Skip to main content

Ridgeway Pharmacy Discloses Third-Party Website Breach Exposing Patient Data

Victor, Montana – – September 21, 2026 -- Ridgeway Pharmacy, Ltd. has confirmed that a vulnerability in its vendor-supported website allowed an unauthorized third party to gain elevated access, potentially exposing patient names, dates of birth, addresses, prescription and health information, insurance details, and, for some individuals, payment card data.

Ridgeway confirms breach originated in vendor-managed site, not internal systems

The pharmacy said the compromise was limited to its externally developed website and did not touch Ridgeway's own internal infrastructure. External cybersecurity and forensic specialists were brought in after operational irregularities were first detected on the site.

Investigation determined exposure scope on August 21, 2026

Ridgeway pinpointed the extent of potentially accessed data on August 21, 2026, identifying that a subset of affected individuals also had payment card information exposed. The company has since remediated the compromised website, deployed a new platform, tightened access controls, and enhanced monitoring against further unauthorized activity.

Federal law enforcement notified as company issues written breach notices

Ridgeway reported the incident to federal law enforcement and mailed written notifications to affected individuals. The pharmacy is offering complimentary identity protection services through TransUnion and has set up a toll-free assistance line, 1-833-516-7133, staffed from 8 a.m. to 8 p.m. ET.

Ridgeway advised affected individuals to monitor account statements, health plan explanations of benefits, and credit reports for unfamiliar activity, and to promptly report any suspicious transactions to their financial institutions.

Published by
fairsonline_team
Industries
News Type