RXNT solution data incident

Unauthorized access within an RXNT solution used by a portion of its healthcare customers, with data acquisition between March 1 and March 3, 2026. Acquisition of personal and medical data held in the affected RXNT solution for healthcare-provider customers.

Last modified

Summary

  • Environment: Not publicly identified
  • Operational impact: No outage or recovery duration quantified
  • Financial impact: No public cost estimate
  • Record status: Developing record. Reviewed August 9, 2026; updated as evidence emerges.

What happened

Unauthorized access within an RXNT solution used by a portion of its healthcare customers, with data acquisition between March 1 and March 3, 2026. [1]

Impact

Acquisition of personal and medical data held in the affected RXNT solution for healthcare-provider customers. [1][2][3]

Documented data types include:

  • Names — Names; affected fields varied by person. [1][3]
  • Social Security numbers — Social Security numbers; affected fields varied by person. [1][3]
  • Clinical information — Medical information reported by the Texas and Massachusetts registries; affected fields varied by person. [1][3]
  • Dates of birth — Dates of birth; affected fields varied by person. [1][3]

A cited record reports 49,338 individuals (Texas residents in report BR-0005076; a subset of the overall count and not additive; as of 2026-05-29). [1][2][3]

A cited record reports 1,183 individuals (Massachusetts residents in report 2026-869; a subset of the overall count and not additive; as of 2026-05-29). [1][2][3]

A cited record reports 65,795 individuals (Total individuals affected in Texas Attorney General report BR-0005076; regulator-reported and not independently verified; as of 2026-05-29). [1][2][3]

RXNT said the incident did not involve payment-card, bank-account, or other financial information and that it was not aware of related identity theft or fraud at the time of notice. [1]

Timeline

  1. Activity began

    Beginning of the data-acquisition window determined by RXNT’s investigation.

    [1]
  2. Documented activity ended

    End of the data-acquisition window determined by RXNT’s investigation.

    [1]
  3. Discovery

    Date RXNT says it became aware of unauthorized activity.

    [1]
  4. Public disclosure

    Date RXNT says it began notifying affected customers; individual and regulator notices could occur later.

    [1]
  5. Briefing updated

    This briefing was last reviewed and updated on August 9, 2026.

Threat Group & Attack Vector

The cited public record does not establish a specific initial-access vector, malware family, exploited vulnerability, or ATT&CK technique.

Actors

  • No threat actor group has been identified in the reviewed public evidence.

TTPs

  • No specific MITRE ATT&CK technique is currently mapped for this case.

Response

RXNT notified law enforcement during its response. RXNT offered affected people a templated 12 or 24 months of complimentary credit monitoring, depending on the individual notice. RXNT said it contained the activity with external cybersecurity experts and confirmed the unauthorized actor was eliminated from the environment. No access path, attribution, scale, or recovery detail is inferred beyond the cited claims. [1]