Skip to content

CVS Pharmacy

Disclosed Jan 30, 20197 years ago5,645 affectedConfirmed

Official notice

The covered entity (CE), CVS Pharmacy, reported that protected health information (PHI) was erroneously placed in a storage container maintained by its business associate, Target Corporation. Subsequently, the storage container was vandalized and the PHI was stolen. This breach incident affected 5,645 individuals. The types of PHI involved included names, addresses, dates of birth, and prescription information. Following this breach incident, CVS notified OCR, affected individuals, and the media.

What is known

People affected5,645 (as reported to HHS)
DisclosedJan 30, 2019
AttackLost or stolen device
Data exposedNames, Health
SectorHealthcare · US
StatusConfirmed

Sources

Source
HHS OCR breach report (archive, resolved): CVS Pharmacy (Healthcare Provider, RI)ocrportal.hhs.gov · Official notice

Notices filed

WhereFiledPeople
HHS archivetotalJan 30, 20195,645

Other breaches at CVS Pharmacy

BreachAffected
Disclosed Feb 16, 2024Feb 16, 20242 years agoInsider1,896
Disclosed Sep 10, 2021Sep 10, 20215 years agoHacking6,221
Disclosed Jul 24, 2020Jul 24, 20206 years agoLost or stolen device26K
Disclosed Oct 13, 2017Oct 13, 20178 years agoLost or stolen device836
Disclosed Sep 11, 2015Sep 11, 201511 years ago323K
History of this record
  • 2026-09-25 · added · backfill source

First seen 2026-09-25 (HHS archive), confirmed by HHS OCR. Record counts are as reported. Not legal advice.

Everything about CVS Pharmacy

New breaches by email

Wednesdays, only in weeks with newly disclosed breaches, the largest first.

Double opt-in. Unsubscribe any time.