DataBreachInformation.com
Investigation OpenMassachusetts AG filing · March 20, 2026

CVS Pharmacy Reports Data Security Incident to Massachusetts Regulators

CVS Pharmacy officially reported a data security incident to Massachusetts authorities on March 20, 2026. This filing indicates that personal information may have been compromised, and the situation is currently under investigation. Individuals who receive direct notifications should review them for specific details.

State
Massachusetts
Reported
March 20, 2026

CVS Pharmacy submitted a data breach notification to the relevant authorities in Massachusetts on March 20, 2026. This official filing confirms that a security incident involving personal information has occurred. The specific circumstances surrounding the breach, including when it took place and the exact method of compromise, are still being investigated by the company.

According to the public filing, the particular types of data exposed in this incident were not specified. Therefore, any affected information is referred to generally as "personal information" or "your data." The total number of individuals impacted by this security event has also not been publicly disclosed in the filing.

When personal information is compromised in a security incident, it can potentially lead to risks such as identity theft or various forms of fraud. While CVS Pharmacy handles a wide range of sensitive consumer data, the notification filed with Massachusetts regulators does not provide details about which specific categories of personal information were involved in this particular breach.

If you receive a direct notification letter from CVS Pharmacy regarding this incident, it is important to read it thoroughly for any specific guidance or offers of assistance. General recommendations include staying alert for any unusual activity across your personal accounts, especially financial or online service accounts. You may also consider reviewing your credit reports periodically.

It is advisable to be cautious of any unsolicited communications, such as emails or phone calls, claiming to be from CVS Pharmacy and requesting personal details. Always verify the legitimacy of such requests directly with the company through official channels. This information is derived from public data breach filings made to state regulatory bodies, serving as a record of reported security incidents.

More Massachusetts data breach cases