Blog > Data Breach & Privacy

Ridgeway Pharmacy Data Breach: What Patients Need to Know

Ridgeway Pharmacy, Ltd., the mail-order pharmacy behind Revive’s prescription delivery service, sent data breach notification letters dated September 21, 2026. The company says an unauthorized party accessed its vendor-built website, potentially exposing names, prescriptions, health and insurance information, and some payment card data.

Ridgeway Pharmacy Data Breach: What Patients Need to Know

What Happened in the Ridgeway Pharmacy Data Breach

How an unauthorized party accessed the Ridgeway Pharmacy website

Ridgeway Pharmacy, Ltd. is a mail-order prescription pharmacy that describes itself as fully licensed to dispense prescriptions in all 50 states. Its website is branded “Revive by Ridgeway,” and it fills prescriptions delivered through Revive Health’s pharmacy service.

According to the company’s notice, Ridgeway’s website, which was designed and developed by a third-party vendor, was accessed by an unauthorized party. In a public statement, Ridgeway said a vulnerability in the vendor’s website allowed an unknown third party to access the site using elevated privileges. The company said its internal systems were not affected.

Ridgeway said it became aware of the incident on August 21, 2026. The breach report filed with the California Attorney General lists a breach date of June 7, 2026, which suggests the unauthorized access may have begun more than two months before it was discovered. Notification letters are dated September 21, 2026.

What Information May Have Been Involved

Prescription, health, and payment information may have been exposed

According to Ridgeway’s notice and public statement, the information that may have been involved includes:

  • Names
  • Addresses
  • Dates of birth
  • Prescription information
  • Health information
  • Health insurance information
  • Payment card information, for a portion of affected individuals

Ridgeway’s notice states that Social Security numbers and driver’s license numbers were not involved.

Prescription and health details are among the most sensitive kinds of personal information. Unlike a credit card number, a medication history or diagnosis cannot be changed or canceled once it has been exposed.

Who May Be Affected by the Ridgeway Pharmacy Breach

Customers who used the Ridgeway or Revive pharmacy website

People who may be affected include patients and customers who used Ridgeway’s website to fill, manage, or pay for prescriptions, including those who received medications through Revive’s mail-order pharmacy service. Because Ridgeway serves patients nationwide, affected individuals may live in any state.

Ridgeway has not published the total number of people affected. Its filing with the California Attorney General indicates that notices were sent to more than 500 California residents.

If you received a notification letter dated on or around September 21, 2026, your information was likely among the data involved.

How Ridgeway Pharmacy Responded and What Protections Are Offered

Ridgeway's response and the credit monitoring offer

According to the company, Ridgeway secured and remediated the affected website, launched a new platform, restricted access, strengthened monitoring, enhanced its security controls, and reevaluated its third-party arrangements. The company said it also reported the incident to federal law enforcement.

Ridgeway is offering affected individuals 12 months of complimentary credit monitoring and identity protection services. According to the notice, enrollment must be completed within 90 days of the date of the letter, which for letters dated September 21, 2026 falls around December 20, 2026.

Ridgeway has not named the website vendor or explained why the breach listed as beginning in June was not identified until late August.

Steps You Can Take to Protect Yourself

How to protect yourself after the Ridgeway Pharmacy breach

  • Keep your notification letter and any related emails in a safe place.
  • Consider enrolling in the complimentary credit monitoring before the deadline listed in your letter.
  • Review your credit card and bank statements for charges you do not recognize, and ask your card issuer about a replacement card if you used a card on the Ridgeway or Revive website.
  • Review Explanation of Benefits statements from your health insurer for prescriptions, visits, or services you did not receive, which can be a sign of medical identity theft.
  • Consider placing a free fraud alert or security freeze with the three major credit bureaus.
  • Be cautious of calls, texts, or emails that mention your prescriptions or ask for personal information, and verify any outreach independently before responding.
  • Keep records of time spent and any out-of-pocket costs connected to the breach.

This is a general overview, not legal advice.

Talk to Wilshire Law Firm

Were you affected by the Ridgeway Pharmacy data breach?

If you received a notice from Ridgeway Pharmacy or Revive about this breach, you may have legal options. Wilshire Law Firm’s award-winning data privacy team is reviewing this incident and can help you understand your rights, including rights California residents may have when medical or health insurance information is exposed.

Contact us for a free consultation with a legal professional. We are available 24/7, and there are no fees unless you get paid.

FAQs

The breach report filed with the California Attorney General lists a breach date of June 7, 2026. Ridgeway said it became aware of the incident on August 21, 2026, and sent notification letters dated September 21, 2026.

According to Ridgeway, a vulnerability in its third-party vendor’s website allowed an unknown party to access the site using elevated privileges. The company has not named the vendor and said its internal systems were not affected.

According to the company, the information may include names, addresses, dates of birth, prescription information, health information, health insurance information, and, for some individuals, payment card information. Ridgeway said Social Security numbers and driver’s license numbers were not involved.

Ridgeway has not published a total. Its filing with the California Attorney General indicates that more than 500 California residents received notices. Because the pharmacy serves patients nationwide, the total may be larger.

Customers and patients who used Ridgeway’s website, including people who received prescriptions through Revive’s mail-order pharmacy service, may be affected. If you received a notification letter, your information was likely involved.

Yes. According to the notice, Ridgeway is offering 12 months of complimentary credit monitoring and identity protection services. Enrollment must be completed within 90 days of the date on your letter.

You may have legal options, especially if your prescription, health, or payment information was exposed. Every situation is different. Wilshire Law Firm offers free case reviews, and there are no fees unless you get paid.

Related Content

Guides, nearby offices, and related practice areas.

Start Your Free Case Review

4.9 out of 2,525 reviews
  • Available 24/7
  • Hablamos Español
  • Nationally-Recognized Powerhouse Team
As seen in:

We'll contact you within minutes

No fees unless you get paid.

By submitting this form, you knowingly, voluntarily, and expressly consent to receive from Wilshire Law Firm telephone calls, emails, and SMS text messages, including those made using an automatic telephone dialing system (auto-dialer), artificial intelligence (AI), and/or pre-recorded or artificial voice messages. These communications are for the purpose of providing prompt consultation regarding your potential case. You understand that by providing your telephone number, you are granting permission to be contacted for this purpose, even if your number is on a federal or state Do-Not-Call registry. Consent is not required as a condition of retaining Wilshire Law Firm. Message and data rates may apply. You may revoke your consent to receive calls, texts, or emails at any time by replying “STOP” to any text message, calling 888-557-3271, filling out the form at wilshirelawfirm.com/do-not-contact or by any other reasonable method. For more information, refer to our Privacy Policy.

Locations

Find your nearest office — serving all of California and employment clients in Oregon and Washington.

Appointments required for office visits

Beverly HillsIrvineLos AngelesOaklandRiversideSacramentoSan DiegoTorrance