
Telehealth platform AgelessRx said it suffered a significant data security incident earlier this year that compromised the sensitive personal information of its patients and staff.
AgelessRx is a U.S.-based tele-health company headquartered in Ann Arbor, Michigan. Founded in 2019, it provides physician-guided longevity and preventive healthcare services, offering online access to prescription therapies, diagnostic testing, and personalised treatments focused on healthy aging and metabolic wellness.
In a data security incident notice filed with the Office of California Attorney General, AgelessRx said that on April 22, it identified unauthorised access within its internal network. The healthcare provider immediately launched an investigation, with assistance from external cyber security experts, to determine the nature and scope of the incident.
It also took steps to secure the affected systems and notified relevant law enforcement authorities about the incident.
“As a result of that investigation, AgelessRx identified that between April 17, 2026 and April 22, 2026, certain help-desk tickets were accessed by an unauthorised actor. AgelessRx is notifying you of this incident because after reviewing the affected data, on May 27, 2026 we determined that your information was included in the affected help-desk tickets,” AgelessRx said.
The compromised data included names, dates of birth, health diagnosis and conditions, medications, and other treatment information. The company, however, did not share the number of affected individuals.
“The confidentiality, privacy, and security of i nformation in our care are among our highest priorities. We are reviewing existing security policies and have implemented additional cybersecurity measures to further protect against similar incidents moving forward,” AgelessRx added.
The tele-healthcare has advised all affected individuals to regularly monitor their credit reports, account and benefit statements and report any suspicious activity to law enforcement authorities, including the police and the state attorney general. It has also offered complimentary identity protection and credit monitoring services through Experian to all individuals.
In April, an unnamed threat group claimed responsibility for the cyber attack on AgelessRx and listed the company as a victim on its data leak site. According to the group, it obtained a database containing sensitive information, including names, email addresses, dates of birth, physical addresses, phone numbers, medical conditions, medications, allergies, prescription details, pharmacy information, and other confidential data.
The threat actors also indicated their willingness to sell the stolen database, suggesting that ransom negotiations with the victim were unsuccessful.
Winstone House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF
020 8349 4363
© 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543