Case Library / Physical Social Engineering (Tailgating & Baiting) / CVS Caremark Pharmacy Trash Disposal Case (FTC/HHS Settlement)

CVS Caremark Pharmacy Trash Disposal Case (FTC/HHS Settlement)

CVS pharmacies nationwide tossed pill bottles, prescriptions, and employee SSNs into unsecured public dumpsters; media exposure across a dozen-plus cities led to a $2.25M HHS settlement and a separate FTC consent order in 2009.

Share:

Reviewed by the Social Engineering Examples team.

What Happened

Beginning around July 2006 and continuing into 2007, television and print media across the United States (most notably an Indianapolis WTHR/13 Investigates series by reporter Bob Segall, later expanded into a multi-city dumpster-diving investigation, with AP wire coverage) found that CVS pharmacy stores were discarding sensitive patient and employee records into open, publicly accessible dumpsters rather than shredding or securely destroying them. Reporters recovered pill bottles bearing patient names, home addresses, prescribing physicians, medications and dosages; medication instruction sheets; pharmacy computer printouts; old prescriptions and refund records; credit card receipts; and employee employment applications and payroll records containing Social Security numbers. WTHR's investigation had itself been triggered by a real-world incident in Bloomington, Indiana: a man posing as a pharmacy employee tricked an elderly victim at her front door into handing over her OxyContin medication, after finding her prescription and address information in a CVS dumpster; this specific incident is documented in WTHR's own reporting (and AP wire syndication), not in the FTC complaint, which contains no named incident and only a general statement that dumpster-exposed data "can be obtained ... for purposes of identity theft or the theft of prescription medicines." The FTC and HHS Office for Civil Rights (OCR) opened coordinated investigations, and on February 18, 2009 announced a joint resolution: CVS Pharmacy, Inc. agreed to pay HHS OCR $2.25 million and adopt a three-year Corrective Action Plan to resolve potential HIPAA Privacy Rule violations (resolution agreement signed January 16, 2009), while CVS Caremark Corporation separately settled FTC charges of unfair and deceptive practices under Section 5 of the FTC Act via a consent order that became final on June 23, 2009. CVS admitted no liability in either settlement.

How the Attack Worked

This was not a social-engineering attack on a person in the moment but a systemic physical-security failure that created raw material for social engineering and identity theft. CVS pharmacies' disposal practices left unsecured, unshredded documents containing protected health information (PHI) and personally identifiable information (PII) in dumpsters accessible to anyone. The exposure method (dumpster diving) is a classic physical reconnaissance technique used to harvest data that then fuels impersonation and crime; this is illustrated by the Bloomington, Indiana case reported by WTHR and picked up by AP wire coverage, in which a thief used address and prescription information recovered from a CVS dumpster to pose as a pharmacy employee and trick an elderly victim into handing over her OxyContin medication at her front door. That specific incident comes from WTHR's own investigative reporting (and subsequent AP syndication), not from the FTC complaint, which does not name any specific incident and only makes the general statement that dumpster-exposed data "can be obtained by individuals for purposes of identity theft or the theft of prescription medicines." The FTC's complaint framed CVS's conduct as an unfair practice because the resulting exposure was likely to cause substantial consumer injury that customers could not reasonably avoid, and it also alleged deceptive privacy claims; HHS framed it as a failure to implement HIPAA-required safeguards for disposal of PHI.

The Lure & the Tell

There was no lure directed at a targeted victim in the traditional social-engineering sense; the "lure" was structural negligence (documents in open trash) rather than a crafted pretext at the corporate level. The downstream crime enabled by that negligence used a classic pretext: per WTHR/AP reporting, a thief impersonated a pharmacy employee at an elderly victim's front door, using her real name, address, and prescription details (recovered from a CVS dumpster) to make the impersonation credible enough to convince her to hand over her OxyContin medication directly to him; no pharmacy refill or fraudulent transaction was involved.

