Data breach may have affected Butler County medical marijuana customers

Credit: DaytonDailyNews

Bloom Medicinals medical marijuana dispensary opens in Seven Mile

Credit: DaytonDailyNews

A company that operates medical marijuana dispensaries, including one in Butler County, was affected by data breach that involved more than 30,000 customers, according to a report.

A report released yesterday indicated that medical marijuana purchasers nationally had their sensitive personal information breached. Bloom Medicinals, which owns the dispensary that opened last year in Seven Mile, was one of three companies in the U.S. identified in the data breach.

Privacy researchers at vpnMentor discovered a breach in a point-of-sale system used by Bloom and other medical marijuana companies.

They said the data breach exposed information about the dispensary’s inventory, monthly sales reports, and compliance reports, as well as the following patient details:

• Full name

• Date of birth

• Medical/State ID and expiration date

• Phone number

• Email address

• Street address

• Date of first purchase

• Whether or not the patient received financial assistance for cannabis purchases

• Whether or not the patient opted in for SMS text notifications

“We were able to view the dispensary’s monthly sales, discounts, returns, and taxes paid,” the company reported. “The sales were further broken down by payment method and product type.”

In Ohio, patients can only use cash to purchase their prescriptions.

Ali Simon, a spokeswoman for the State of Ohio Board of Pharmacy that regulates the dispensaries, said Bloom is the only Ohio cannabis company that uses the THSuite point-of-sale system in question.

“The board takes any breach of data security and private patient information very seriously,” Simon wrote. “The board cannot comment at this time, but is looking into this issue.”

Bloom could not immediately be reached for comment.

The Seven Mile location opened last October on Main Street.