An employee at Freedom Fertility Pharmacy, operated by Lynnfield Drug, Inc., mistakenly emailed customer names, email addresses, and diagnosis or condition information to an unauthorized recipient in September 2026. The company confirmed the error, disciplined the employee, and filed notice with Massachusetts regulators. Affected individuals should watch for suspicious messages referencing their health and consider speaking with a data breach attorney.
| Company | Lynnfield Drug, Inc. |
|---|---|
| Industry | Healthcare |
| Data Types Exposed | Names, Email Addresses, Diagnosis or Condition Information |
| People Affected | 15 Massachusetts residents (total nationwide count not publicly disclosed) |
| Attack Method | Employee Error |
| Regulators Notified | Not Publicly Disclosed |
Were you affected by this breach?
You may be owed compensation.
Data breach victims can recover money for identity-theft losses, out-of-pocket costs, wasted time, and the ongoing risk of fraud — usually with no upfront cost, and no fee unless you win.
Check if you qualify — free reviewWhat Happened in the Lynnfield Drug, Inc. Data Breach?
Freedom Fertility Pharmacy, which operates under the company Lynnfield Drug, Inc., recently told customers about a privacy incident involving an employee mistake. According to the notification, a staff member sent an email containing personal information to someone who had no right to see it. This was not the work of outside hackers. Instead, the company describes it as a simple human error during routine email handling.
The mistake happened in September 2026. The company says it discovered the misdirected email just a few days later that same month. This short gap between the error and its discovery suggests internal review processes caught the issue relatively quickly, even though the message had already reached the wrong recipient by then.
After discovering the problem, the pharmacy’s privacy office looked into how it happened. As a result, the company says it disciplined the employee involved to prevent a repeat of the same error. However, the notification letter does not say whether the unauthorized recipient confirmed deleting the email or whether the information was ever viewed, shared, or misused by that person.
Because this incident was reported through a formal state filing rather than claimed by an outside attacker, the facts described here come directly from the company’s own notification. This means the details below reflect what Lynnfield Drug, Inc. has confirmed, not an unverified third-party claim.
Who was affected?
The people affected are customers of Freedom Fertility Pharmacy, a specialty pharmacy that fills fertility medications. Because fertility treatment often involves ongoing prescriptions and regular contact with a pharmacy, affected individuals may have an established customer relationship with the company spanning months or longer.
The notification letter filed with Massachusetts regulators reports 15 Massachusetts residents affected. This number, however, only reflects individuals in that one state. The company has not disclosed a nationwide total, so the true number of people affected across the country has not been publicly disclosed.
Given the nature of fertility pharmacy services, affected customers may include individuals undergoing sensitive reproductive health treatments. This population can include people managing a wide range of family planning circumstances, which makes the privacy of their records especially important to protect.
What Information Was Potentially Exposed?
The notification letter describes a narrow but sensitive set of information included in the misdirected email. Unlike many large-scale breaches, this incident did not involve a hacked database or stolen financial records. Instead, it involved a single email containing specific personal details.
- Customer names
- Email addresses
- Diagnosis or condition information
The letter states that Social Security numbers and financial account details were not part of the exposed email. This limits certain types of financial fraud risk. However, the diagnosis or condition data stands out because of how personal and permanent this kind of exposure can be.
For example, unlike a password, a medical diagnosis cannot be changed after disclosure. Because Freedom Fertility Pharmacy specializes in fertility medications, the diagnosis or condition tied to a customer’s record could reveal details about reproductive health or family planning. This creates a risk of emotional distress, unwanted contact, or targeted phishing attempts that reference a person’s health history.
In addition, exposed email addresses paired with health details can be used by scammers to craft convincing phishing messages. These messages often pretend to be from a pharmacy, doctor’s office, or insurance provider. Because the sender appears to know real medical details, recipients may be more likely to click a malicious link or share further personal information.
What is the company doing?
Lynnfield Drug, Inc. says its privacy office investigated the circumstances of the misdirected email right after discovering it. The company also says it took steps meant to reduce any harm that could result from the disclosure. As part of its response, the company disciplined the employee responsible for the error.
The company filed its notification letter with Massachusetts regulators in October 2026, consistent with state breach notification requirements. This filing was submitted to the Massachusetts Office of Consumer Affairs and Business Regulation. The letter does not mention any offer of free credit monitoring or identity protection services, which is consistent with the fact that financial account numbers and Social Security numbers were not involved.
Instead, the company directs anyone who suspects misuse of their information to contact local law enforcement and file a police report. It also points customers toward the Federal Trade Commission’s website for general guidance on protecting personal information. The letter identifies Freedom Fertility as part of the Evernorth family of companies and lists the privacy office at Express Scripts, Inc. as the contact for further questions.
What Should Affected Individuals Do?
Watch for Suspicious Health-Related Contact
Because the exposed data included diagnosis or condition information, affected individuals should be alert to unexpected messages referencing their health or medications. Scammers sometimes use stolen health details to make phishing attempts look more believable. If a message mentions your treatment or prescriptions and comes from an unfamiliar sender, treat it with suspicion.
Avoid clicking links or downloading attachments from senders you do not recognize. Instead, contact your pharmacy or provider directly using a phone number you already know is legitimate. This simple habit can prevent a scammer from tricking you into revealing more personal information.
Review Your Notification Letter Carefully
If you received a letter from Freedom Fertility Pharmacy, read it fully and keep a copy for your records. The letter contains specific details about what was exposed and who to contact with questions. Because this incident did not involve financial account numbers, the guidance focuses mostly on health privacy rather than credit protection.
If anything in the letter is unclear, reach out to the privacy office listed in the notification. Documenting your communication can also be useful later if you decide to consult an attorney about your rights.
Monitor Your Credit Reports as a Precaution
Although Social Security numbers were not part of this exposure, it is still wise to check your credit reports periodically. Identity thieves sometimes combine small pieces of personal information from multiple sources to attempt fraud. As a result, staying alert to unfamiliar accounts or inquiries is a reasonable precaution.
You can request free credit reports annually from each of the three major credit bureaus. Reviewing these reports regularly helps you catch unauthorized activity early, before it causes lasting financial damage.
Consider Filing a Police Report if You Suspect Misuse
The company’s own notification recommends contacting local law enforcement if you believe your information is being misused. Filing a police report creates an official record that can support any later claims related to identity theft or fraud.
This step is especially important if you notice unusual activity tied to your identity after receiving this notification. A police report can also strengthen your position if you choose to pursue legal action or seek compensation for harm caused by the disclosure.
Talk to a Data Breach Attorney About Your Options
Because this incident involved health-related information tied to fertility treatment, some affected individuals may have legal options worth exploring. An attorney who handles data breach cases can review your situation and explain whether you may qualify to join a claim.
Many attorneys offer free consultations for cases like this, so there is generally no upfront cost to learn more. Speaking with a professional can help you understand your rights and decide on the best next step for your circumstances.
Get a Free Case Review
Tell us how this breach affected you. A data breach attorney will review your situation at no cost and with no obligation — it takes about two minutes.
