Rite Aid Corporation
bd_0466f8196c933572 · schema v1 · pii pii-v1
Full breach record for Rite Aid Corporation →10 incidents on fileRite Aid Pharmacy Store 01617 (NY) reported to HHS on 2016-02-03 an Unauthorized Access/Disclosure affecting 976 individuals. From November 19, 2014 through November 18, 2015, an internal employee obtained customers' credit card information and other personal identifiers from Desktop Computer and other systems, using them to commit credit card fraud. ePHI involved included names, addresses, dates of birth, and credit card data. The employee was terminated; card handling policies were revised; OCR provided technical assistance on HIPAA Security Rule compliance. Breached info located on Desktop Computer, Other.
J jump to incidentP pin to compareR raw source
Incident timeline
Nov 19, 2014
Begins
Nov 18, 2015
Discovered
Feb 3, 2016
Filed
vs. sector median
on median
Linked disclosures
Why this link?Regulatory filings (1) · sorted by filing gap
- Massachusetts State AGbd_98776dfa47a3fd872016-02-09 · +6dVerified
Filing propagation · 2 filings · 2 states
View merged incident ↗Pattern: first filing Feb 3 (NY), last Feb 9 (MA) — a 6-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.