Skip to content

CVS Caremark

Disclosed Jun 28, 20215 years ago3,064 affectedConfirmed

Official notice

The covered entity (CE), CVS Caremark, reported that an employee mailed the electronic protected health information (ePHI) of 3,064 individuals to the wrong recipients. The ePHI involved included names, diagnoses, and health insurance information. The CE notified HHS, affected individuals, and the media. In response to the breach, the CE retrained its staff and implemented additional administrative safeguards.

What is known

People affected3,064 (as reported to HHS)
DisclosedJun 28, 2021
AttackInsider
Data exposedNames, Health
SectorHealthcare · US
StatusConfirmed

Sources

Source
HHS OCR breach report (archive, resolved): CVS Caremark (Business Associate, RI)ocrportal.hhs.gov · Official notice

Notices filed

WhereFiledPeople
HHS archivetotalJun 28, 20213,064

Other breaches at CVS Caremark

BreachAffected
Disclosed May 13, 2025May 13, 20251 year agoInsider2,599
Disclosed Oct 26, 2012Oct 26, 201213 years agoLost or stolen device4,305
Disclosed May 11, 2011May 11, 201115 years agoLost or stolen device654
History of this record
  • 2026-09-25 · added · backfill source

First seen 2026-09-25 (HHS archive), confirmed by HHS OCR. Record counts are as reported. Not legal advice.

Everything about CVS Caremark

New breaches by email

Wednesdays, only in weeks with newly disclosed breaches, the largest first.

Double opt-in. Unsubscribe any time.