People search Walgreens data breach timeline because regulated data and trust are existential—one incident triggers class actions and regulator exams. BreachHistory indexes 7 Walgreens-linked incidents, with headline counts up to 100K+ in catalog rows. This page maps every attested event through 2026 with internal links to canonical records.
Why Walgreens breach history matters
Walgreens operates in Healthcare. Across indexed rows, recurring themes include mixed intrusion and disclosure events. Understanding the chronological pattern helps security teams, customers, and regulators separate confirmed disclosures from forum marketing.
Full timeline through 2026
2014 — — Crescent Health Inc.: Walgreens has notified some patients of a breach…
Unverified claim — treat actor counts cautiously. Walgreens has notified some patients of a breach when an employee stole some patients information, which included names, dates of birth, and Social Security Numbers in the form of a Medicare ID number and provided the information to a third party. Walgreens is claiming that no credit card, banking or other personal information was involved. The company has set up a hotling for those affected, 1-866-312-8654 from 7 a.m to 7 p.m Central Standard time, Monday through Friday. Exposed categories include Personal information. No attested victim count is published for this row yet. See the walgreens2014 and canonical BreachHistory entry.
2013 — — Crescent Health Inc.: Desktop computer hardware was stolen from the…
Cataloged incident. Desktop computer hardware was stolen from the Anaheim Billing Center of Crescent Healthcare, Inc. on December 28, 2012. The theft was discovered on Monday, December 31 and reported to law enforcement. Names, Social Security numbers, health insurance identification numbers, health insurance information, dates of birth, diagnoses, other medical information, disability codes, addresses, and phone numbers may have been exposed.UPDATE (04/03/2013): Over 100,000 people were affected. Exposed categories include Personal information. BreachHistory cites approximately 100K+ affected records in this row. See the walgreens2013 and canonical BreachHistory entry.
2013 — — Crescent Health Inc.: Names, Social Security numbers, health insurance…
Cataloged incident. Names, Social Security numbers, health insurance identification numbers, health insurance information, dates of birth, diagnoses, other medical information, disability codes, addresses, and phone numbers may have been exposed via a laptop theft. BreachHistory cites approximately 100K+ affected records in this row. See the crescent-health-incu and canonical BreachHistory entry.
2012 — — Crescent Health Inc.: Walgreens was ordered to pay $16
Cataloged incident. Walgreens was ordered to pay $16.57 million as a part of a settlement of a civil environmental prosecution. Walgreens was accused of illegally dumping hazardous waste as well as confidential customer medical information. It is unclear what type of customer medical information was mishandled.UPDATE (12/13/2012): The civil enforcement lawsuit was first filed in Alameda County in June of 2012. It was the result of investigations that took place in San Diego County in the summer and fall of 2011. Exposed categories include Personal information. No attested victim count is published for this row yet. See the walgreens2012 and canonical BreachHistory entry.
2011 — — Crescent Health Inc.: According to a complaint filed against Walgreens,…
Cataloged incident. According to a complaint filed against Walgreens, Walgreens sold confidential information of customers to data mining companies who resold it to pharmaceutical companies. Walgreens is accused of receiving payment for prescription information that only patients had the right to sell. Walgreens sells patient data that includes sex, age group, state, ID number of the providing doctor and the name of the drug that is taken. Exposed categories include Personal information. No attested victim count is published for this row yet. See the walgreens2011 and canonical BreachHistory entry.
2010 — — Crescent Health Inc.: A hacker managed to obtain Walgreens' email…
Cataloged incident. A hacker managed to obtain Walgreens' email marketing list. People on the list were sent realistic-looking phishing emails that directed them to a web page under hacker control. The only information that was stolen during the hack was the email list. People who fell victim to the phishing scam may have entered other personal information into the phony web page. Exposed categories include Personal information. No attested victim count is published for this row yet. See the walgreens2010 and canonical BreachHistory entry.
2009 — — Crescent Health Inc.: Names, dates of birth and Social Security numbers…
Unverified claim — treat actor counts cautiously. Names, dates of birth and Social Security numbers of roughly 28,000 state retirees were e-mailed to the Kentucky Retirement Systems without being properly encrypted for security purposes by its pharmacy benefit provider. The e-mail contained dates of birth, Social Security numbers and health insurance claim numbers but not personal health information. The file contained information only on members who were both Medicare-eligible a Exposed categories include Personal information. BreachHistory cites approximately 28K+ affected records in this row. See the walgreens2009 and canonical BreachHistory entry.
Patterns and analysis
- Mixed intrusion and disclosure events — appears across multiple Walgreens catalog entries; prioritize controls that address this class of failure.
- Record-count hygiene — BreachHistory indexes actor-cited figures separately from company-confirmed totals; read each row's technicalWriteup before treating counts as fact.
- 2026 monitoring — New disclosures roll into this timeline as they are verified or labeled unverified per catalog policy.
What to do if you may be affected
- Step 1: Enable phishing-resistant MFA on every account tied to this brand.
- Step 2: Use unique passwords and a password manager—breach rows often involve credential reuse.
- Step 3: Monitor official company breach notices and regulator filings, not dark-web downloads.
- Step 4: Watch for medical-ID theft and billing fraud after health-data incidents.
- Step 5: Bookmark the Walgreens company page for new 2026+ disclosures.
Canonical BreachHistory hub
Explore every indexed row: breachhistory.com/walgreens · Latest: walgreens2014.
Sources: BreachHistory catalog (7 rows for Walgreens), company and regulator disclosures cited in individual breach records.