Rite Aid Corporation
ent_019dea5daf2cb05a914c7585fcf3b376
Disclosures
23
State AG · Leak Site · HHS OCR · 14 jurisdictions
Incidents
3
filings grouped by incident
Max affected reported
2,200,000
as filed · State AG OR
Leak-site claims
3
unverified actor claims
Identity resolution
- Canonical name
- Rite Aid Corporation
- Normalized
- rite aid— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- 529900W353T1JY1DKT44
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- riteaid.com
Disclosure history (23)newest first
- 🦬Montana State AGas victim2024-07-15
Rite Aid Corporation reported a data breach to the Montana Attorney General. The breach was reported on 2024-07-15. The breach occurred on 6/6/2024. 619 Montana residents were affected.
- 🐻California State AGas victim2024-07-15
Rite Aid Corporation reported that on June 6, 2024, an unknown third party impersonated an employee to compromise business credentials and access systems. The attacker acquired purchaser data (name, address, DOB, driver's license/government ID) for transactions between June 6, 2017, and July 30, 2018. No SSN, financial, or patient data was impacted. Rite Aid detected the incident within 12 hours, terminated access, and is offering identity monitoring via Kroll.
- 🦫Oregon State AGas victim2024-07-15
Rite Aid Corporation reported a data breach to the Oregon Attorney General. The breach was reported on 2024-07-15. The breach occurred during 6/6/2024 - 6/6/2024. The breach was discovered on 6/6/2024. 2,200,000 individuals were affected. Notice was sent on 7/15/2024.
- 🍁Vermont State AGas victim2024-07-15
Rite Aid notified consumers in Vermont of a data breach where an unknown third party compromised business credentials by impersonating an employee. The incident, occurring between June 2017 and July 2018, exposed names, addresses, dates of birth, and driver's license numbers. Rite Aid reported the incident to law enforcement and regulators, engaged Kroll for identity monitoring services, and implemented additional security measures.
- 🌲Washington State AGas victim2024-07-15
Rite Aid Corporation, a health sector entity reported a phishing incident to the Washington Attorney General. The organization became aware of the incident on 2024-06-06 and filed notice on 2024-07-15. 96,270 Washington residents were affected. 39 days elapsed between awareness and notification. 0 days to identify the breach. 0 days to contain the breach.
- 🏎️Indiana State AGas victim2024-07-15
Rite Aid Corporation reported a data breach to the Indiana Attorney General. The breach occurred on 2024-06-06 and was reported on 2024-07-15. 6,923 Indiana residents were affected. 2,200,000 individuals affected in total.
- 💎Delaware State AGas victim2024-07-15
Rite Aid Corporation disclosed a data breach where an unknown third party used phishing to steal business credentials and access systems. Data from purchases between June 2017 and July 2018 was compromised, including names, addresses, DOBs, and driver's licenses. No SSNs or financial data were impacted. Rite Aid reported to law enforcement and offered Kroll identity monitoring.
- ⛰️New Hampshire State AGas victim2024-07-15
Rite Aid Corporation notified New Hampshire and nationwide residents of a security incident where an unknown third party impersonated an employee to compromise business credentials and access systems on June 6, 2024. The breach affected approximately 2.2 million individuals nationwide, including 36,121 New Hampshire residents. Purchaser data associated with retail product purchases was acquired. Rite Aid detected the incident within 12 hours, terminated access, and engaged Kroll for identity monitoring services.
- 🦞Maine State AGas victim2024-07-15
On June 6, 2024, an unknown actor impersonated a Rite Aid employee to compromise credentials and access business systems. Detection occurred within 12 hours. By June 17, data from purchases (Jun 2017–Jul 2018) was confirmed exfiltrated: name, address, DOB, driver's license/gov-ID. No SSNs, financial, or patient data affected. ~2.2M individuals nationally; 30,137 Maine residents. Kroll monitoring (12 mo.) offered.
- GLOBALLeak Siteas victim2024-07-11
- 🌲Washington State AGas victim2023-07-19
Rite Aid Corporation, a health sector entity reported a other incident to the Washington Attorney General. The organization became aware of the incident on 2023-05-31 and filed notice on 2023-07-19. 1,409 Washington residents were affected. 49 days elapsed between awareness and notification. 4 days to identify the breach. 0 days to contain the breach.
