Data Breach & Privacy
Blog > Data Breach & Privacy
Ridgeway Pharmacy Data Breach: What Patients Need to Know
Ridgeway Pharmacy, Ltd., the mail-order pharmacy behind Revive’s prescription delivery service, sent data breach notification letters dated September 21, 2026. The company says an unauthorized party accessed its vendor-built website, potentially exposing names, prescriptions, health and insurance information, and some payment card data.

What Information May Have Been Involved
Prescription, health, and payment information may have been exposed
According to Ridgeway’s notice and public statement, the information that may have been involved includes:
- Names
- Addresses
- Dates of birth
- Prescription information
- Health information
- Health insurance information
- Payment card information, for a portion of affected individuals
Ridgeway’s notice states that Social Security numbers and driver’s license numbers were not involved.
Prescription and health details are among the most sensitive kinds of personal information. Unlike a credit card number, a medication history or diagnosis cannot be changed or canceled once it has been exposed.
Who May Be Affected by the Ridgeway Pharmacy Breach
Customers who used the Ridgeway or Revive pharmacy website
People who may be affected include patients and customers who used Ridgeway’s website to fill, manage, or pay for prescriptions, including those who received medications through Revive’s mail-order pharmacy service. Because Ridgeway serves patients nationwide, affected individuals may live in any state.
Ridgeway has not published the total number of people affected. Its filing with the California Attorney General indicates that notices were sent to more than 500 California residents.
If you received a notification letter dated on or around September 21, 2026, your information was likely among the data involved.
How Ridgeway Pharmacy Responded and What Protections Are Offered
Ridgeway's response and the credit monitoring offer
According to the company, Ridgeway secured and remediated the affected website, launched a new platform, restricted access, strengthened monitoring, enhanced its security controls, and reevaluated its third-party arrangements. The company said it also reported the incident to federal law enforcement.
Ridgeway is offering affected individuals 12 months of complimentary credit monitoring and identity protection services. According to the notice, enrollment must be completed within 90 days of the date of the letter, which for letters dated September 21, 2026 falls around December 20, 2026.
Ridgeway has not named the website vendor or explained why the breach listed as beginning in June was not identified until late August.
Steps You Can Take to Protect Yourself
How to protect yourself after the Ridgeway Pharmacy breach
- Keep your notification letter and any related emails in a safe place.
- Consider enrolling in the complimentary credit monitoring before the deadline listed in your letter.
- Review your credit card and bank statements for charges you do not recognize, and ask your card issuer about a replacement card if you used a card on the Ridgeway or Revive website.
- Review Explanation of Benefits statements from your health insurer for prescriptions, visits, or services you did not receive, which can be a sign of medical identity theft.
- Consider placing a free fraud alert or security freeze with the three major credit bureaus.
- Be cautious of calls, texts, or emails that mention your prescriptions or ask for personal information, and verify any outreach independently before responding.
- Keep records of time spent and any out-of-pocket costs connected to the breach.
This is a general overview, not legal advice.
Talk to Wilshire Law Firm
Were you affected by the Ridgeway Pharmacy data breach?
If you received a notice from Ridgeway Pharmacy or Revive about this breach, you may have legal options. Wilshire Law Firm’s award-winning data privacy team is reviewing this incident and can help you understand your rights, including rights California residents may have when medical or health insurance information is exposed.
Contact us for a free consultation with a legal professional. We are available 24/7, and there are no fees unless you get paid.
FAQs
The breach report filed with the California Attorney General lists a breach date of June 7, 2026. Ridgeway said it became aware of the incident on August 21, 2026, and sent notification letters dated September 21, 2026.
According to Ridgeway, a vulnerability in its third-party vendor’s website allowed an unknown party to access the site using elevated privileges. The company has not named the vendor and said its internal systems were not affected.
According to the company, the information may include names, addresses, dates of birth, prescription information, health information, health insurance information, and, for some individuals, payment card information. Ridgeway said Social Security numbers and driver’s license numbers were not involved.
Ridgeway has not published a total. Its filing with the California Attorney General indicates that more than 500 California residents received notices. Because the pharmacy serves patients nationwide, the total may be larger.
Customers and patients who used Ridgeway’s website, including people who received prescriptions through Revive’s mail-order pharmacy service, may be affected. If you received a notification letter, your information was likely involved.
Yes. According to the notice, Ridgeway is offering 12 months of complimentary credit monitoring and identity protection services. Enrollment must be completed within 90 days of the date on your letter.
You may have legal options, especially if your prescription, health, or payment information was exposed. Every situation is different. Wilshire Law Firm offers free case reviews, and there are no fees unless you get paid.

