MARYLANDPhysicalHealthcareRetail & ConsumerHealthcareTheftCustomer Data InvolvedHEALTH_BASICIDENTITY_BASICMediumResolved
Rite Aid Corporation
bd_3e4595c9e0dbf200 · schema v1 · pii pii-v1
Full breach record for Rite Aid Corporation →On April 27, 2015, rioters in Baltimore, MD broke into, vandalized, and looted eight Rite Aid locations, taking 2,345 filled 'will-call' prescriptions. The stolen prescriptions contained patients' names, addresses, and medication names. Rite Aid reported the breach to HHS on June 3, 2015, and notified affected individuals and the media, offering credit monitoring. All vandalized locations except one that was burned were re-opened with full security restored. OCR obtained assurances of corrective action. Breached information located on Other/Paper-Films.
HIPAA clock✓ HHS notified5 weeks discovery → filing
⚠ occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.
Tracked as a single-filing incident — the only disclosure on record for this event so far.Confirmed2,345 affectedView incident
Source provenance
- Source URL
- https://ocrportal.hhs.gov/ocr/breach/breach_report.jsf
DisclosureLens renders the full SEC/HHS filing inline below from the originating regulator’s public record (§4.5 fair report privilege).
- Filed at
- Jun 3, 2015
- Raw hash
- eaa584b1d09c924b403b2005be60c23899e2449988e83bd0e77f603923c00e6f
Source filing
AI-assisted summary above. The structured extract on this page was generated from the document below. Inspect the source to verify or correct any field.
Reporting entity
- Name
- Rite Aid Corporationnorm: rite aid
- Domain
- riteaid.com
- Industry
- Health Care Services
Victim entity
- Name
- Rite Aid Corporationnorm: rite aid
- Domain
- riteaid.com
- Industry
- Health Care Services
- Industry
- Healthcaresource defaultRetail & Consumerllm
Incident
- Discovered
- Apr 27, 2015
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- 2,345
- Data types
- HEALTH_BASICIDENTITY_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1052 Exfiltration Over Physical Medium
- Threat actor
- ExternalFinancial
- Regulator citations
- HHS OCR obtained assurances that corrective actions were implemented
Compliance
- Time to disclose
- 5 weeks(37 days from discovery to filing)
- Compliance flags
- HHS notified
- Discovery-date grounding
- occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.
- Clock breakdown
Statute Window Elapsed Threshold Status HIPAA Discovered: Apr 27, 2015→ Notified: not extracted— regulatory submission HHS notified
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.