Outcome

CVS Pharmacy, Inc. paid $2,250,000 to HHS OCR and implemented a mandated 3-year Corrective Action Plan (revised policies, workforce training, internal monitoring, and reporting on disposal of PHI). CVS Caremark Corporation's FTC consent order required establishment of a comprehensive information security program, biennial independent third-party assessments for 20 years, and detailed recordkeeping, with no upfront monetary penalty but exposure to civil penalties for future violations of the order. CVS publicly apologized, acknowledged the findings were unacceptable, and said it would require pharmacy waste to be bagged and returned to CVS warehouses rather than placed in store dumpsters, alongside revised in-store training. This was one of the earliest joint HHS-FTC enforcement actions combining HIPAA Privacy Rule and FTC Act authority over the same underlying conduct, and it functioned as a precursor to the subsequent, similarly structured Rite Aid dumpster-disposal case.

Why It Matters

The case established that improper physical disposal of PHI/PII is independently enforceable both as a HIPAA violation and as an FTC-Act unfair/deceptive practice, and it shows how a purely physical-security lapse (unsecured trash) becomes an enabler for later social-engineering crime (impersonating a pharmacy employee using data scavenged from the trash). It is frequently cited as a foundational case for "privacy by disposal" obligations in healthcare and retail, and as the model the FTC and HHS followed shortly after in the parallel Rite Aid dumpster-disposal enforcement action.

Defenses

Shred or otherwise render unreadable any documents containing PHI/PII (prescription labels, pill bottles, medication records, employment/payroll records with SSNs, financial account data) before disposal; use locked/secured waste receptacles rather than open store dumpsters for pharmacy and HR waste; enforce documented, audited disposal procedures with employee training and periodic compliance checks; treat physical trash as an attack surface equivalent to digital systems for social-engineering risk, since scavenged personal details can be used to construct credible impersonation pretexts (e.g., posing as an employee) in follow-on crimes.

