CVS Pharmacy Reports Data Security Incident to Massachusetts AG
CVS Pharmacy has officially reported a data security incident to the Massachusetts Attorney General, confirming that personal information was compromised. An investigation is ongoing to determine the full scope of the breach and its impact. Affected individuals should stay vigilant for potential misuse of their data.
- State
- Massachusetts
- Reported
- March 20, 2026
CVS Pharmacy officially filed a report with the Massachusetts Attorney General on March 20, 2026, concerning a data security incident within its systems. This disclosure indicates that personal information handled by the company has been exposed.
At present, the specific nature of this breach, including the method of compromise and the exact categories of personal information involved, has not been publicly detailed. CVS Pharmacy has stated that an investigation into the incident is currently underway to ascertain its full extent and impact.
While the precise nature of the data involved remains under investigation, any compromise of personal information can lead to various risks for those affected. These risks might include unauthorized access to online accounts or attempts at identity-related fraud.
Individuals who receive a direct notification from CVS Pharmacy regarding this incident should take immediate steps to protect themselves. It is advisable to remain vigilant for any suspicious communications, regularly review financial and credit statements for unusual activity, and consider changing passwords for online accounts.
This case file documents the official reporting by CVS Pharmacy to regulatory authorities in Massachusetts. Further details will be added as more information becomes available from the ongoing investigation into this security event.
What to do if you were affected
These general steps can help limit the risk of identity theft and fraud after any data breach.
Stay alert to targeted scams
Be cautious of calls, texts, or emails that reference this breach. Legitimate organizations won't ask you to confirm sensitive details through an unsolicited message.
Keep your notification letter
Save the notice you received. It documents that your information was involved and is often needed to enroll in any credit monitoring offered or to join a related legal claim.
Related data breach cases
- The Financial Guys, LLC, and affiliates
- The Chartwell Law Offices, LLP
- National Corporate Housing
- MONROE COUNTY HEALTH CENTER
- Analytix Solutions
- Builders FirstSource, Inc.
- Recovery Cafe
- Lehigh Valley Restaurant Brands
- Nest Builders, Inc. dba dbHMS
- Upstaging, Inc.
- Betterment
- Heart of America Medical Center
- Newsweb LLC
- Arkansas Oral & Maxillofacial Surgeons State