WALMART INC.
ent_019dea4cdcc59179f676e3cd714820c1
Disclosures
25+
State AG · HHS OCR · 8 jurisdictions
Multi-filing incidents
6
incidents joining 2+ filings here
Max affected reported
14,532
nationwide · HHS OCR AR
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- WALMART INC.
- Normalized
- walmart— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- Y87794H0US1R65VBXU25
- SEC EDGAR CIK
- 0000104169
- Domain
- walmart.com
Disclosure history (newest 25)newest first
- Maine State AGas victim2025-01-09
Walmart Inc. reported an insider wrongdoing incident to the Maine AG involving 2 Maine residents. The breach occurred on December 10, 2024, and was discovered on January 3, 2025. Affected individuals were notified in writing on January 10, 2025. Walmart offered 12 months of Experian identity protection and credit monitoring services to affected individuals.
- ARKANSASHHS OCRas victim2024-06-14
Walmart Inc. reported to HHS on 2024-06-14 an Unauthorized Access/Disclosure affecting 1,267 individuals. A technical error made by an employee allowed PHI — including names, dates of birth, and gender — to be viewable via the Internet. Breached information was located on a Network Server. The CE notified HHS, affected individuals, and the media, then implemented additional technical safeguards and retrained its workforce.
- Indiana State AGas victim2024-04-05
Walmart Inc reported a data breach to the Indiana Attorney General. The breach occurred on 2023-09-01 and was reported on 2024-04-05. 9 Indiana residents were affected. 361 individuals affected in total.
- Massachusetts State AGas victim2024-04-05
Walmart Inc. reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2024-04-05. 13 Massachusetts residents were affected.
- New Hampshire State AGas victim2024-02-26
Walmart Inc. notified the NH AG of a late January 2024 incident where an unauthorized party accessed Spark Driver accounts. Affected data included driver verification, tax info, background checks, and credentials. Walmart reset passwords, implemented additional security checks, notified law enforcement, and provided 2 years of Kroll identity monitoring to 1 NH resident.
- Maine State AGas victim2024-02-23
Walmart Inc. identified a data breach resulting from an external system hack. The incident, which occurred between December 2023 and February 2024, compromised the names and Social Security numbers of 204 individuals. Walmart notified the affected parties in February 2024 and offered two years of identity theft and fraud monitoring services.
- Indiana State AGas victim2024-02-23
Walmart Inc reported a data breach to the Indiana Attorney General. The breach occurred on 2023-12-03 and was reported on 2024-02-23. 4 Indiana residents were affected. 204 individuals affected in total.
- Massachusetts State AGas victim2024-02-22
Walmart Inc. reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2024-02-22. 3 Massachusetts residents were affected.
- Montana State AGas victim2024-02-22
Walmart Inc disclosed that in late January 2024, an unauthorized party accessed Spark Driver account profiles. The breach potentially exposed Social Security Numbers, driver's license numbers, dates of birth, names, and contact information. Walmart launched an investigation, reset passwords, implemented additional security checks, notified law enforcement, and provided two years of complimentary identity monitoring via Kroll.
- Massachusetts State AGas victim2022-03-06
Walmart Inc. reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2022-03-06. 3 Massachusetts residents were affected. The report records the breach type as paper.
- Montana State AGas victim2021-10-26
Walmart Store #1071 in Wood River, IL reported a lost laptop containing patient information from its Vision Center on September 14, 2021. The data included names, dates of birth, and visual field test results for individuals who visited between April 2017 and October 2017. Walmart found no evidence of theft or misuse.
- ARKANSASHHS OCRas victim2021-10-26
Walmart, Inc. reported to HHS on 2021-10-26 a Loss affecting 828 individuals. Breached information located on Laptop. The PHI involved included names, dates of birth, and other treatment information.
- ARKANSASHHS OCRas victim2021-06-18
Walmart Inc. reported to HHS on 2021-06-18 a Loss affecting 14,532 individuals. Breached information located on Paper/Films. The incident involved the loss of documents containing PHI (names, DOB, addresses, diagnoses, treatment info). The entity implemented additional safeguards and retrained staff on records management.