- PAHHS OCRas victim2023-07-19
Rite Aid Corporation reported to HHS on 2023-07-19 a Hacking/IT Incident affecting 23,433 individuals. Breached information located on Network Server. The cyber-attack compromised PHI including names, dates of birth, addresses, medications, and health insurance information. The entity notified HHS, affected individuals, and the media, installed software patches, and implemented technical safeguards.
- 🐻California State AGas victim2023-07-19
Rite Aid Corporation disclosed a data breach involving a vulnerability in a vendor partner's software exploited by an unknown third party. The incident occurred on May 27, 2023, and was discovered on May 31, 2023. Affected data included limited protected health information (names, DOB, addresses, prescription info) but no SSNs or financial data. Rite Aid installed a patch, notified regulators/law enforcement, and offered one year of identity monitoring via Kroll.
- GLOBALLeak Siteas victim2023-07-11
Online Pharmacy and Store - Rite Aid
- GLOBALLeak Siteas victim2021-01-02
riteaid.com
- 🐻California State AGas victim2018-10-01
Rite Aid Corporation disclosed that due to a programming update on August 30, 2018, Rite Aid associates were inadvertently included in a standard eligibility file sent to Empower Retirement, a vendor for Walgreens. The exposed data included names, contact information, Social Security numbers, and benefits-related information. Rite Aid worked with Empower to confirm no misuse occurred and offered one year of identity monitoring services to affected associates.
- NEW YORKHHS OCRas victim2016-02-03
Rite Aid Pharmacy Store 01617 (NY) reported to HHS on 2016-02-03 an Unauthorized Access/Disclosure affecting 976 individuals. From November 19, 2014 through November 18, 2015, an internal employee obtained customers' credit card information and other personal identifiers from Desktop Computer and other systems, using them to commit credit card fraud. ePHI involved included names, addresses, dates of birth, and credit card data. The employee was terminated; card handling policies were revised; OCR provided technical assistance on HIPAA Security Rule compliance. Breached info located on Desktop Computer, Other.
- 🌲Washington State AGas victim2015-09-29
Rite Aid Corporation, a business sector entity reported a unauthorized access incident to the Washington Attorney General. 2,721 Washington residents were affected.
- 🐻California State AGas victim2015-09-22
Rite Aid Corporation reported a data security incident involving its third-party service provider, PNI Digital Media, which hosts the mywayphotos.riteaid.com platform. Malware on PNI's servers allowed unauthorized access to customer data between August 20, 2014, and July 14, 2015. Compromised data included names, addresses, phone numbers, email addresses, and payment card information (including card numbers, security codes, and expiration dates). Rite Aid shut down the affected online and mobile photo services and provided one year of complimentary credit monitoring and identity theft protection through Kroll to affected individuals.
- MARYLANDHHS OCRas victim2015-06-03
On April 27, 2015, rioters in Baltimore, MD broke into, vandalized, and looted eight Rite Aid locations, taking 2,345 filled 'will-call' prescriptions. The stolen prescriptions contained patients' names, addresses, and medication names. Rite Aid reported the breach to HHS on June 3, 2015, and notified affected individuals and the media, offering credit monitoring. All vandalized locations except one that was burned were re-opened with full security restored. OCR obtained assurances of corrective action. Breached information located on Other/Paper-Films.
- WASHINGTONHHS OCRas victim2014-07-30
Rite Aid Store 5256 (Milton, WA) reported to HHS on 2014-07-30 a theft affecting 522 individuals. A box of paper prescription records was removed from the backroom, exposing names, addresses, and dates of birth. Breached information located on Paper/Films. OCR investigated and provided technical assistance. The CE improved physical safeguards and clarified PHI storage policies.
- FEDERALHHS OCRas victim2012-05-10
Rite Aid Store 1343 reported to HHS on 2012-05-10 a Theft affecting 2905 individuals. The breach involved the theft of hard copy prescriptions from a storage building, which contained patient names and prescription details. The breached information was located on Paper/Films. In response, the entity secured remaining records, improved physical security, notified relevant parties, and offered identity theft protection to those affected.
- PAHHS OCRas victim2011-12-07
Rite Aid Corporation (PA) reported to HHS OCR on 2011-12-07 a breach classified as 'Other' affecting 2,900 individuals. Breached information was located on Paper/Films. No business associate was involved. No further detail is available from the web description.