Morton LTC Pharmacy Data Breach Exposes Patient Health and Personal Information

Published: 8 October 2026
Healthcare data breach illustration
Breach Discovery: Not Publicly DisclosedBreach Notification: Not Publicly Disclosed

A ransomware group called RunSomeWares has claimed to have breached Morton LTC Pharmacy, a Wisconsin pharmacy serving long-term care facilities, potentially exposing patient health and personal information. The pharmacy has not confirmed the claim publicly. Affected individuals should monitor credit reports and insurance statements closely and watch for official notification.

CompanyMorton LTC Pharmacy
IndustryHealthcare
Data Types ExposedPatient Names and Contact Information, Dates of Birth, Medication and Prescription Records, Health Insurance Information, Social Security Numbers, Billing and Payment Account Details
People AffectedNot Publicly Disclosed
Attack MethodRansomware
Regulators NotifiedNot Publicly Disclosed

Were you affected by this breach?

You may be owed compensation.

Data breach victims can recover money for identity-theft losses, out-of-pocket costs, wasted time, and the ongoing risk of fraud — usually with no upfront cost, and no fee unless you win.

Check if you qualify — free review

What Happened in the Morton LTC Pharmacy Data Breach?

Morton LTC Pharmacy, a fourth-generation family-owned pharmacy based in Wisconsin, has reportedly been targeted in a cyberattack. A threat actor group calling itself RunSomeWares has claimed responsibility for the incident on a dark web leak site. The claim indicates the group may have accessed sensitive systems tied to the pharmacy’s operations.

As of now, Morton LTC Pharmacy has not publicly confirmed this incident. The exact method RunSomeWares used to gain access has not been disclosed. Because this is a claim made by the attacker group rather than a confirmed statement from the company, many details about the timeline remain unknown.

At this stage, there is no publicly available information confirming when the breach was discovered internally. There is also no confirmed notification date available. As a result, individuals who may be affected should watch for official communication from Morton LTC Pharmacy or regulatory bodies in the coming weeks. Independent forensic verification of the attacker’s claims has not yet been reported.

Who was affected?

Morton LTC Pharmacy serves long-term care facilities, which typically means its clients include elderly and vulnerable patients. This raises particular concern because long-term care pharmacy patients often have more extensive medical histories. In addition, these patients may be less equipped to monitor their own accounts for suspicious activity.

The total number of individuals affected by this incident has not been publicly disclosed. It is not yet clear whether the exposure includes only patients or also extends to employees of the pharmacy. Given the nature of long-term care pharmacy services, family members or caregivers managing a patient’s affairs could also be indirectly affected if account access or billing information was compromised.

What Information Was Potentially Exposed?

Because Morton LTC Pharmacy has not issued a formal statement, the specific data types involved in this incident have not been officially confirmed. However, pharmacies serving long-term care patients typically maintain highly sensitive categories of information. Based on the nature of the business and the sector targeted, the following types of data may be at risk.

  • Patient names and contact information
  • Dates of birth
  • Medication and prescription records
  • Health insurance information
  • Social Security numbers
  • Billing and payment account details

If medical and prescription data were indeed exposed, affected individuals could face a heightened risk of medical identity theft. This occurs when someone uses stolen health information to obtain medical services, prescriptions, or equipment under another person’s identity. This can also create dangerous inaccuracies in a victim’s medical records, which may affect future care.

In addition, if Social Security numbers or financial account details were part of the exposure, individuals could face conventional identity theft risks. This includes fraudulent credit applications, unauthorized loans, or tax fraud. Because long-term care patients are a historically targeted group for fraud, these risks deserve serious attention from caregivers and family members alike.

What is the company doing?

Morton LTC Pharmacy has not publicly confirmed the ransomware claim made by RunSomeWares. Therefore, no official statement regarding an investigation, remediation steps, or notification process is currently available. As this is based on a claim from the threat actor group rather than a confirmed disclosure by the pharmacy, readers should treat any response details as unconfirmed at this time.

Should the breach be confirmed, affected individuals would typically expect notification from the pharmacy describing the scope of the incident. Pharmacies handling protected health information are generally required to follow breach notification rules. Until Morton LTC Pharmacy releases an official statement, the extent of its response efforts remains unknown.

What Should Affected Individuals Do?

Monitor Your Credit Reports

Affected individuals, or their caregivers, should request a copy of their credit report from each of the three major credit bureaus. This allows you to check for unfamiliar accounts, inquiries, or activity you don’t recognize. Because the specific data exposed in this incident hasn’t been confirmed, a cautious approach is wise.

You are entitled to a free credit report annually from each bureau. Checking reports regularly over the next year can help catch early warning signs of fraud. For example, a sudden new credit account or hard inquiry could indicate your information is being misused.

Consider a Fraud Alert or Credit Freeze

If Social Security numbers or financial information turn out to have been exposed, placing a fraud alert or credit freeze is a strong protective step. A fraud alert requires creditors to verify your identity before opening new accounts in your name. A credit freeze goes further by restricting access to your credit file entirely.

Both options are free and can be requested directly through the credit bureaus. Because long-term care patients may rely on family members to manage finances, caregivers should consider setting up these protections on behalf of vulnerable patients. This extra layer of security can prevent significant financial harm down the line.

Watch for Medical Billing and Insurance Fraud

Because this breach involves a pharmacy, it’s worth paying close attention to medical bills and insurance statements. Look for unfamiliar charges, prescriptions you did not request, or insurance claims for services you never received. This can be a sign that your health information has been misused.

If you notice anything suspicious, contact your health insurance provider immediately. In addition, request a copy of your insurance claims history to check for discrepancies. Catching medical identity theft early can prevent larger complications with your medical records and insurance coverage.

Stay Alert for Phishing Attempts

After a healthcare-related data breach, scammers often use stolen information to craft convincing phishing emails, texts, or phone calls. These messages may impersonate the pharmacy, an insurance company, or even a government agency. Be cautious of any unexpected communication asking for personal or financial details.

Never click links or provide information in response to unsolicited messages. Instead, verify requests by contacting the organization directly using a phone number or website you know is legitimate. This simple habit can prevent scammers from gaining further access to your accounts.

Consult a Data Breach Attorney

If you believe you were affected by this incident, it may be worth speaking with an attorney who focuses on data breach cases. They can help you understand your rights and whether you may be eligible for compensation. Many offer free consultations to evaluate your situation.

Because this incident involves a healthcare provider, additional protections under health privacy laws may apply. An attorney can help clarify whether Morton LTC Pharmacy’s handling of this incident meets legal obligations. This guidance can be especially valuable for patients or families who are unsure of their next steps.

Get a Free Case Review

Tell us how this breach affected you. A data breach attorney will review your situation at no cost and with no obligation — it takes about two minutes.



Related Data Breaches

View the full list of tracked data breaches →