- Delaware State AGas victim2021-03-05
Walmart Inc. issued a Delaware state AG breach notification regarding a third-party data hosting service compromise. An unauthorized party accessed records on January 20, 2021, and Walmart was notified on February 16, 2021. Walmart's own systems were not affected. Affected data included names, addresses, DOB, phone numbers, and prescription/medication details. Walmart offered one year of identity monitoring services.
- ARKANSASHHS OCRas victim2021-03-05
Walmart Inc. reported to HHS on 2021-03-05 a Hacking/IT Incident affecting 2,071 individuals. Breached information located on Network Server. The breach involved a business associate compromising PHI (names, addresses, DOB, phone, medication, insurance info).
- Illinois State AGas victim2021-01-01
WALMART filed a data-breach notice with the Illinois Attorney General during 2021 (case 21-430). The register records the breach as discovered on September 14, 2021. Illinois does not publish the number of people affected — 815 ILCS 530/10 permits the Attorney General to publish only the entity name, the types of personal information and the date range.
- ARKANSASHHS OCRas victim2020-11-20
Walmart Inc. reported to HHS on 2020-11-20 a Theft affecting 524 individuals. Breached information located on Paper/Films. Documents containing PHI (names, birthdates, medications) were stolen during a burglary.
- ARKANSASHHS OCRas victim2020-02-12
Walmart Inc. reported to HHS on 2020-02-12 a Loss affecting 3,606 individuals. Breached information located on Paper/Films. The incident involved missing pharmacy prescription records containing PHI (names, addresses, phone numbers, DOB, medications). Walmart notified HHS, individuals, and media, and implemented new administrative safeguards and staff retraining.
- ARKANSASHHS OCRas victim2019-10-17
Walmart Inc. reported to HHS on 2019-10-17 a Loss affecting 4211 individuals. Breached information located on Other Portable Electronic Device. A missing flash drive contained ePHI including names, addresses, dates of birth, and medical images. The entity notified HHS, individuals, and media, provided credit monitoring, sanctioned the employee, and retrained staff.
- Montana State AGas victim2019-10-17
Walmart Store #3404 in Roseville, MN lost a flash drive containing patient PII and biometric data (retina images) from its Vision Center on September 10, 2019. No theft or criminal behavior was indicated. Data included names, DOB, and retina images.
- ARKANSASHHS OCRas victim2019-08-09
Walmart Inc. reported to HHS on 2019-08-09 a Loss affecting 4,738 individuals. Breached information located on Paper/Films. The incident involved missing pharmacy prescription records containing PHI (names, addresses, phone numbers, DOB, medication info). The entity implemented additional safeguards and retrained employees.
- ARKANSASHHS OCRas victim2019-07-26
Walmart Inc. reported to HHS on 2019-07-26 a Loss affecting 3,135 individuals. Breached information located on Paper/Films. The incident involved missing pharmacy prescription records containing names, addresses, phone numbers, dates of birth, and medication information. The entity implemented additional safeguards and retrained staff.
- ARKANSASHHS OCRas victim2018-03-26
Walmart Inc. reported to HHS on 2018-03-26 a Unauthorized Access/Disclosure affecting 741 individuals. Breached information located on Email, Other. A system error caused patient information (names and prescription data) to be viewed by the wrong patient via the CE's app or email. The CE provided breach notification to HHS, affected individuals, and the media, and implemented improved technical safeguards.
- ARKANSASHHS OCRas victim2018-02-22
Walmart, Inc. (AR) reported to HHS on 2018-02-22 an Unauthorized Access/Disclosure affecting 735 individuals. An internal programming error in pharmacy account profiles caused ePHI — including names, contact information, dates of birth, insurance card holder numbers, and prescription history — to be viewable by other patients or their authorized representatives via the online pharmacy portal or record requests. Breached information located in Electronic Medical Records. OCR investigation concluded with CE implementing improved administrative safeguards and quality assurance protocols.
- Montana State AGas victim2018-02-22
Walmart Stores, Inc. notified Montana residents of a data breach affecting pharmacy account profiles. An internal error on January 29, 2018, potentially exposed patient names, contact info, DOB, insurance details, and prescription history to other patients. No SSNs or payment card data were involved. Walmart addressed the error and provided 12 months of identity protection services.