CVS HEALTH CORPORATION
bd_dc8cb8248b2781d9 · schema v1 · pii pii-v1
Full breach record for CVS HEALTH CORPORATION →8 incidents on fileTALX Corporation, a subsidiary of Equifax, provided a supplemental notification to the New Hampshire Attorney General regarding a security incident affecting CVS Health employees. On July 8, 2019, TALX discovered that an unauthorized individual accessed the account of one NH resident, potentially viewing their 2015 W-2 form. The access occurred on December 10, 2016, via Knowledge-Based Authentication (KBA) bypass. TALX has implemented MFA and fraud prevention tools.
J jump to incidentP pin to compareR raw source
Incident timeline
Dec 10, 2016
Begins
Jul 8, 2019
Discovered
Sep 3, 2019
Filed
vs. sector median
on median
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.