Sources
Attack Chain & Defense
The sequence the attacker ran
How it could have been stopped
1
Target selection: Opportunistic thieves and, per WTHR/AP reporting, at least one documented offender identify pharmacy locations that leave waste in open, publicly accessible dumpsters rather than locked or secured receptacles, typically through casual observation of a store's trash-handling habits rather than any digital reconnaissance.
Countering Stage 1: Locking or securing store dumpsters, and using windowless, gated, or company-controlled enclosures instead of open public receptacles, removes the reconnaissance opportunity at its source; this is essentially the fix CVS adopted afterward.
2
Physical collection (dumpster diving): The thief physically searches the unsecured dumpster and recovers discarded pharmacy and HR waste, pill bottles and prescription labels, patient information sheets, refill and computer printouts, credit card and insurance receipts, and employee applications or payroll records with Social Security numbers, the exact categories documented in the FTC complaint and WTHR's reporting.
Countering Stage 2: Even where a dumpster is later reached, shredding or otherwise rendering PHI and PII unreadable before disposal (pill labels, prescription printouts, SSN-bearing HR records) means there is nothing usable to retrieve regardless of physical access.
3
Data triage and profile-building: The thief sorts recovered material into what is directly usable for financial/identity fraud (SSNs, card and insurance numbers) versus what can support a credible impersonation of pharmacy staff (a real patient's name, address, medication, dosage, and prescribing physician), consistent with how WTHR described the Bloomington, Indiana case unfolding.
Countering Stage 3: The same destroy-before-disposal control removes the raw material for triage; there is no separate practical defense once intact records are already in an attacker's hands, so this stage is best addressed by preventing Stage 2's collection rather than intercepting sorting after the fact.
4
Pretext construction: Using the victim's own real prescription details recovered from the trash, the thief builds a pretext of being a pharmacy employee or technician who needs to correct a filling error, a story that only works because it is grounded in accurate, victim-specific data the thief should not otherwise have.
Countering Stage 4: Pretext construction happens off-site with no visibility to the pharmacy or the eventual victim, so it cannot be directly detected or blocked; the realistic control is upstream (destroying the data that makes the pretext credible, per Stage 2) rather than trying to catch the pretext being built.
5
In-person impersonation and execution: Per WTHR and AP wire reporting, the thief approached the elderly victim at her front door posing as pharmacy staff, invoking the fabricated "filling error" and urgency to persuade her to hand over her prescription medication directly, with no digital system or transaction involved.
Countering Stage 5: Consumer and employee education that legitimate pharmacy staff do not make unannounced home visits to reclaim or correct dispensed medication, paired with a standing instruction to verify any such claim by calling the pharmacy's published number before handing anything over, would have interrupted the in-person impersonation.
6
Objective completion: For the Bloomington incident, the thief left with the victim's OxyContin in hand, a high-value controlled substance obtainable without ever needing to defraud CVS's own systems; separately, the SSNs, payment-card, and insurance data exposed by the same disposal failure created an ongoing, harder-to-quantify risk of identity theft and financial fraud against other customers and employees, which is the harm the FTC and HHS complaints centered on even though no other individual case was named in the settlements.
Countering Stage 6: Once medication has been physically handed over there is no technical recovery, making Stage 5's verification habit the last real intervention point for that specific harm; for the broader identity-theft and financial-fraud risk from exposed SSNs and card data, standard post-exposure controls (credit freezes, fraud alerts, breach monitoring) reduce downstream damage but do not prevent it, which is why regulators required CVS to fix disposal practices (Stage 2) rather than relying on after-the-fact monitoring alone.
Quick Facts
Victim
CVS Caremark Corporation / CVS Pharmacy, Inc. (and, downstream, CVS's pharmacy customers and employees whose records were exposed)
Location
Nationwide United States; media (WTHR/13 Investigates, corroborated by the World Privacy Forum's FTC comment filing) identified CVS-specific dumpster findings in cities including Indianapolis IN, Woonsocket RI (CVS world headquarters, worst-found), Boston MA, Chicago IL, Cleveland OH, Dallas TX, Detroit MI, Louisville KY, Miami FL, New Haven CT, Philadelphia PA, and Phoenix AZ; the broader WTHR multi-chain sweep also checked Denver, CO and Washington, DC, but per the World Privacy Forum's published list, "CVS does not operate pharmacies in the Denver area" and no CVS-specific records were found there or in Washington, DC
Date
Discovered July 2006 into 2007; HHS resolution agreement signed January 16, 2009; settlement announced February 18, 2009; FTC final consent order approved June 23, 2009
Impact
$2,250,000 paid by CVS Pharmacy, Inc. to HHS Office for Civil Rights (HIPAA Privacy Rule resolution), plus a 3-year Corrective Action Plan; the parallel FTC consent order imposed no monetary payment but required an ongoing security program, independent biennial assessments, and recordkeeping, with civil penalties possible only for future violations of the order
Status
Confirmed
Case Type
Real-World Incident
Sector
Healthcare
Related

Related Cases

Rite Aid Pharmacy Dumpster Disposal of Patient and Employee Records

TV investigative reporters filmed Rite Aid pharmacy dumpsters nationwide overflowing with readable prescription labels, patient records and job applications, leading…

Incident 2006Read →

Nations Title Agency / Nations Holding Company Dumpster Diving and Hack Exposure (FTC Settlement, 2006)

A Kansas City TV station found intact consumer home-loan applications with Social Security and account numbers tossed in a title…

Incident 2006Read →

American United Mortgage Company Dumpster Diving / Improper Disposal Case (FTC v. American United Mortgage, 2007-2008)

The FTC's first-ever case under the FACTA Disposal Rule: a Northbrook, Illinois mortgage lender repeatedly dumped intact customer credit reports…

Incident 2006Read →