Freedom Fertility Pharmacy, operated by Lynnfield Drug, Inc., has told customers that an employee error sent their personal information to someone who was not authorized to see it. The exposed details include health-related information.
Freedom Fertility Pharmacy’s Data Breach Investigation
Freedom Fertility Pharmacy, the trade name of Lynnfield Drug, Inc., has notified customers of an incident in which personal information was sent by e-mail to an unauthorized recipient. In its notification letter, the company explains that the cause was an employee inaccuracy rather than an attack by outside criminals. The letter was filed with Massachusetts regulators and appears on that state’s October 2026 list of data breach notification letters, where the filing reports 15 Massachusetts residents affected.
According to the letter, the incident occurred on September 19, 2026, and was discovered on September 22, 2026. The notification itself is dated October 7, 2026. The company describes the matter as a potential disclosure of customer information. The e-mail that went to the wrong recipient could have included a customer’s e-mail address, name, and diagnosis or condition. The letter identifies Freedom Fertility as an Evernorth company and directs questions to the privacy office at Express Scripts, Inc.
The company says its privacy office investigated the circumstances and took steps to reduce any harm that might result. To prevent a repeat, it states that it disciplined the employee responsible. The letter does not say who the unauthorized recipient was, whether that person has confirmed deleting the message, or whether anyone has used or shared the information. It also does not state a total number of affected people across all states, so the Massachusetts figure should be read as a count of Massachusetts residents only.
Misdirected e-mail is one of the most common causes of privacy incidents in health care and pharmacy settings. It does not require a hacker, a stolen password, or malware. A single autocomplete mistake, a wrong attachment, or a reply sent to the wrong address can place personal details in front of a stranger. Because these incidents involve a message rather than a compromised database, the exposure is often limited to a small number of people, as the Massachusetts count suggests here. Even so, the nature of the information matters more than the number of people involved.
In this case, the information includes a diagnosis or condition. Freedom Fertility Pharmacy fills fertility medications, so a customer’s diagnosis or condition can reveal sensitive details about reproductive health and family planning. Health information of this kind is among the most private categories of personal data. Unlike a password or a card number, it cannot be changed once it has been disclosed, and its release can cause embarrassment, stress, or discrimination concerns even where no financial harm follows.
Health privacy rules treat information about a person’s condition with particular care. Pharmacies and the companies that own them are expected to limit who can see patient details, to train staff on handling messages that contain them, and to put safeguards around outgoing e-mail. When a message goes to the wrong person, the affected customer has no way to know who read it or what was done with it, which is why even a small, well-contained incident can leave people uneasy. A prompt, plain explanation of what was sent and to whom is the most useful thing a company can give the people affected, and this letter provides only part of that picture.
The company’s letter takes a notably short and plain approach. It does not offer credit monitoring or identity protection services, which is consistent with the fact that the e-mail described did not include Social Security numbers or financial account details. What the letter does recommend is that anyone who believes their information is being misused contact local law enforcement to file a police report, and that people seek guidance from the Federal Trade Commission about protecting personal information.
People who received this letter should keep it and should pay attention to any unexpected contact that references their health, their medications, or their treatment. Messages from unfamiliar senders that seem to know personal medical details may be attempts to take advantage of the disclosure. Class Action U is following this incident, and the details above may be updated as more information becomes available from the company or from regulators.
When Did This Breach Occur?
The incident occurred on September 19, 2026, and the company discovered it on September 22, 2026. Freedom Fertility Pharmacy’s notification letter to affected customers is dated October 7, 2026, and it was filed with Massachusetts regulators in October 2026.
What Information Was Breached?
According to the notification letter, the e-mail sent to the unauthorized recipient could have included the customer’s e-mail address, name, and diagnosis or condition. The letter does not say that Social Security numbers, financial account numbers, or medication lists were included. The specific diagnosis or condition information is the most sensitive element because of what it can reveal about a person’s health.
What You Can Do
Read your notification letter carefully and keep a copy. The company says anyone who believes their information is being misused should contact local law enforcement to file a police report, and it points customers to the Federal Trade Commission at ftc.gov for guidance on protecting personal information. Questions can be directed to the privacy office named in the letter.
Because the exposed information is health-related, be cautious about unexpected e-mails, calls, or texts that mention your health or prescriptions, avoid clicking links in messages from senders you do not recognize, and review any explanation-of-benefits statements for services you did not receive.
File a Data Breach Lawsuit Against Freedom Fertility Pharmacy
If you received a notice from Freedom Fertility Pharmacy, your health-related personal information may have been disclosed without your permission. Pharmacies and the companies behind them are expected to keep patient information confidential, and people affected by a failure to do so may have legal options worth discussing with an attorney.
Contact us at Class Action U, where we’ll connect you with a lawyer skilled in class action lawsuits. If you’ve been contacted about this breach, received notice, or discovered you were impacted, fill out our quick, easy, and secure form to sign up. There is no cost to reach out to our legal partner and no obligation after speaking with someone from our team.