
Kroger Postal Prescription Services (Kroger PPS), a full-service mail-order pharmacy based in Portland, Oregon, filed a data breach notification with the US Department of Health and Human Services Office for Civil Rights (HHS-OCR) after discovering that confidential consumer information in the company’s possession had been subject to unauthorized access.
While the HHS-OCR listing does not specify the data types that were leaked, it appears that the breach affected consumers’ protected health information based on the company’s filing with the HHS-OCR. According to the HHS-OCR, the Kroger PPS data breach affected the information of 82,466 people who created online PPS accounts between July 2014 and January 13, 2023.
On March 15, Kroger PPS sent data breach notification letters to all impacted individuals after confirming that consumer data had been leaked. At this time, little information is available about the Kroger PPS breach.
When Kroger Postal Prescription Services discovered that sensitive consumer data had been made available to an unauthorized party, they reviewed the affected files to determine what information had been compromised and which customers had been impacted.
Kroger is currently reviewing its procedures to make changes that will reduce the likelihood of a similar incident occurring. Under various names, the company operates over 2,700 grocery stores in 35 states and Washington, D.C. Kroger employs over 500,000 people and has an annual revenue of approximately $144 billion.
Winston House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF
020 8349 4363
© 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543