Skip to content

CVS Pharmacy

Disclosed Jul 24, 20206 years ago26,234 affectedConfirmed

Official notice

The covered entity (CE), CVS Pharmacy, reported that a number of its CVS stores across the country had been vandalized. The breach affected the protected health information (PHI) of 26,234 individuals. The PHI involved included names, addresses, and dates of birth, as well as clinical information including medications prescribed. The CE notified HHS, affected individuals, the media, and provided substitute note. Following the breach, CVS assembled a response team to investigate and restore operations, and provided its pharmacy teams with additional guidance and recommendations for securing PHI that had been tampered or removed. In its mitigation efforts, the CE implemented additional physical, administrative, technical, and security safeguards to better protect its PHI. CVS apologized to all affected individuals and provided a toll-free phone number to call with questions or concerns.

What is known

People affected26,234 (as reported to HHS)
DisclosedJul 24, 2020
AttackLost or stolen device
Data exposedNames, Health
SectorHealthcare · US
StatusConfirmed

Sources

Source
HHS OCR breach report (archive, resolved): CVS Pharmacy (Healthcare Provider, RI)ocrportal.hhs.gov · Official notice

Notices filed

WhereFiledPeople
HHS archivetotalJul 24, 202026,234

Other breaches at CVS Pharmacy

BreachAffected
Disclosed Feb 16, 2024Feb 16, 20242 years agoInsider1,896
Disclosed Sep 10, 2021Sep 10, 20215 years agoHacking6,221
Disclosed Jan 30, 2019Jan 30, 20197 years agoLost or stolen device5,645
Disclosed Oct 13, 2017Oct 13, 20178 years agoLost or stolen device836
Disclosed Sep 11, 2015Sep 11, 201511 years ago323K
History of this record
  • 2026-09-25 · added · backfill source

First seen 2026-09-25 (HHS archive), confirmed by HHS OCR. Record counts are as reported. Not legal advice.

Everything about CVS Pharmacy

New breaches by email

Wednesdays, only in weeks with newly disclosed breaches, the largest first.

Double opt-in. Unsubscribe any time.