DataBreachSearch.com

Did CVS Pharmacy have a data breach?

Answer

Yes. CVS Pharmacy reported a data breach to the Massachusetts Attorney General on March 20, 2026.

What the filing says

Reported to
Massachusetts Attorney General
Filing date
March 20, 2026
Breach date
Not stated in the filing
People affected
Not stated in the filing

In plain terms

On March 20, 2026, CVS Pharmacy filed a report with the Massachusetts Attorney General's Office regarding a data security incident. The company states an investigation is ongoing to understand the full scope of what happened. This means that personal information held by CVS Pharmacy may have been impacted.

CVS Pharmacy has officially reported a data security incident to the Office of the Massachusetts Attorney General. This filing, dated March 20, 2026, confirms that the company experienced an event involving its data systems.

Details provided in the public record indicate that CVS Pharmacy is currently investigating the breach. The specific type of incident and the categories of personal information involved have not been publicly specified by the company at this time.

Individuals who may be affected by this incident should be aware that their personal information could have been accessed without authorization. CVS Pharmacy is expected to issue direct notifications to those whose data is confirmed to have been compromised once their investigation is complete.

To help protect yourself, it is always recommended to monitor your financial accounts and credit reports for any unusual activity. Be cautious of unexpected emails, calls, or messages requesting personal details, as these could be phishing attempts.

Consider enabling multi-factor authentication on online accounts where available, and regularly review account statements. Changing passwords for important online services to strong, unique combinations is also a prudent general security measure.

Commonly recommended next steps

  • Stay alert to targeted scams

    Be cautious of calls, texts, or emails that reference this breach. Legitimate organizations won't ask you to confirm sensitive details through an unsolicited message.

  • Keep your notification letter

    Save the notice you received. It documents that your information was involved and is often needed to enroll in any credit monitoring offered or to join a related legal claim.

Look up another company

Other breaches reported in Massachusetts

DataBreachSearch.com reports what was filed with state regulators. It is not legal advice, is not a law firm, and is not affiliated with any government agency or with CVS Pharmacy.