Skip to content

CVS Pharmacy

Disclosed Feb 16, 20242 years ago1,896 affectedConfirmed

Official notice

The covered entity (CE), CVS Pharmacy, reported that an error on its website allowed the protected health information (PHI) of 1,896 individuals to be viewable by others. The PHI involved included names, addresses, and financial information. The CW notified HHS and the affected individuals. In response to the breach, the CE provided complimentary credit monitoring services and implemented additional administrative, technical, and security safeguards to better protect its PHI.

What is known

People affected1,896 (as reported to HHS)
DisclosedFeb 16, 2024
AttackInsider
Data exposedNames, Health
SectorHealthcare · US
StatusConfirmed

Sources

Source
HHS OCR breach report (archive, resolved): CVS Pharmacy (Healthcare Provider, RI)ocrportal.hhs.gov · Official notice

Notices filed

WhereFiledPeople
HHS archivetotalFeb 16, 20241,896

Other breaches at CVS Pharmacy

BreachAffected
Disclosed Sep 10, 2021Sep 10, 20215 years agoHacking6,221
Disclosed Jul 24, 2020Jul 24, 20206 years agoLost or stolen device26K
Disclosed Jan 30, 2019Jan 30, 20197 years agoLost or stolen device5,645
Disclosed Oct 13, 2017Oct 13, 20178 years agoLost or stolen device836
Disclosed Sep 11, 2015Sep 11, 201511 years ago323K
History of this record
  • 2026-09-25 · added · backfill source

First seen 2026-09-25 (HHS archive), confirmed by HHS OCR. Record counts are as reported. Not legal advice.

Everything about CVS Pharmacy

New breaches by email

Wednesdays, only in weeks with newly disclosed breaches, the largest first.

Double opt-in. Unsubscribe any time.