Skip to main content
Back
PillPack.com

PillPack.com Data Breach (2015)

PillPack.com

lowVERIS
Disclosed

January 1, 2015

4103 days ago

Records

Undisclosed

Confirmed

Root Cause

Misconfiguration

Industry

Retail

Description

During the signup process, PillPack.com prompts users for their identifying information. In the end of the signup rocess, the user is shown a list of their existing prescriptions in all other pharmacies in order to make the process of transferring them to PillPack.com easier.Testing has shown that the prescription history is looked up by full name and birthdate alone, with the other information provided not used for validation of user's identity.

PillPack.com Data Breach (2015) | ExposedMap