Walgreen Co. Data Breach
Walgreens Paper Records Theft Affects 1,704 Patients in Illinois
What happened in the Walgreen Co. data breach?
The Walgreen Co. data breach was reported on August 31, 2022 and affected 1,704 individuals. The breach type was Theft involving Paper/Films. This breach occurred in Illinois. Under HIPAA, affected patients must be notified within 60 days and may be entitled to credit monitoring services.
Walgreen Co. Breach Details
Walgreens Co. Data Breach Report
Incident Overview
Walgreen Co., one of the largest pharmacy and healthcare retailers in the United States, reported a data breach affecting 1,704 individuals in Illinois. The breach occurred through the theft of paper records and films containing protected health information (PHI). The breach was formally reported to the U.S. Department of Health and Human Services (HHS) on August 31, 2022, indicating that the incident was discovered and investigated during the preceding months. This breach represents a significant security incident involving physical healthcare records, a vulnerability that persists despite the healthcare industry's transition toward electronic health records (EHRs).
Discovery and Response Timeline
The specific date of discovery was not disclosed in the breach notification submission, though the August 31, 2022 submission date indicates the breach was identified and investigated within a reasonable timeframe to meet HIPAA Breach Notification Rule requirements. Walgreens initiated an investigation upon discovery of the missing paper records and films. The company conducted a thorough review to determine the scope of the breach, identify affected individuals, and assess what types of health information may have been compromised. Following standard HIPAA protocols, Walgreens notified affected individuals of the breach and reported the incident to HHS as required by the Breach Notification Rule, which mandates notification when a breach of unsecured PHI affects more than 500 residents of a state or jurisdiction.
Breach Mechanism and Specifics
The breach involved the theft of physical paper records and films—a method that highlights vulnerabilities in physical security controls at healthcare facilities. Paper-based records and radiographic films (X-rays, CT scans, and other diagnostic imaging) are particularly sensitive because they contain comprehensive patient health information and diagnostic images that cannot be easily replaced or monitored for misuse. Theft of physical records typically occurs due to inadequate access controls, insufficient monitoring of storage areas, or lapses in chain-of-custody procedures. Unlike digital breaches that may be detected through system logs and network monitoring, physical theft can go undetected for extended periods until inventory audits or patient inquiries reveal missing documents. The location designation "Paper/Films" indicates that the compromised materials were stored in physical form rather than electronic format, suggesting the breach occurred at a pharmacy location or healthcare facility where patient records and diagnostic images are maintained.
Organizational Context
Walgreen Co. operates as a major pharmacy and healthcare services provider with thousands of locations across the United States, including Illinois where this breach occurred. The company provides prescription filling services, over-the-counter medications, healthcare consultations, and increasingly, clinical services through its healthcare clinics. Walgreens maintains extensive patient records including prescription histories, medication allergies, medical conditions, and in some cases, diagnostic imaging and clinical notes. The organization's size and distributed nature—with numerous individual pharmacy locations—creates significant challenges for maintaining consistent physical security protocols across all facilities. The breach did not involve a Business Associate, indicating that the compromised information was directly under Walgreens' control and responsibility.
Patient Impact and Affected Population
Approximately 1,704 individuals in Illinois had their protected health information potentially exposed through this theft. These patients likely included individuals who had filled prescriptions at affected Walgreens locations, received clinical services, or had diagnostic imaging performed at Walgreens healthcare facilities. The compromised paper records and films may have contained sensitive information including names, addresses, dates of birth, Social Security numbers, insurance information, prescription histories, medical diagnoses, medication lists, and diagnostic imaging results. Patients were notified of the breach in accordance with HIPAA requirements, which mandate notification without unreasonable delay and no later than 60 calendar days after discovery of a breach of unsecured PHI. The notification likely included information about the types of data compromised, steps Walgreens was taking to prevent future incidents, and recommended actions patients should take to protect themselves.
HIPAA Compliance and Industry Context
Under the HIPAA Breach Notification Rule, covered entities like Walgreens must notify affected individuals, the media (if more than 500 residents are affected), and HHS when unsecured PHI is accessed, acquired, used, or disclosed in a manner not permitted by HIPAA. Physical theft of paper records and films constitutes a breach unless the entity can demonstrate through a risk assessment that there is a low probability that the PHI has been compromised. The fact that Walgreens reported this as a breach indicates they determined the risk of unauthorized access to be significant. Physical security breaches involving paper records remain a persistent vulnerability in healthcare despite technological advances. According to HHS breach statistics, theft accounts for a substantial portion of reported breaches, particularly in retail pharmacy settings where records may be stored in less secure environments than hospital systems. This incident underscores the importance of maintaining strong physical security controls, including restricted access to record storage areas, regular inventory audits, employee training on information security, and clear chain-of-custody procedures for sensitive documents.
What Data Was Exposed
Risks to Patients
What to Do If You Were Affected by the Walgreen Co. Breach
Monitor credit reports from all three major credit bureaus (Equifax, Experian, TransUnion) for unauthorized accounts or inquiries. Consider placing a fraud alert or credit freeze to prevent unauthorized credit applications.
Review prescription records and medication histories with your pharmacy and healthcare providers to ensure no unauthorized prescriptions have been filled or medications obtained in your name.
Monitor healthcare Explanation of Benefits (EOB) statements and medical bills for unauthorized services or claims. Contact your insurance provider immediately if you identify suspicious activity.
Consider enrolling in identity theft protection services or credit monitoring services that provide alerts for suspicious activity. Be cautious of unsolicited communications claiming to be from healthcare providers or financial institutions.
Monitor Your Medical Records
Request copies to check for unauthorized changes
Check More Illinois Breaches
Search all breaches reported in Illinois
Technical Notes
Walgreen Co. Has 2 Reported Breaches
This organization has been involved in multiple reported data breaches.
View full breach history for Walgreen Co.