Rite Aid Corporation
ent_019dea5daf2cb05a914c7585fcf3b376
Disclosures
24
State AG · Leak Site · HHS OCR · 15 jurisdictions
Multi-filing incidents
5
incidents joining 2+ filings here
Max affected reported
2,200,000
nationwide · State AG OR
Leak-site claims
3
unverified actor claims
Identity resolution
- Canonical name
- Rite Aid Corporation
- Normalized
- rite aid— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- 529900W353T1JY1DKT44
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- riteaid.com
Disclosure history (24)newest first
- Montana State AGas victim2024-07-15
Rite Aid Corporation notified Montana residents of a data breach where an unknown third party compromised business credentials between June 2017 and July 2018. The incident exposed names, addresses, DOBs, and driver's license numbers. Rite Aid detected the breach on June 6, 2024, reported it to regulators, and engaged Kroll for identity monitoring services.
- California State AGas victim2024-07-15
Rite Aid Corporation reported that on June 6, 2024, an unknown third party impersonated an employee to compromise business credentials and access systems. The attacker acquired purchaser data (name, address, DOB, driver's license/government ID) for transactions between June 6, 2017, and July 30, 2018. No SSN, financial, or patient data was impacted. Rite Aid detected the incident within 12 hours, terminated access, and is offering identity monitoring via Kroll.
- South Carolina State AGas victim2024-07-15
Rite Aid Corporation notified South Carolina consumers of a data breach where an unknown third party compromised business credentials via impersonation/phishing. Access occurred between June 6, 2017, and July 30, 2018. Data exposed included names, addresses, DOBs, and driver's licenses. No SSNs or financial data were impacted. Kroll identity monitoring was offered.
- Massachusetts State AGas victim2024-07-15
Rite Aid Corporation reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2024-07-15. 59,708 Massachusetts residents were affected.
- Oregon State AGas victim2024-07-15
Rite Aid Corporation reported a data breach to the Oregon Attorney General. The breach was reported on 2024-07-15. The breach occurred during 6/6/2024 - 6/6/2024. The breach was discovered on 6/6/2024. 2,200,000 individuals were affected. Notice was sent on 7/15/2024.
- Vermont State AGas victim2024-07-15
Rite Aid notified consumers in Vermont of a data breach where an unknown third party compromised business credentials by impersonating an employee. The incident, occurring between June 2017 and July 2018, exposed names, addresses, dates of birth, and driver's license numbers. Rite Aid reported the incident to law enforcement and regulators, engaged Kroll for identity monitoring services, and implemented additional security measures.
- Washington State AGas victim2024-07-15
Rite Aid Corporation reported a data breach in Washington affecting 96,270 residents. An unknown third party used phishing to compromise business credentials and access systems. Data exposed included names, addresses, DOBs, and driver's licenses from purchases made between June 2017 and July 2018. The incident was detected on June 6, 2024, and reported to law enforcement and regulators.
- Indiana State AGas victim2024-07-15
Rite Aid Corporation reported a data breach to the Indiana Attorney General. The breach occurred on 2024-06-06 and was reported on 2024-07-15. 6,923 Indiana residents were affected. 2,200,000 individuals affected in total.
- Delaware State AGas victim2024-07-15
Rite Aid Corporation disclosed a data breach where an unknown third party used phishing to steal business credentials and access systems. Data from purchases between June 2017 and July 2018 was compromised, including names, addresses, DOBs, and driver's licenses. No SSNs or financial data were impacted. Rite Aid reported to law enforcement and offered Kroll identity monitoring.
- New Hampshire State AGas victim2024-07-15
Rite Aid Corporation notified the New Hampshire Attorney General of a security incident on June 6, 2024, where an unknown third party impersonated an employee to compromise business credentials and access systems. Approximately 2.2 million individuals nationwide, including 36,121 New Hampshire residents, were affected. Data acquired included purchaser information related to retail product purchases. Rite Aid detected the incident within 12 hours, terminated access, and is offering identity monitoring services.
