CVS HEALTH CORPORATION
ent_019e0d7de0fee734cea4e30bd64a769a
Disclosures
8
State AG · HHS OCR · 4 jurisdictions
Multi-filing incidents
—
no multi-filing incident in sample
Max affected reported
12,914
nationwide · HHS OCR RI
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- CVS HEALTH CORPORATION
- Normalized
- cvs health— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- 549300EJG376EN5NQE29
- SEC EDGAR CIK
- 0000064803
- Domain
- cvshealth.com
Disclosure history (8)newest first
- Maine State AGas victim2024-04-08
CVS reported an internal system breach that occurred on January 1, 2023, and was discovered on January 5, 2023. The breach affected 10 Maine residents. Affected individuals were notified electronically on January 10, 2023, and offered identity theft protection services.
- New Hampshire State AGas victim2019-09-03
TALX Corporation, a subsidiary of Equifax, provided a supplemental notification to the New Hampshire Attorney General regarding a security incident affecting CVS Health employees. On July 8, 2019, TALX discovered that an unauthorized individual accessed the account of one NH resident, potentially viewing their 2015 W-2 form. The access occurred on December 10, 2016, via Knowledge-Based Authentication (KBA) bypass. TALX has implemented MFA and fraud prevention tools.
- Massachusetts State AGas victim2018-09-06
CVS Health reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2018-09-06. 3 Massachusetts residents were affected. The report records the breach type as electronic.
- Massachusetts State AGas victim2018-02-27
CVS Health reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2018-02-27. 6 Massachusetts residents were affected. The report records the breach type as paper.
- RHODE ISLANDHHS OCRas victim2017-03-08
CVS Health reported to HHS on 2017-03-08 a theft affecting 724 individuals. On January 11, 2017, a box of hard copy prescriptions was stolen from a CVS location in Indiana. The stolen information included patient names, dates of birth, addresses, and prescription details. In response, CVS retrained staff and conducted an internal audit to improve record security.
- RHODE ISLANDHHS OCRas victim2016-12-05
CVS Health reported to HHS on 2016-12-05 a Theft affecting 626 individuals. Breached information located on Paper/Films. An individual broke into a CVS Pharmacy in Whiteville, NC during Hurricane Matthew and stole 626 individuals' completed prescriptions containing PHI.
- Massachusetts State AGas victim2016-01-14
CVS Health reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2016-01-14. 1 Massachusetts residents were affected. The report records the breach type as electronic.
- RHODE ISLANDHHS OCRas victim2015-06-26
CVS Health reported to HHS on 2015-06-26 a Theft affecting 12,914 individuals. Breached information located on Desktop Computer. The covered entity's store in Baltimore, Maryland was looted and computers containing ePHI (names, partial DOB, addresses, medication names/dosage, prescription numbers) were stolen. Affected individuals received 1 year of free credit monitoring.
Subsidiary disclosures (newest 10)filed by group companies
◈ These filings were made by or about subsidiaries of CVS HEALTH CORPORATION — not by CVS HEALTH CORPORATION itself. Corporate relationships are mapped from GLEIF relationship records and SEC Exhibit 21 filings.
- Massachusetts State AGvia CVS Pharmacy, Inc.2026-03-20
CVS Pharmacy reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2026-03-20. 1 Massachusetts residents were affected.
- CONNECTICUTHHS OCRvia AETNA INC.2026-02-27
Aetna (Business Associate, CT) reported to HHS OCR on 2026-02-27 an Unauthorized Access/Disclosure affecting 10,888 individuals. Breached information was located on Paper/Films. A business associate was present. No further description was provided.
- CONNECTICUTHHS OCRvia AETNA INC.2026-02-27
Aetna reported to HHS on 2026-02-27 a Unauthorized Access/Disclosure affecting 775 individuals. Breached information located on Paper/Films.
- CONNECTICUTHHS OCRvia AETNA INC.2024-12-20
Aetna ACE (Health Plan, CT) reported to HHS on 2024-12-20 an Unauthorized Access/Disclosure affecting 1,317 individuals. A business associate employee mailed PHI — including names, addresses, and medications — to wrong recipients. Breached information was located on Other Portable Electronic Device. The CE notified HHS and affected individuals; the BA implemented additional administrative and technical safeguards in response.
- Massachusetts State AGvia CVS Pharmacy, Inc.2024-10-03
CVS Pharmacy reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2024-10-03. 39 Massachusetts residents were affected.
- CONNECTICUTHHS OCRvia AETNA INC.2024-05-03
Aetna ACE (CT, Health Plan) reported to HHS on 2024-05-03 a Hacking/IT Incident affecting 9,191 individuals. A vendor of its business associate experienced a cyber-attack that compromised PHI including names, addresses/zip codes, birthdates, and other identifiers. Breached information was located on a Network Server. HHS and affected individuals were notified.
- Illinois State AGvia AETNA LIFE INSURANCE COMPANY2024-05-01
AETNA LIFE INSURANCE CO. filed a data-breach notice with the Illinois Attorney General in May 2024 (case 24-05-010). The register records the breach as discovered on August 21, 2023. Additional entities named: KEENAN & ASSOCIATES, ONTRAK HEALTH. Illinois does not publish the number of people affected — 815 ILCS 530/10 permits the Attorney General to publish only the entity name, the types of personal information and the date range.
- Washington State AGvia AETNA INC.2024-02-28
Welltok, Inc. reported a supplemental data event on behalf of Aetna ACE involving the MOVEit Transfer server. An unknown actor exploited software vulnerabilities to access the server on May 30, 2023, and exfiltrated data including names, diagnoses, and health insurance info. Welltok was alerted on July 26, 2023. Notices were sent to 2,653 Washington residents starting Feb 23, 2024.
- RHODE ISLANDHHS OCRvia CVS Pharmacy, Inc.2024-02-16
CVS Pharmacy, Inc. reported to HHS on 2024-02-16 a Unauthorized Access/Disclosure affecting 1896 individuals. Breached information located on Network Server. An error on its website allowed PHI, including names, addresses, and financial information, to be viewable by others.
- Massachusetts State AGvia AETNA INC.2023-12-14
Aetna reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2023-12-14. 12 Massachusetts residents were affected. The report records the breach type as electronic.