Ridgeway Pharmacy Ltd. is notifying customers that their health information, insurance information, payment card details, and prescription records may have been exposed after an unauthorized party accessed the pharmacy’s website — a website built and run by a third-party vendor, not Ridgeway’s own internal systems.
Ridgeway Pharmacy Ltd., a California independent pharmacy, has begun notifying customers of a data breach involving their personal and health information. According to the notice letter, Ridgeway became aware on August 21, 2026 that a third-party vendor’s website — the platform used to run the pharmacy’s website — had been accessed by an unauthorized party. The underlying breach dates to June 7, 2026, meaning roughly 75 days passed between the breach and Ridgeway’s discovery of it. Notice went out to affected individuals and was reported to the California Attorney General on September 21, 2026, about a month after discovery.
Source: Ridgeway Pharmacy Ltd. notice letter and California Attorney General data breach report, filed 09/21/2026.
What Information Was Exposed
Ridgeway’s own notice letter confirms that the exposed information may have included customers’ name, address, date of birth, health information, health insurance information, payment card information, and prescription information. The letter states that Social Security numbers and driver’s license numbers were not involved. A separate filing with Massachusetts regulators lists a smaller set of confirmed categories for its own state residents, which we flag below.
Your Personally Identifiable Information (PII) includes information that can be used to identify you, such as your name and other personal details. Organizations that manage healthcare data are legally required to safeguard this information. When PII is exposed in a data breach, it can potentially be used by cybercriminals to commit identity theft, financial fraud, or other misuse.
Much of the information involved in this incident may also qualify as Protected Health Information (PHI). PHI includes medical or healthcare-related data protected under federal and state privacy laws. When PHI is compromised, it can be misused for medical identity theft or insurance fraud.
Residents of California may be entitled to additional protections under the California Consumer Privacy Act (CCPA), which provides enhanced rights regarding the collection, use, and safeguarding of personal information.
A Vendor Breach, Not Ridgeway’s Own Systems
Ridgeway’s notice letter is direct about the source of the breach: the compromised system was the pharmacy’s website, which was designed and operated by an outside vendor, and the letter states plainly that “at no time did this incident involve any of Ridgeway’s internal systems.” Ridgeway has not publicly named the vendor. Identifying that vendor matters — a breach at a shared website platform provider could mean other pharmacies or businesses using the same vendor were affected too, and it may point to an additional responsible party beyond Ridgeway itself.
Why This Matters
Prescription and health insurance records are among the most sensitive categories of personal information — they can reveal medical conditions, treatments, and coverage details that go well beyond what a typical retail data breach exposes. Combined with payment card information, this creates risk on two fronts: medical identity theft and financial fraud.
What You Can Do Now
- Enroll in the credit monitoring services offered in Ridgeway’s notice letter before the enrollment deadline
- Review your health insurance explanation-of-benefits statements for services you didn’t receive
- Monitor your payment card and bank statements closely for unauthorized charges
- Consider placing a fraud alert or credit freeze with the three major credit bureaus
- Contact us for a free case review if you received a notice letter from Ridgeway Pharmacy
Do You Have Legal Options?
Pharmacies that collect and store health, insurance, and payment information have a legal duty to secure that information — including the vendors and platforms they rely on. If you received a notice letter from Ridgeway Pharmacy, you may have legal options.
If you received a data breach notice from Ridgeway Pharmacy, contact Emery | Reddy today for a free case review.
FAQ
What information was exposed in the Ridgeway Pharmacy breach?
Ridgeway’s notice letter confirms name, address, date of birth, health information, health insurance information, payment card information, and prescription information. Social Security numbers and driver’s license numbers were not involved.
How many people are affected?
Ridgeway has not released a national total. A Massachusetts regulatory filing confirms at least 2,329 Massachusetts residents were affected, but that is a state subset — the full number of affected customers, including in California, is not yet public.
Was this a breach of Ridgeway’s own systems?
No. Ridgeway’s notice letter states the breach involved a third-party vendor’s website platform and specifically says the incident did not involve Ridgeway’s internal systems. The vendor has not been publicly named.
How long did it take Ridgeway to notify customers?
About 75 days passed between the breach (June 7, 2026) and Ridgeway becoming aware of it (August 21, 2026), and notice followed about a month later, on September 21, 2026.
Do I have a legal claim?
Pharmacies have a legal duty to protect the health, insurance, and payment information they collect, including from vendors and third-party platforms they rely on. If you received a notice letter from Ridgeway Pharmacy, contact the Data Breach Attorneys at Emery | Reddy at 916.995.5968 or www.emeryreddy.com for a Free Case Review. No Fee Unless We Recover.