CVS Pharmacy, Inc.
ent_019e0c38fb0e2c8ec07385573e6a7ca6
Disclosures
14
State AG · HHS OCR · HHS OCR enforcement · 6 jurisdictions
Multi-filing incidents
2
incidents joining 2+ filings here
Max affected reported
30,629
as filed · State AG MA
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- CVS Pharmacy, Inc.
- Normalized
- cvs pharmacy— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- 9845006FF4C40R05B003
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- cvs.com
- Corporate parent
- CVS HEALTH CORPORATION— per GLEIF relationship records
Disclosure history (14)newest first
- Massachusetts State AGas victim2026-03-20
CVS Pharmacy reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2026-03-20. 1 Massachusetts residents were affected.
- Massachusetts State AGas victim2024-10-03
CVS Pharmacy reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2024-10-03. 39 Massachusetts residents were affected.
- RHODE ISLANDHHS OCRas victim2024-02-16
CVS Pharmacy, Inc. reported to HHS on 2024-02-16 a Unauthorized Access/Disclosure affecting 1896 individuals. Breached information located on Network Server. An error on its website allowed PHI, including names, addresses, and financial information, to be viewable by others.
- RHODE ISLANDHHS OCRas victim2022-02-11
CVS Pharmacy reported to HHS on 2022-02-11 a Hacking/IT Incident affecting 6221 individuals. Breached information located on Network Server. The PHI involved included names, addresses, dates of birth, medications, and other treatment information.
- California State AGas victim2022-02-11
CVS Pharmacy reported a password spraying incident targeting its retail website (www.CVS.com). Automated attempts used common passwords to acquire valid account credentials. Internal systems were not impacted. Affected data included first name, last name, date of birth, mailing address, email address, and limited prescription information (medication name, last fill date). No SSN or financial data was involved. Passwords for impacted accounts were reset.
- RHODE ISLANDHHS OCRas victim2021-09-10
CVS Pharmacy reported to HHS on 2021-09-10 a Theft affecting 826 individuals. Breached information located on Paper/Films. A former employee possessed prescription records containing PHI (names, addresses, DOB, medication info). The entity notified HHS and individuals, established a help line, updated policies, and retrained staff.
- RHODE ISLANDHHS OCRas victim2020-07-24
CVS Pharmacy reported to HHS on 2020-07-24 a Loss affecting 26,234 individuals. Breached information located on Paper/Films. The incident involved vandalism at CVS stores resulting in the tampering or removal of Protected Health Information (PHI), including names, addresses, dates of birth, and clinical medication data. CVS implemented additional safeguards and provided substitute notes to affected individuals.
- RHODE ISLANDHHS OCRas victim2019-01-30
CVS Pharmacy (RI) reported to HHS OCR on 2019-01-30 a Theft breach affecting 5,645 individuals. PHI was erroneously placed in a storage container maintained by business associate Target Corporation; the container was subsequently vandalized and the PHI stolen. Breached information was in Paper/Films form and included names, addresses, dates of birth, and prescription information. CVS notified OCR, affected individuals, and the media.
- RHODE ISLANDHHS OCRas victim2017-10-13
CVS Pharmacy reported to HHS on 2017-10-13 a Theft affecting 836 individuals. Breached information located on Paper/Films. An individual broke into a CVS Pharmacy in Riverview, Florida during Hurricane Irma and stole completed prescriptions containing PHI including names, DOBs, addresses, and medication names.
- South Carolina State AGas victim2015-09-14
CVS Pharmacy, Inc. disclosed that an illegal intrusion into third-party vendor PNI Digital Media's systems hosting CVSPhoto.com potentially exposed customer data including names, payment card details, and credentials between June 2014 and July 2015. CVS detected unusual activity in July 2015, took the site down, engaged forensic investigators, and offered one year of credit monitoring.
- Massachusetts State AGas victim2015-09-11
CVS Pharmacy Inc. reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2015-09-11. 30,629 Massachusetts residents were affected. The report records the breach type as electronic.
- California State AGas victim2015-09-11
CVS Pharmacy, Inc. disclosed an unauthorized intrusion into the systems of its independent vendor, PNI Digital Media, which hosted the CVSPhoto.com website. The intrusion occurred between June 2014 and July 2015 and potentially resulted in the unauthorized acquisition of payment card numbers, verification codes, names, addresses, phone numbers, email addresses, and usernames/passwords. CVS took down the website, engaged forensic investigators, and offered one year of credit monitoring to affected customers.
- New Hampshire State AGas victim2015-09-10
CVS Pharmacy, Inc. notified the NH Attorney General of a breach at third-party vendor PNI Digital Media affecting CVSPhoto.com. Unauthorized access occurred between June 2014 and July 2015, exposing payment card data, names, and credentials. Approximately 2,493 NH residents were affected. CVS disabled the site, engaged forensic investigators, and provided 12 months of credit monitoring via Experian.
- FEDERALHHS OCR enforcementas victim2009-01-16
HHS OCR settled a HIPAA Privacy Rule case with CVS Pharmacy, Inc. for $2.25 million regarding inadequate disposal of protected health information (prescription labels/prescriptions) in unsecured dumpsters. CVS implemented a Corrective Action Plan including policy revisions, employee training, sanctions, and third-party assessments.