Skip to content

Kroger Co., for itself

Disclosed Oct 25, 20196 years ago4,812 affectedConfirmed

Official notice

The covered entity (CE), The Kroger Company, reported that a shipping service lost a box of patient records containing the protected health information (PHI) of approximately 4,812 individuals. The records were being shipped from its off-site storage facility; however, the off-site storage vendor shipped more than the PHI requested. The PHI involved included names, prescription numbers, and health insurance information. The CE notified HHS, affected individuals, the media, and provided a toll-free number for questions or concerns. The CE implemented additional administrative safeguards and retrained its staff. OCR obtained documentation that the CE implemented the corrective actions noted.

What is known

People affected4,812 (as reported to HHS)
DisclosedOct 25, 2019
AttackLost or stolen device
Data exposedNames, Health
SectorHealthcare · US
StatusConfirmed

Sources

Source
HHS OCR breach report (archive, resolved): Kroger Co., for itself (Healthcare Provider, OH)ocrportal.hhs.gov · Official notice

Notices filed

WhereFiledPeople
HHS archivetotalOct 25, 20194,812

Other breaches at Kroger Co., for itself

BreachAffected
Disclosed Feb 26, 2014Feb 26, 201412 years ago504
History of this record
  • 2026-09-25 · added · backfill source

First seen 2026-09-25 (HHS archive), confirmed by HHS OCR. Record counts are as reported. Not legal advice.

Everything about Kroger Co., for itself

New breaches by email

Wednesdays, only in weeks with newly disclosed breaches, the largest first.

Double opt-in. Unsubscribe any time.