Walgreen Co.
ent_019e0ba36f06d92da728dcdcbbcc51c4
Disclosures
16
HHS OCR · State AG · 3 jurisdictions
Multi-filing incidents
1
incidents joining 2+ filings here
Max affected reported
160,000
as filed · HHS OCR FEDERAL
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- Walgreen Co.
- Normalized
- walgreen— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- 549300OVVD7Z46FDMX80
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- walgreens.com
- Corporate parent
- Walgreens Boots Alliance, Inc.— per SEC Exhibit 21 filing
Disclosure history (16)newest first
- ILHHS OCRas victim2024-10-01
Walgreen Co. (IL) reported to HHS OCR on 2024-10-01 an Unauthorized Access/Disclosure affecting 1,915 individuals. A workforce member allowed two unauthorized individuals to access patients' PHI, including demographic and clinical information, stored on a laptop. In response, the CE revised its policies, implemented additional technical safeguards, sanctioned the workforce member, and retrained its workforce.
- FEDERALHHS OCRas victim2022-08-31
Walgreen Co. reported to HHS on 2022-08-31 that one of its pharmacies was burglarized and a box containing paper records with the protected health information (PHI) of 1,704 individuals was stolen. The PHI involved included names, addresses, dates of birth, claims information, medications, and health plan information.
- ILHHS OCRas victim2021-12-27
Walgreen Co. (IL) reported to HHS OCR on 2021-12-27 a Loss affecting 1,352 individuals. A box of prescription records containing PHI was damaged and potentially exposed. PHI involved included names, addresses, dates of birth, diagnoses, medications, and other treatment information. Located on Paper/Films. The CE notified HHS, affected individuals, the media, provided substitute notice, and implemented additional administrative safeguards.
- ILHHS OCRas victim2021-01-08
Walgreen Company reported to HHS on 2021-01-08 a Unauthorized Access/Disclosure affecting 16,089 individuals. Breached information located on Email. The incident involved impermissible disclosure of PHI including names, addresses, medications, and financial/treatment data. The entity notified HHS, individuals, and media, and implemented additional technical safeguards.
- 🐻California State AGas victim2020-07-24
Walgreen Co. reported a physical theft incident occurring between May 26 and June 5, 2020, where intruders broke into multiple California Walgreens stores, stealing pharmacy records, hard drives, and automation devices. The breach compromised customer PII (names, addresses, DOB, driver's licenses) and PHI (prescriptions, clinical info). Walgreens notified affected individuals, coordinated with law enforcement, and offered one year of Experian IdentityWorks monitoring.
- ILHHS OCRas victim2020-02-28
Walgreen Company reported to HHS on 2020-02-28 a Unauthorized Access/Disclosure affecting 6681 individuals. Breached information located on Network Server. An error in its database allowed the protected health information (PHI) of 6,681 individuals to be viewed by others. The PHI involved included names, addresses, medications, health insurance information, and financial information.
- 🐻California State AGas victim2020-02-28
Walgreen Co. disclosed a January 2020 incident where an internal application error in its mobile app allowed customers to view other customers' secure messages. Affected data included names, prescription numbers, drug names, store numbers, and shipping addresses. No financial or SSN data was involved. Walgreens disabled the feature and implemented a technical correction.
- 🐻California State AGas victim2018-06-19
Walgreen Co. notified the California AG of a physical skimming incident at two Walgreens-owned Rite Aid locations in Nashville, TN. Unauthorized skimming devices were attached to POS pin pads between Dec 20, 2017, and Apr 17, 2018. Potential data exposure includes credit/debit card numbers, PINs, and customer names. No fraud was confirmed. Walgreens disabled devices, notified law enforcement, and offered credit monitoring.
- ILHHS OCRas victim2018-04-27
Walgreen Co. reported to HHS on 2018-04-27 a Theft affecting 703 individuals. Breached information located on Paper/Films. A Nashville, Tennessee pharmacy was burglarized, resulting in the theft of PHI including names, addresses, DOBs, SSNs, medications, and insurance info. Walgreens notified HHS, individuals, media, and law enforcement, provided credit monitoring, and implemented safeguards.
- ILHHS OCRas victim2017-02-03
Walgreen Co. reported to HHS on 2017-02-03 a Unauthorized Access/Disclosure affecting 4500 individuals. Breached information located on Paper/Films. The covered entity sent improperly formatted survey letters where PHI was visible in the envelope's addressee window, exposing prescription histories, clinical, and demographic data. The entity investigated, revised quality control steps, retrained staff, notified HHS and individuals, and posted a substitute notice on its website.
- ILHHS OCRas victim2016-03-04
Walgreen Co. reported to HHS on 2016-03-04 a Theft affecting 880 individuals. Breached information located on Paper/Films. The incident involved the theft of prescription records containing names, DOBs, addresses, and medication data from a New York store.
- ILHHS OCRas victim2015-08-07
Walgreen Co. reported to HHS on 2015-08-07 a Unauthorized Access/Disclosure affecting 8345 individuals. Breached information located on Paper/Films. A vendor mailed lawsuit settlement postcards containing PHI and addresses, which were viewable during the postal route.
- ILHHS OCRas victim2015-05-01
Walgreen Co. reported to HHS on 2015-05-01 a Loss affecting 1138 individuals. Breached information located on Paper/Films. The breach involved missing pharmacy paper logs containing patient PHI (names, DOB, addresses, prescription numbers) from a Stafford, Texas location.
- FEDERALHHS OCRas victim2014-12-15
The covered entity (CE), Walgreens, mailed patient notification letters to incorrect third parties. The letters included first and last names, addresses, dates of birth, phone numbers, provider names, and details of the vaccines administered and affected approximately 160,000 individuals. The CE provided breach notification to HHS, affected individuals, and the media, and placed notice on its website. Following the breach, the CE resolved issues in its use of the electronic health record (EHR) that were factors in the breach, updated data in the prescriber database and trained its staff on the new requirements. As a result of OCR’s investigation, Walgreens improved safeguards by resolving two issues in its use of the EHR.
- ILHHS OCRas victim2013-12-06
Walgreen Co. reported to HHS on 2013-12-06 a breach of type 'Other' affecting 17,350 individuals. Breached information was located on Paper/Films. No business associate was involved.
- ILHHS OCRas victim2012-07-30
Walgreen Co. (IL) reported to HHS OCR on 2012-07-30 a Theft breach affecting 1,240 individuals. Breached information was located on Paper/Films. No business associate was involved. No further detail was provided in the web description.