WALMART INC.
ent_019dea4cdcc59179f676e3cd714820c1
Disclosures
24
SEC 10-K Item 1C · State AG · HHS OCR · 6 jurisdictions
Incidents
6
filings grouped by incident
Max affected reported
27,393
as filed · HHS OCR FEDERAL
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- WALMART INC.
- Normalized
- walmart— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- Y87794H0US1R65VBXU25
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- walmart.com
Disclosure history (24)newest first
- FEDERALSEC 10-K Item 1Cas victim2026-03-13
Walmart's 10-K Item 1C disclosure states that while the company experienced certain cybersecurity incidents and threats from its own systems and third-party service providers, it is not aware of any risks from cybersecurity threats that have materially affected or are reasonably likely to materially affect its business, financial condition, or results of operations. The filing details robust governance, including Board and Audit Committee oversight, and a comprehensive cybersecurity program.
- 🦞Maine State AGas victim2025-01-09
Walmart Inc. reported an insider wrongdoing incident to the Maine AG involving 2 Maine residents. The breach occurred on December 10, 2024, and was discovered on January 3, 2025. Affected individuals were notified in writing on January 10, 2025. Walmart offered 12 months of Experian identity protection and credit monitoring services to affected individuals.
- ARHHS OCRas victim2024-06-14
Walmart Inc. reported to HHS on 2024-06-14 an Unauthorized Access/Disclosure affecting 1,267 individuals. A technical error made by an employee allowed PHI — including names, dates of birth, and gender — to be viewable via the Internet. Breached information was located on a Network Server. The CE notified HHS, affected individuals, and the media, then implemented additional technical safeguards and retrained its workforce.
- 🏎️Indiana State AGas victim2024-04-05
Walmart Inc reported a data breach to the Indiana Attorney General. The breach occurred on 2023-09-01 and was reported on 2024-04-05. 9 Indiana residents were affected. 361 individuals affected in total.
- 🦞Maine State AGas victim2024-02-23
Walmart Inc. identified a data breach resulting from an external system hack. The incident, which occurred between December 2023 and February 2024, compromised the names and Social Security numbers of 204 individuals. Walmart notified the affected parties in February 2024 and offered two years of identity theft and fraud monitoring services.
- 🏎️Indiana State AGas victim2024-02-23
Walmart Inc reported a data breach to the Indiana Attorney General. The breach occurred on 2023-12-03 and was reported on 2024-02-23. 4 Indiana residents were affected. 204 individuals affected in total.
- 🦬Montana State AGas victim2024-02-22
Walmart Inc reported a data breach to the Montana Attorney General. The breach was reported on 2024-02-22. The breach occurred from 1/1/2024 to 1/30/2024. 1 Montana residents were affected.
- 🦬Montana State AGas victim2021-10-26
Walmart reported a data breach to the Montana Attorney General. The breach was reported on 2021-10-26. The breach occurred on 9/14/2021. 1 Montana residents were affected.
- ARHHS OCRas victim2021-06-18
Walmart Inc. reported to HHS on 2021-06-18 a Loss affecting 14,532 individuals. Breached information located on Paper/Films. The incident involved the loss of documents containing PHI (names, DOB, addresses, diagnoses, treatment info). The entity implemented additional safeguards and retrained staff on records management.
- 💎Delaware State AGas victim2021-03-05
Walmart Inc. issued a Delaware state AG breach notification regarding a third-party data hosting service compromise. An unauthorized party accessed records on January 20, 2021, and Walmart was notified on February 16, 2021. Walmart's own systems were not affected. Affected data included names, addresses, DOB, phone numbers, and prescription/medication details. Walmart offered one year of identity monitoring services.
- 💎Delaware State AGas victim2021-03-05
Walmart notified Delaware AG of a breach affecting customer data via a supplier's compromised data hosting service. Unauthorized access occurred Jan 20, 2021; Walmart notified Feb 16, 2021. Data included names, DOB, addresses, and prescription details. Walmart's systems were not directly affected. One year of identity monitoring offered.
- ARHHS OCRas victim2021-03-05
Walmart Inc. reported to HHS on 2021-03-05 a Hacking/IT Incident affecting 2,071 individuals. Breached information located on Network Server. The breach involved a business associate compromising PHI (names, addresses, DOB, phone, medication, insurance info).
