CVS CAREMARK
ent_235ea3d041ed551fef1fcc46
Disclosures
5
HHS OCR · 2 jurisdictions
Multi-filing incidents
—
no multi-filing incident in sample
Max affected reported
4,305
nationwide · HHS OCR AZ
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- CVS CAREMARK
- Normalized
- cvs caremark— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- No match
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- None on record
Disclosure history (5)newest first
- RHODE ISLANDHHS OCRas victim2025-05-13
CVS Caremark reported to HHS on 2025-05-13 a Unauthorized Access/Disclosure affecting 2599 individuals. Breached information located on Paper/Films. Business associate present.
- RHODE ISLANDHHS OCRas victim2021-06-28
CVS Caremark reported to HHS on 2021-06-28 a Unauthorized Access/Disclosure affecting 3064 individuals. Breached information located on Paper/Films. An employee mailed ePHI (names, diagnoses, health insurance) to wrong recipients. The CE retrained staff and implemented administrative safeguards.
- ARIZONAHHS OCRas victim2013-07-02
CVS Caremark reported to HHS on 2013-07-02 a data breach affecting 4,305 individuals. The business associate for Northrop Grumman Retiree Health Plan erroneously sent paper documents containing members' names and prescribed medications to other members. In response, the company revised its quality control policies and retrained employees.
- RHODE ISLANDHHS OCRas victim2012-10-26
CVS Caremark reported to HHS on 2012-10-26 a Theft affecting 955 individuals. Breached information located on Paper/Films.
- ARIZONAHHS OCRas victim2011-05-11
CVS CAREMARK reported to HHS on 2011-05-11 a Theft, Unauthorized Access/Disclosure affecting 654 individuals. Breached information located on Paper/Films. An employee impermissibly accessed and printed patient drug transfer reports to fill fraudulent prescriptions, disclosing PHI to a third party.