Ridgeway Pharmacy Ltd discovered in August 2026 that an unauthorized party accessed its website through a third-party vendor, potentially exposing names, addresses, birth dates, health and insurance information, payment card details, and prescription records. The exact number of affected customers has not been publicly disclosed. Affected individuals should enroll in the free credit monitoring Ridgeway is offering within 90 days and watch for signs of medical or financial fraud.
| Company | Ridgeway Pharmacy Ltd |
|---|---|
| Industry | Healthcare |
| Data Types Exposed | Name, Address, Date of Birth, Health Information, Insurance Information, Payment Card Information, Prescription Information |
| People Affected | Not Publicly Disclosed |
| Attack Method | Third-Party Vendor Breach |
| Regulators Notified | California Attorney General |
Were you affected by this breach?
You may be owed compensation.
Data breach victims can recover money for identity-theft losses, out-of-pocket costs, wasted time, and the ongoing risk of fraud — usually with no upfront cost, and no fee unless you win.
Check if you qualify — free reviewWhat Happened in the Ridgeway Pharmacy Data Breach?
Ridgeway Pharmacy Ltd has notified customers about a data security incident tied to its pharmacy website. The company discovered the issue in August 2026. An unauthorized party had gained access to the site, which was built and maintained by an outside vendor rather than Ridgeway’s own systems.
According to the notification, the breach involved the website platform specifically. Ridgeway stated that its internal systems were never touched. Instead, the unauthorized access ran through the third-party vendor’s infrastructure that powered the pharmacy’s online presence, which is a common target because vendor platforms often hold customer records outside a company’s direct security controls.
Once Ridgeway learned of the intrusion, it moved to bring in outside help. The company hired external cybersecurity and forensic experts to investigate the scope of the incident. It also reported the matter to federal law enforcement. As part of the review, investigators examined data and technical records the vendor provided about the website’s operation, which allowed Ridgeway to determine which records may have been viewed or taken.
Who was affected?
The notification does not state a specific number of affected individuals. Therefore, the total count of impacted customers has not been publicly disclosed. Based on the nature of the breach, those affected appear to be customers who used Ridgeway’s pharmacy website to fill prescriptions or manage their accounts.
Because the exposed data includes prescription and insurance information, the incident likely affects people who rely on Ridgeway for ongoing medication needs. This may include elderly patients, individuals managing chronic conditions, or anyone who submitted payment and health details through the site. The breach notice does not indicate whether minors were among those affected, though the enrollment instructions for credit monitoring note that the offered service may not be available to individuals under 18.
What Information Was Potentially Exposed?
Ridgeway’s investigation identified several categories of personal data that may have been accessed on the pharmacy website. The company was direct in stating what was and was not involved. Notably, Social Security numbers and driver’s license numbers were not part of this incident.
- Full name
- Home address
- Date of birth
- Health information
- Insurance information
- Payment card information
- Prescription information
Even without Social Security numbers in the mix, this combination of data carries real risk. For example, health and prescription details combined with a name and birth date can support medical identity theft, where someone uses stolen health information to obtain treatment, medication, or insurance benefits fraudulently. This can also lead to inaccurate medical records that follow a victim for years.
In addition, payment card information exposed alongside personal identifiers raises the risk of financial fraud. Scammers often use these details for unauthorized purchases or to create convincing phishing messages that reference a person’s real prescriptions or pharmacy visits. As a result, affected individuals should treat any unexpected calls or emails referencing their medications with caution.
What is the company doing?
As soon as Ridgeway confirmed the incident, it launched a full investigation into what happened and how far it reached. The company remediated the affected website and rebuilt it on a new platform. It also strengthened access controls and expanded monitoring to catch unauthorized activity going forward.
Ridgeway has since reviewed its relationships with third-party vendors connected to the website. This included asking about additional security measures and pushing vendors to adopt stronger protections. In addition, the company filed a formal notification with the California Attorney General, as required under state breach notification law.
To help affected customers, Ridgeway is offering free access to Single Bureau Credit Monitoring, credit report, and credit score services through Cyberscout, a TransUnion company. This coverage lasts 12 months from the date of enrollment and includes alerts whenever changes appear on a person’s credit file. Ridgeway is also providing proactive fraud assistance for anyone with questions or concerns about identity theft.
What Should Affected Individuals Do?
Enroll in the Free Credit Monitoring Offered
Anyone who received a notification letter should enroll in the credit monitoring service right away. Ridgeway has given a 90-day enrollment window from the date of the letter, so acting quickly matters. The service is free and includes ongoing alerts if new activity shows up on a credit file.
To sign up, visit the enrollment website listed in the notification letter and use the unique code provided. Because enrollment requires an internet connection and an email account, those without regular internet access may want help from a family member. Note that the service may not be available to those under 18.
Watch for Signs of Medical Identity Theft
Because health and prescription information was involved, affected individuals should review insurance statements and explanation-of-benefits notices closely. Look for any medical services, prescriptions, or claims that do not match your actual care. This is one of the clearest warning signs of medical identity theft.
If anything looks unfamiliar, contact your insurance provider immediately to dispute the charge. In addition, request a copy of your medical records periodically to confirm they only reflect your actual treatment history. Catching errors early can prevent long-term complications with insurance coverage or future medical care.
Monitor Financial Accounts and Consider a Fraud Alert
Since payment card information was part of this breach, affected individuals should check bank and credit card statements regularly. Look for any charges you do not recognize, even small ones, since fraudsters often test stolen cards with minor purchases first. Report anything suspicious to your card issuer right away.
You may also want to place a fraud alert on your credit file. This step makes it harder for someone to open new credit accounts using your name. While Social Security numbers were not exposed in this incident, a fraud alert still adds a useful layer of protection given the other personal details involved.
Stay Alert to Phishing Attempts
Because attackers now have real names, addresses, and even prescription details, phishing attempts following this breach could look highly convincing. Be cautious of emails, texts, or calls claiming to be from Ridgeway, your insurance company, or a credit monitoring service. Never click links or share personal details in response to unsolicited messages.
Instead, go directly to the official website or call the company using a number you already trust. If you receive a suspicious message referencing your prescriptions, verify it with your pharmacy directly. This extra step can prevent scammers from tricking you into handing over even more sensitive information.
Get a Free Case Review
Tell us how this breach affected you. A data breach attorney will review your situation at no cost and with no obligation — it takes about two minutes.
More Information
Official data breach notification from California Attorney General
