CVS pharmacies nationwide tossed pill bottles, prescriptions, and employee SSNs into unsecured public dumpsters; media exposure across a dozen-plus cities led to a $2.25M HHS settlement and a separate FTC consent order in 2009.
Reviewed by the Social Engineering Examples team.
Beginning around July 2006 and continuing into 2007, television and print media across the United States (most notably an Indianapolis WTHR/13 Investigates series by reporter Bob Segall, later expanded into a multi-city dumpster-diving investigation, with AP wire coverage) found that CVS pharmacy stores were discarding sensitive patient and employee records into open, publicly accessible dumpsters rather than shredding or securely destroying them. Reporters recovered pill bottles bearing patient names, home addresses, prescribing physicians, medications and dosages; medication instruction sheets; pharmacy computer printouts; old prescriptions and refund records; credit card receipts; and employee employment applications and payroll records containing Social Security numbers. WTHR's investigation had itself been triggered by a real-world incident in Bloomington, Indiana: a man posing as a pharmacy employee tricked an elderly victim at her front door into handing over her OxyContin medication, after finding her prescription and address information in a CVS dumpster; this specific incident is documented in WTHR's own reporting (and AP wire syndication), not in the FTC complaint, which contains no named incident and only a general statement that dumpster-exposed data "can be obtained ... for purposes of identity theft or the theft of prescription medicines." The FTC and HHS Office for Civil Rights (OCR) opened coordinated investigations, and on February 18, 2009 announced a joint resolution: CVS Pharmacy, Inc. agreed to pay HHS OCR $2.25 million and adopt a three-year Corrective Action Plan to resolve potential HIPAA Privacy Rule violations (resolution agreement signed January 16, 2009), while CVS Caremark Corporation separately settled FTC charges of unfair and deceptive practices under Section 5 of the FTC Act via a consent order that became final on June 23, 2009. CVS admitted no liability in either settlement.
This was not a social-engineering attack on a person in the moment but a systemic physical-security failure that created raw material for social engineering and identity theft. CVS pharmacies' disposal practices left unsecured, unshredded documents containing protected health information (PHI) and personally identifiable information (PII) in dumpsters accessible to anyone. The exposure method (dumpster diving) is a classic physical reconnaissance technique used to harvest data that then fuels impersonation and crime; this is illustrated by the Bloomington, Indiana case reported by WTHR and picked up by AP wire coverage, in which a thief used address and prescription information recovered from a CVS dumpster to pose as a pharmacy employee and trick an elderly victim into handing over her OxyContin medication at her front door. That specific incident comes from WTHR's own investigative reporting (and subsequent AP syndication), not from the FTC complaint, which does not name any specific incident and only makes the general statement that dumpster-exposed data "can be obtained by individuals for purposes of identity theft or the theft of prescription medicines." The FTC's complaint framed CVS's conduct as an unfair practice because the resulting exposure was likely to cause substantial consumer injury that customers could not reasonably avoid, and it also alleged deceptive privacy claims; HHS framed it as a failure to implement HIPAA-required safeguards for disposal of PHI.
There was no lure directed at a targeted victim in the traditional social-engineering sense; the "lure" was structural negligence (documents in open trash) rather than a crafted pretext at the corporate level. The downstream crime enabled by that negligence used a classic pretext: per WTHR/AP reporting, a thief impersonated a pharmacy employee at an elderly victim's front door, using her real name, address, and prescription details (recovered from a CVS dumpster) to make the impersonation credible enough to convince her to hand over her OxyContin medication directly to him; no pharmacy refill or fraudulent transaction was involved.
CVS Pharmacy, Inc. paid $2,250,000 to HHS OCR and implemented a mandated 3-year Corrective Action Plan (revised policies, workforce training, internal monitoring, and reporting on disposal of PHI). CVS Caremark Corporation's FTC consent order required establishment of a comprehensive information security program, biennial independent third-party assessments for 20 years, and detailed recordkeeping, with no upfront monetary penalty but exposure to civil penalties for future violations of the order. CVS publicly apologized, acknowledged the findings were unacceptable, and said it would require pharmacy waste to be bagged and returned to CVS warehouses rather than placed in store dumpsters, alongside revised in-store training. This was one of the earliest joint HHS-FTC enforcement actions combining HIPAA Privacy Rule and FTC Act authority over the same underlying conduct, and it functioned as a precursor to the subsequent, similarly structured Rite Aid dumpster-disposal case.
The case established that improper physical disposal of PHI/PII is independently enforceable both as a HIPAA violation and as an FTC-Act unfair/deceptive practice, and it shows how a purely physical-security lapse (unsecured trash) becomes an enabler for later social-engineering crime (impersonating a pharmacy employee using data scavenged from the trash). It is frequently cited as a foundational case for "privacy by disposal" obligations in healthcare and retail, and as the model the FTC and HHS followed shortly after in the parallel Rite Aid dumpster-disposal enforcement action.
Shred or otherwise render unreadable any documents containing PHI/PII (prescription labels, pill bottles, medication records, employment/payroll records with SSNs, financial account data) before disposal; use locked/secured waste receptacles rather than open store dumpsters for pharmacy and HR waste; enforce documented, audited disposal procedures with employee training and periodic compliance checks; treat physical trash as an attack surface equivalent to digital systems for social-engineering risk, since scavenged personal details can be used to construct credible impersonation pretexts (e.g., posing as an employee) in follow-on crimes.
TV investigative reporters filmed Rite Aid pharmacy dumpsters nationwide overflowing with readable prescription labels, patient records and job applications, leading…
A Kansas City TV station found intact consumer home-loan applications with Social Security and account numbers tossed in a title…
The FTC's first-ever case under the FACTA Disposal Rule: a Northbrook, Illinois mortgage lender repeatedly dumped intact customer credit reports…