CVS Pharmacy, Inc.
ent_019e0c38fb0e2c8ec07385573e6a7ca6
Disclosures
5
State AG · HHS OCR · 2 jurisdictions
Incidents
—
no linked incident in sample
Max affected reported
26,234
nationwide · HHS OCR RI
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- CVS Pharmacy, Inc.
- Normalized
- cvs pharmacy— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- 9845006FF4C40R05B003
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- cvs.com
- Corporate parent
- CVS HEALTH CORPORATION— per GLEIF relationship records
Disclosure history (5)newest first
- 🐻California State AGas victim2022-02-11
CVS Pharmacy disclosed a security incident involving password spraying attacks against customer accounts on CVS.com. The attack occurred between January 6, 2022, and January 25, 2022. The incident resulted in the unauthorized access of customer names, dates of birth, mailing addresses, email addresses, and limited prescription information. No financial or Social Security numbers were compromised. CVS reset passwords for affected accounts and implemented additional website security measures.
- RIHHS OCRas victim2021-09-10
CVS Pharmacy reported to HHS on 2021-09-10 a Theft affecting 826 individuals. Breached information located on Paper/Films. A former employee possessed prescription records containing PHI (names, addresses, DOB, medication info). The entity notified HHS and individuals, established a help line, updated policies, and retrained staff.
- RIHHS OCRas victim2020-07-24
CVS Pharmacy reported to HHS on 2020-07-24 a Loss affecting 26,234 individuals. Breached information located on Paper/Films. The incident involved vandalism at CVS stores resulting in the tampering or removal of Protected Health Information (PHI), including names, addresses, dates of birth, and clinical medication data. CVS implemented additional safeguards and provided substitute notes to affected individuals.
- RIHHS OCRas victim2019-01-30
CVS Pharmacy (RI) reported to HHS OCR on 2019-01-30 a Theft breach affecting 5,645 individuals. PHI was erroneously placed in a storage container maintained by business associate Target Corporation; the container was subsequently vandalized and the PHI stolen. Breached information was in Paper/Films form and included names, addresses, dates of birth, and prescription information. CVS notified OCR, affected individuals, and the media.
- 🐻California State AGas victim2015-09-11
CVS Pharmacy, Inc. disclosed a breach affecting its CVSPhoto.com website, managed by third-party vendor PNI Digital Media. The incident occurred between June 19, 2014, and July 14, 2015, involving unauthorized access to PNI's systems. Affected data included names, payment card numbers, expiration dates, CVVs, addresses, phone numbers, emails, and login credentials. CVS disabled the site, engaged forensic investigators, and provided one year of free credit monitoring via Experian to affected customers.