Walgreens Boots Alliance, Inc.
ent_019e46a9e35c24a46cd47468e67dd53b
Disclosures
4
Leak Site · SEC 10-K Item 1C · State AG · 4 jurisdictions
Incidents
1
filings grouped by incident
Max affected reported
2,872
as filed · State AG IN
Leak-site claims
1
unverified actor claims
Identity resolution
- Canonical name
- Walgreens Boots Alliance, Inc.
- Normalized
- walgreens boots alliance— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- 549300RPTUOIXG4LIH86
- SEC EDGAR CIK
- 0001618921
- Domain
- walgreens.com
Disclosure history (4)newest first
- GLOBALLeak Siteas victim2025-07-14
Walgreens is an American pharmaceutical retail company, established in 1901. It is one of the largest US drugstore chains, known for selling prescription and non-prescription drugs, health and wellness products, cosmetics, and groceries. It also offers health services like immunization and patient care clinics. Often, Walgreens operates 24/7 to allow customers access to their products and services at any hour.
- FEDERALSEC 10-K Item 1Cas victim2024-10-15
Walgreens Boots Alliance (WBA) filed its 2024 Form 10-K disclosing its cybersecurity risk management strategy under Item 1C. The filing describes a comprehensive governance structure involving the CIO, CISO, TRC, and Audit Committee. It details the Data Security Event Plan (DSEP) and engagement of third-party experts for forensics and legal counsel. As of the filing date, WBA stated it was not aware of any cybersecurity threats that have materially affected its business or results of operations.
- 🦬Montana State AGas victim2024-10-01
Walgreens reported a data breach to the Montana Attorney General. The breach was reported on 2024-10-01. The breach occurred from 7/22/2024 to 8/17/2024. 3 Montana residents were affected.
- 🏎️Indiana State AGas victim2024-06-07
Pfizer Inc reported a data breach to the Indiana Attorney General. The breach occurred on 2024-02-21 and was reported on 2024-06-07. 2,872 Indiana residents were affected.
Subsidiary disclosures (newest 10)filed by group companies
◈ These filings were made by or about subsidiaries of Walgreens Boots Alliance, Inc. — not by Walgreens Boots Alliance, Inc. itself. Corporate relationships are mapped from GLEIF relationship records and SEC Exhibit 21 filings.
- ILHHS OCRvia Walgreen Co.2024-10-01
Walgreen Co. (IL) reported to HHS OCR on 2024-10-01 an Unauthorized Access/Disclosure affecting 1,915 individuals. A workforce member allowed two unauthorized individuals to access patients' PHI, including demographic and clinical information, stored on a laptop. In response, the CE revised its policies, implemented additional technical safeguards, sanctioned the workforce member, and retrained its workforce.
- FEDERALHHS OCRvia Walgreen Co.2022-08-31
Walgreen Co. reported to HHS on 2022-08-31 that one of its pharmacies was burglarized and a box containing paper records with the protected health information (PHI) of 1,704 individuals was stolen. The PHI involved included names, addresses, dates of birth, claims information, medications, and health plan information.
- ILHHS OCRvia Walgreen Co.2021-12-27
Walgreen Co. (IL) reported to HHS OCR on 2021-12-27 a Loss affecting 1,352 individuals. A box of prescription records containing PHI was damaged and potentially exposed. PHI involved included names, addresses, dates of birth, diagnoses, medications, and other treatment information. Located on Paper/Films. The CE notified HHS, affected individuals, the media, provided substitute notice, and implemented additional administrative safeguards.
- ILHHS OCRvia Walgreen Co.2021-01-08
Walgreen Company reported to HHS on 2021-01-08 a Unauthorized Access/Disclosure affecting 16,089 individuals. Breached information located on Email. The incident involved impermissible disclosure of PHI including names, addresses, medications, and financial/treatment data. The entity notified HHS, individuals, and media, and implemented additional technical safeguards.
- 🐻California State AGvia Walgreen Co.2020-07-24
Walgreen Co. reported a physical theft incident occurring between May 26 and June 5, 2020, where intruders broke into multiple California Walgreens stores, stealing pharmacy records, hard drives, and automation devices. The breach compromised customer PII (names, addresses, DOB, driver's licenses) and PHI (prescriptions, clinical info). Walgreens notified affected individuals, coordinated with law enforcement, and offered one year of Experian IdentityWorks monitoring.
- ILHHS OCRvia Walgreen Co.2020-02-28
Walgreen Company reported to HHS on 2020-02-28 a Unauthorized Access/Disclosure affecting 6681 individuals. Breached information located on Network Server. An error in its database allowed the protected health information (PHI) of 6,681 individuals to be viewed by others. The PHI involved included names, addresses, medications, health insurance information, and financial information.
- 🐻California State AGvia Walgreen Co.2020-02-28
Walgreen Co. disclosed a January 2020 incident where an internal application error in its mobile app allowed customers to view other customers' secure messages. Affected data included names, prescription numbers, drug names, store numbers, and shipping addresses. No financial or SSN data was involved. Walgreens disabled the feature and implemented a technical correction.
- 🐻California State AGvia Walgreen Co.2018-06-19
Walgreen Co. notified the California AG of a physical skimming incident at two Walgreens-owned Rite Aid locations in Nashville, TN. Unauthorized skimming devices were attached to POS pin pads between Dec 20, 2017, and Apr 17, 2018. Potential data exposure includes credit/debit card numbers, PINs, and customer names. No fraud was confirmed. Walgreens disabled devices, notified law enforcement, and offered credit monitoring.
- ILHHS OCRvia Walgreen Co.2018-04-27
Walgreen Co. reported to HHS on 2018-04-27 a Theft affecting 703 individuals. Breached information located on Paper/Films. A Nashville, Tennessee pharmacy was burglarized, resulting in the theft of PHI including names, addresses, DOBs, SSNs, medications, and insurance info. Walgreens notified HHS, individuals, media, and law enforcement, provided credit monitoring, and implemented safeguards.
- ILHHS OCRvia Walgreen Co.2017-02-03
Walgreen Co. reported to HHS on 2017-02-03 a Unauthorized Access/Disclosure affecting 4500 individuals. Breached information located on Paper/Films. The covered entity sent improperly formatted survey letters where PHI was visible in the envelope's addressee window, exposing prescription histories, clinical, and demographic data. The entity investigated, revised quality control steps, retrained staff, notified HHS and individuals, and posted a substitute notice on its website.