRx’s first press release was issued May 5. Now they have issued a “second wave” release for additional people being notified. That release (embedded below), submitted to Maine’s attorney general, indicates that those being notified are not being offered any credit monitoring services.
DataBreaches.net will continue monitoring this incident and will update this post as more details become available.
May 21: CaptureRx issued a complete list of entities for whom it was making notification (links added as news stories appear):
- Adirondack Medical Center dba Adirondack Health
- Adventist Health Mendocino Coast
- Adventist Health Reedley
- Adventist Health Rideout
- Adventist Health Sonora
- Adventist Health Ukiah Valley
- Amoskeag Health, formerly known as Manchester Community Health Center
- Arcare
- Asian Health Services
- Aurora Professional Pharmacy
- BARTZ-ALTADONNA COMMUNITY HEALTH CENTER
- Broad Top Area Medical Center Inc
- Broaddus Hospital
- Brookdale Hospital Medical Center
- Brookshire Grocery Company
- Brownsville Community Health Center dba New Horizon Medical Center
- Cabun Rural Health Services, Inc
- Camden-On-Gauley Medical Center, Inc.
- ChesPenn Health Services, Inc.
- Chota Community Health Services
- Coleman Pharmacy of Alma
- Communicare Health Centers
- Community Health Centers of the Central Coast Inc
- Community Medical Center
- Cottage Hospital
- Davis Medical Center
- Dayspring Health Inc.
- Discount Emporium, Inc. dba Drug Emporium
- East Arkansas Family Health Center, Inc.
- East Central Mississippi Health Care, Inc
- East Liberty Family Health Care Center
- Eastman Drugs Inc
- Echo Community Health Care, Inc.
- Ellis Hospital dba Ellis Medicine
- Family Health Centers of San Diego
- Feather River Health Center
- Giant Eagle, Inc.
- Grande Ronde Hospital
- Greater Seacoast Community Health
- Harbor Regional Health
- Hardin County Regional Health Center dba Lifespan health
- Healthsource of Ohio, Inc.
- Hidalgo Medical Services, Inc.
- Hoffman Drug-True Value
- Hudson Headwaters Health Network
- Inverness Apothecary Trinity
- Kaleida Health
- Lehigh Valley Hospital
- Lifecare Family Health & Dental Center
- Loudoun Community Health Center dba HealthWorks for Northern Virginia
- Loyola University Medical Center, Maywood, Illinois
- Magnolia Regional Medical Center
- Marc Glassman, Inc.
- Marshall Medical Center
- Mendocino Community Health Clinic
- Mercy Health – Mercy Campus
- Mercy Hospital and Medical Center
- Miller County Hospital
- Monadnock Community Hospital
- Monongahela Valley Association of Health Centers, Inc.
- Mount Desert Island Hospital
- Mountain Valleys Health Centers
- Munson Healthcare – Cadillac
- Munson Healthcare – Cherlevoix
- Munson Healthcare – Grayling
- Munson Healthcare – Kalkaska Memorial Health
- Munson Healthcare – Manistee
- Munson Healthcare – Munson Medical Center
- Munson Healthcare – Ostego Memorial
- Northeast Community Clinic, Inc., A California Non-Profit Public Benefit Corporation
- Northern Light Mayo Hospital
- Northern Valley Indian Health, Inc.
- NY Drugs INC DBA Castle Hill Community Pharmacy
- Okanogan County Public Hospital District No. 3 d/b/a Mid-Valley Hospital
- Our Lady Of Lourdes Memorial Hospital
- PeaceHealth Peace Harbor Medical Center
- Pocahontas Memorial Hospital
- Primary Health Network, Inc.
- R&D Pharmacy
- Rhea Medical Center
- Richford Health Center, Inc.
- Rite Aid Corporation (together with its affiliates, “Rite Aid”)(98,964)
- Rutland Hospital, Inc. dba Rutland Regional Medical Center
- Saint Alphonsus Regional Medical Center
- Saint Francis Healthcare
- Save Mart Pharmacy
- Schenectady Family Health Services DBA Hometown Health Centers
- Shasta Community Health Center
- Siskiyou Hospital, Inc. dba Fairchild Medical Center
- Sistersville General Hospital
- Skagit Regional Health (21,027)
- Southeastern Grocers, Inc. d/b/a Winn-Dixie, BI-LO, Fresco y Mas, and Harveys
- Southwest Virginia Community Health Systems, Inc.
- Spectrum Health Services, Inc.
- St. Agnes Hospital
- St. Charles Health Council/Stone Mountain Health Services
- St. Joseph Health System-Tawas
- Standish Community Hospital, Inc.
- Summit Pacific Medical Center
- Tampa Family Health Centers, Inc.
- Temple University Health System, Inc.
- Third Street Community Clinic
- Three Lower Counties Community Services, Inc., d/b/a Chesapeake Health Care
- Tri-Cities Community Health
- Trinitas Regional Medical Center
- Trinity Health System
- UK Healthcare
- UMass Memorial Medical Center
- Unity Care Northwest (4,241)
- University of Kansas School of Medicine-Wichita Medical Practice Association
- UPMC Cole
- UPMC Wellsboro
- Valley Medical Center
- Valley-Wide Health Systems, Inc.
- Vital Rx of Louisiana
- Vital Rx of Tennessee
- Wayne Memorial Community Health Center
- West End Drug Company
- Western Sierra Medical Clinic, Inc.
- White County Medical Center d/b/a Unity Health
- White River Health System
Hello,
You spelled Million incorrectly in the title.
I sure did. Fixed it now — thank you.