- ARHHS OCRas victim2020-02-12
Walmart Inc. reported to HHS on 2020-02-12 a Loss affecting 3,606 individuals. Breached information located on Paper/Films. The incident involved missing pharmacy prescription records containing PHI (names, addresses, phone numbers, DOB, medications). Walmart notified HHS, individuals, and media, and implemented new administrative safeguards and staff retraining.
- ARHHS OCRas victim2019-10-17
Walmart Inc. reported to HHS on 2019-10-17 a Loss affecting 4211 individuals. Breached information located on Other Portable Electronic Device. A missing flash drive contained ePHI including names, addresses, dates of birth, and medical images. The entity notified HHS, individuals, and media, provided credit monitoring, sanctioned the employee, and retrained staff.
- 🦬Montana State AGas victim2019-10-17
Walmart reported a data breach to the Montana Attorney General. The breach was reported on 2019-10-17. The breach occurred on 9/10/2019. 1 Montana residents were affected.
- ARHHS OCRas victim2019-08-09
Walmart Inc. reported to HHS on 2019-08-09 a Loss affecting 4,738 individuals. Breached information located on Paper/Films. The incident involved missing pharmacy prescription records containing PHI (names, addresses, phone numbers, DOB, medication info). The entity implemented additional safeguards and retrained employees.
- ARHHS OCRas victim2019-07-26
Walmart Inc. reported to HHS on 2019-07-26 a Loss affecting 3,135 individuals. Breached information located on Paper/Films. The incident involved missing pharmacy prescription records containing names, addresses, phone numbers, dates of birth, and medication information. The entity implemented additional safeguards and retrained staff.
- ARHHS OCRas victim2018-03-26
Walmart Inc. reported to HHS on 2018-03-26 a Unauthorized Access/Disclosure affecting 741 individuals. Breached information located on Email, Other. A system error caused patient information (names and prescription data) to be viewed by the wrong patient via the CE's app or email. The CE provided breach notification to HHS, affected individuals, and the media, and implemented improved technical safeguards.
- ARHHS OCRas victim2018-02-22
Walmart, Inc. (AR) reported to HHS on 2018-02-22 an Unauthorized Access/Disclosure affecting 735 individuals. An internal programming error in pharmacy account profiles caused ePHI — including names, contact information, dates of birth, insurance card holder numbers, and prescription history — to be viewable by other patients or their authorized representatives via the online pharmacy portal or record requests. Breached information located in Electronic Medical Records. OCR investigation concluded with CE implementing improved administrative safeguards and quality assurance protocols.
- 🦬Montana State AGas victim2018-02-22
Walmart, Inc. reported a data breach to the Montana Attorney General. The breach was reported on 2018-02-22. The breach occurred on 1/29/2018. 5 Montana residents were affected.
- ARHHS OCRas victim2016-11-04
Wal-Mart Stores, Inc. reported to HHS on 2016-11-04 an Unauthorized Access/Disclosure affecting 771 individuals. Breached information was located on Paper/Films. An internal file merging process error caused letters and refund checks to be sent to wrong recipients. PHI involved included patient names, store locations, optical order numbers, dates of orders, and refund amounts. The CE implemented improved administrative safeguards, quality assurance protocols, and staff retraining. OCR obtained assurances of corrective action.
- FEDERALHHS OCRas victim2016-06-08
Wal-Mart Stores, Inc. reported to HHS on June 8, 2016, an incident of unauthorized disclosure affecting 27,393 individuals. The breach occurred when its business associate, Harte-Hanks Direct Marketing/Kansas City, LLC, erroneously mailed refund checks, exposing protected health information including names, store locations, refund amounts, and prescription or order numbers. The breached information was in paper form. OCR opened an investigation into the matter.
- ARHHS OCRas victim2016-03-01
Walmart Stores, Inc. (AR, Healthcare Provider) reported to HHS OCR on 2016-03-01 an Unauthorized Access/Disclosure affecting 4,800 individuals. A software change caused a technical error that made ePHI viewable on Walmart's online pharmacy account portal. Exposed data included names, addresses, phone numbers, email addresses, prescriptions, insurance information, treatment information, and last four digits of credit card numbers. Breached information located on Electronic Medical Record. Walmart notified affected individuals, offered identity theft protection, and implemented additional privacy and security measures.
- 🦬Montana State AGas victim2016-03-01
Wal-Mart Stores, Inc. reported a data breach to the Montana Attorney General. The breach was reported on 2016-03-01. The breach occurred from 2/15/2016 to 2/18/2016. 29 Montana residents were affected.