DisclosureLens
NEW YORKMisuseHealthcareRetail & ConsumerHealthcarePrivilege AbuseData MishandlingCustomer Data InvolvedData ExfiltratedHealth (basic)Identity (basic)Financial credentialsLowResolved

Rite Aid Corporation

bd_0466f8196c933572 · schema v1 · pii pii-v1

Severity

Low

Discovered

Nov 18, 2015

Filed

Feb 3, 2016

To disclose

11 weeks

Affected

976

Linked

2 filings

Confidence

95%
Full breach record for Rite Aid Corporation10 incidents on file

Rite Aid Pharmacy Store 01617 (NY) reported to HHS on 2016-02-03 an Unauthorized Access/Disclosure affecting 976 individuals. From November 19, 2014 through November 18, 2015, an internal employee obtained customers' credit card information and other personal identifiers from Desktop Computer and other systems, using them to commit credit card fraud. ePHI involved included names, addresses, dates of birth, and credit card data. The employee was terminated; card handling policies were revised; OCR provided technical assistance on HIPAA Security Rule compliance. Breached info located on Desktop Computer, Other.

HIPAA clock HHS notified11 weeks discovery → filing
unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.

Incident timeline

undetected · 364 days
discovery → filing · 11 weeks / 77 days

Nov 19, 2014

Begins

Nov 18, 2015

Discovered

Feb 3, 2016

Filed

vs. sector median

on median

This filing is one of 2 about the same incident.View merged incident

Linked disclosures

Why this link?

Regulatory filings (1) · sorted by filing gap

Filing propagation · 2 filings · 2 states

View merged incident ↗
HHS OCRFeb 3 · first · this page

Pattern: first filing Feb 3 (NY), last Feb 9 (MA) — a 6-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.