- Maine State AGas victim2024-07-15
Rite Aid Corporation reported an external system breach on June 6, 2024, where an unknown third party compromised business credentials to access systems. Data acquired included names, addresses, dates of birth, and driver's license numbers for purchases made between June 2017 and July 2018. Approximately 2.2 million individuals were affected, including 30,137 Maine residents. Rite Aid notified affected individuals on July 15, 2024, and offered 12 months of identity monitoring through Kroll.
- GLOBALLeak Siteas victim2024-07-11
- Illinois State AGas victim2024-07-01
RITE AID CORPORATION filed a data-breach notice with the Illinois Attorney General in July 2024 (case 24-07-017). The register records the breach as discovered on June 6, 2024. Illinois does not publish the number of people affected — 815 ILCS 530/10 permits the Attorney General to publish only the entity name, the types of personal information and the date range.
- Massachusetts State AGas victim2023-07-19
Rite Aid Corporation reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2023-07-19. 238 Massachusetts residents were affected. The report records the breach type as electronic.
- Washington State AGas victim2023-07-19
Rite Aid Corporation reported a data breach in Washington affecting 1,409 residents. An unknown third party exploited a vulnerability in a vendor's software between May 27 and May 31, 2023. The incident exposed PHI including names, DOBs, addresses, and prescription details. Rite Aid engaged Kroll for credit monitoring and notified law enforcement.
- PENNSYLVANIAHHS OCRas victim2023-07-19
Rite Aid Corporation reported to HHS on 2023-07-19 a Hacking/IT Incident affecting 23,433 individuals. Breached information located on Network Server. The cyber-attack compromised PHI including names, dates of birth, addresses, medications, and health insurance information. The entity notified HHS, affected individuals, and the media, installed software patches, and implemented technical safeguards.
- California State AGas victim2023-07-19
Rite Aid Corporation disclosed a data breach involving a vulnerability in a vendor partner's software exploited by an unknown third party. The incident occurred on May 27, 2023, and was discovered on May 31, 2023. Affected data included limited protected health information (names, DOB, addresses, prescription info) but no SSNs or financial data. Rite Aid installed a patch, notified regulators/law enforcement, and offered one year of identity monitoring via Kroll.
- GLOBALLeak Siteas victim2023-07-11
Online Pharmacy and Store - Rite Aid
- GLOBALLeak Siteas victim2021-01-02
riteaid.com
- PENNSYLVANIAHHS OCRas victim2020-07-29
Rite Aid Corporation reported to HHS on 2020-07-29 a Theft affecting 13,600 individuals. Breached information located on Paper/Films. Documents containing PHI (names, addresses, birthdates, prescription info) were stolen during looting due to civil unrest.
- California State AGas victim2018-10-01
Rite Aid Corporation disclosed that due to a programming update on August 30, 2018, Rite Aid associates were inadvertently included in a standard eligibility file sent to Empower Retirement, a vendor for Walgreens. The exposed data included names, contact information, Social Security numbers, and benefits-related information. Rite Aid worked with Empower to confirm no misuse occurred and offered one year of identity monitoring services to affected associates.
- Massachusetts State AGas victim2018-10-01
Rite Aid Corporation reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2018-10-01. 214 Massachusetts residents were affected. The report records the breach type as electronic.
- Massachusetts State AGas victim2016-02-09
Rite Aid Corporation reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2016-02-09. 3 Massachusetts residents were affected. The report records the breach type as electronic.
- NEW YORKHHS OCRas victim2016-02-03
Rite Aid Pharmacy Store 01617 (NY) reported to HHS on 2016-02-03 an Unauthorized Access/Disclosure affecting 976 individuals. From November 19, 2014 through November 18, 2015, an internal employee obtained customers' credit card information and other personal identifiers from Desktop Computer and other systems, using them to commit credit card fraud. ePHI involved included names, addresses, dates of birth, and credit card data. The employee was terminated; card handling policies were revised; OCR provided technical assistance on HIPAA Security Rule compliance. Breached info located on Desktop Computer, Other.