CVS HEALTH CORPORATION
ent_019e0d7de0fee734cea4e30bd64a769a
Disclosures
8
SEC 10-K Item 1C · State AG · HHS OCR · 3 jurisdictions
Incidents
—
no linked incident in sample
Max affected reported
12,914
nationwide · HHS OCR RI
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- CVS HEALTH CORPORATION
- Normalized
- cvs health— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- 549300EJG376EN5NQE29
- SEC EDGAR CIK
- 0000064803
- Domain
- cvshealth.com
Disclosure history (8)newest first
- FEDERALSEC 10-K Item 1Cas victim2026-02-10
Item 1C of a 10-K filing describing the registrant's cybersecurity risk management and governance. The company states it did not experience a material cybersecurity incident during the year ended December 31, 2025. The filing details the company's information security program, incident response plan, and board oversight of cybersecurity risks.
- 🦞Maine State AGas victim2024-04-08
CVS reported an internal system breach that occurred on January 1, 2023, and was discovered on January 5, 2023. The breach affected 10 Maine residents. Affected individuals were notified electronically on January 10, 2023, and offered identity theft protection services.
- RIHHS OCRas victim2021-06-28
CVS Caremark reported to HHS on 2021-06-28 a Unauthorized Access/Disclosure affecting 3064 individuals. Breached information located on Paper/Films. An employee mailed ePHI (names, diagnoses, health insurance) to wrong recipients. The CE retrained staff and implemented administrative safeguards.
- FEDERALHHS OCRas victim2017-03-08
CVS Health reported to HHS on 2017-03-08 a theft affecting 724 individuals. On January 11, 2017, a box of hard copy prescriptions was stolen from a CVS location in Indiana. The stolen information included patient names, dates of birth, addresses, and prescription details. In response, CVS retrained staff and conducted an internal audit to improve record security.
- RIHHS OCRas victim2016-12-05
CVS Health reported to HHS on 2016-12-05 a Theft affecting 626 individuals. Breached information located on Paper/Films. An individual broke into a CVS Pharmacy in Whiteville, NC during Hurricane Matthew and stole 626 individuals' completed prescriptions containing PHI.
- RIHHS OCRas victim2015-06-26
CVS Health reported to HHS on 2015-06-26 a Theft affecting 12,914 individuals. Breached information located on Desktop Computer. The covered entity's store in Baltimore, Maryland was looted and computers containing ePHI (names, partial DOB, addresses, medication names/dosage, prescription numbers) were stolen. Affected individuals received 1 year of free credit monitoring.
- FEDERALHHS OCRas victim2013-07-02
CVS Caremark reported to HHS on 2013-07-02 a data breach affecting 4,305 individuals. The business associate for Northrop Grumman Retiree Health Plan erroneously sent paper documents containing members' names and prescribed medications to other members. In response, the company revised its quality control policies and retrained employees.
- RIHHS OCRas victim2012-10-26
CVS Caremark reported to HHS on 2012-10-26 a Theft affecting 955 individuals. Breached information located on Paper/Films.
Subsidiary disclosures (newest 10)filed by group companies
◈ These filings were made by or about subsidiaries of CVS HEALTH CORPORATION — not by CVS HEALTH CORPORATION itself. Corporate relationships are mapped from GLEIF relationship records and SEC Exhibit 21 filings.
- CTHHS OCRvia AETNA INC.2026-02-27
Aetna (Business Associate, CT) reported to HHS OCR on 2026-02-27 an Unauthorized Access/Disclosure affecting 10,888 individuals. Breached information was located on Paper/Films. A business associate was present. No further description was provided.
- CTHHS OCRvia AETNA INC.2026-02-27
Aetna reported to HHS on 2026-02-27 a Unauthorized Access/Disclosure affecting 775 individuals. Breached information located on Paper/Films.
- 🦞Maine State AGvia AETNA LIFE INSURANCE COMPANY2023-12-01
Aetna Life Insurance Company reported a cybersecurity incident occurring on May 29, 2023, discovered on June 6, 2023. The breach involved unauthorized access via a software vulnerability in an external system. Approximately 310,019 individuals were affected, including 1,017 Maine residents. The incident compromised names and Social Security Numbers. Aetna notified affected individuals in writing starting September 14, 2023, and offered 12 months of credit monitoring and identity restoration services through Kroll.
- 💎Delaware State AGvia AETNA LIFE INSURANCE COMPANY2023-09-14
Pension Benefit Information, LLC (PBI) disclosed a data breach involving MOVEit Transfer software exploited by an unauthorized third party on May 29-30, 2023. The incident affected data belonging to clients, including Aetna Life Insurance. PBI patched servers, investigated, and offered 12 months of credit monitoring. Data potentially exposed included names and government identifiers.
- 🦞Maine State AGvia AETNA LIFE INSURANCE COMPANY2023-09-12
Aetna Life Insurance Company reported a data breach affecting 970 Maine residents. The breach was discovered on June 6, 2023, and occurred on May 29, 2023. The incident was an external system breach due to a software vulnerability, resulting in the compromise of names and Social Security numbers. Aetna offered 12 months of credit monitoring and identity restoration services to affected individuals.
- 🌲Washington State AGvia AETNA LIFE INSURANCE COMPANY2023-09-08
Aetna Life Insurance Company, a health sector entity reported a ransomware incident to the Washington Attorney General. The organization became aware of the incident on 2023-06-06 and filed notice on 2023-09-08. 2,303 Washington residents were affected. 94 days elapsed between awareness and notification. 8 days to identify the breach. 116 days to contain the breach.
- 🦬Montana State AGvia AETNA LIFE INSURANCE COMPANY2023-09-07
Aetna Life Insurance Company reported a data breach to the Montana Attorney General. The breach was reported on 2023-09-07. The breach occurred from 5/29/2023 to 5/30/2023. 831 Montana residents were affected.
- CTHHS OCRvia AETNA INC.2022-12-27
Aetna ACE (CT, Health Plan) reported to HHS on 2022-12-27 a Hacking/IT Incident affecting 4,222 individuals. Several employees were the subjects of an email phishing scheme. PHI exposed included names, medications, diagnoses, and health insurance and other treatment information. Breached information was located in Email. The CE notified HHS, affected individuals, and the media, and implemented additional technical and security safeguards; staff were retrained on email security.
- 🐻California State AGvia AETNA INC.2022-07-27
Aetna, via its vendor OneTouchPoint, Inc. (OTP), disclosed a ransomware incident discovered on April 28, 2022. Unauthorized access to OTP servers began April 27, 2022, resulting in encrypted files. OTP engaged forensic specialists and law enforcement. Customer data, including names and specific data elements, was present on impacted servers; Social Security numbers were not affected. Notification was sent to affected individuals starting June 3, 2022. No evidence of misuse was found.
- CTHHS OCRvia AETNA INC.2022-02-15
Aetna ACE (Health Plan, CT) reported to HHS on 2022-02-15 a Hacking/IT Incident affecting 893 individuals. The breach occurred at a business associate and impacted PHI including names, dates of birth, addresses, claims information, diagnoses, lab results, medications, and other treatment information. Breached information located on Network Server. The CE notified HHS, affected individuals, and media, and implemented additional technical safeguards, credit monitoring, and employee retraining.