TV investigative reporters filmed Rite Aid pharmacy dumpsters nationwide overflowing with readable prescription labels, patient records and job applications, leading to a joint FTC/HHS settlement including a $1 million HIPAA payment and a 20-year FTC security-audit order.
Reviewed by the Social Engineering Examples team.
Beginning with a 2006 Indianapolis TV investigation and expanding through 2007-2008, local news teams across the United States, most notably WTHR-13 "13 Investigates" in Indianapolis, filmed open, publicly accessible dumpsters behind Rite Aid pharmacy stores containing pharmacy labels, pill bottles, prescription and refill records bearing patients' names, addresses, phone numbers, birth dates and prescribing physicians, along with employment applications and other employee PII. The FTC's complaint states such findings were reported in "at least 7 cities throughout the United States" but does not itemize them; WTHR's own published accounts of its broader multi-chain investigation (covering CVS, Walgreens, and Rite Aid dumpsters collectively, not Rite Aid alone) cite Phoenix, Denver, Miami, Detroit, and Philadelphia in addition to the originating Indianapolis probe, with the exact cities where Rite Aid dumpsters specifically were documented not itemized in any accessible primary or secondary source. The exposure was not the result of a hack or a con; it was a systemic failure to secure sensitive paper records before physical disposal at scale, across a chain of nearly 4,800 stores. The news coverage prompted the FTC and the HHS Office for Civil Rights to open a joint investigation, which culminated in coordinated settlements announced July 27, 2010.
There was no active "attacker" technique in the conventional social-engineering sense: the exposure was a disposal-security failure that created an ongoing, exploitable opportunity for anyone (identity thieves, opportunists, or in this case journalists) to retrieve sensitive records simply by accessing store dumpsters. Rite Aid pharmacies nationwide discarded pharmacy labels, pill bottles, prescription and refill records containing patients' names, addresses, phone numbers, birth dates and prescribing doctors, plus employee/job-applicant paperwork, directly into industrial trash containers located in store parking areas or loading docks that were physically accessible to the public without needing to breach any lock, badge, or system. The FTC's and HHS/OCR's investigations found the root causes were organizational: no adequate written policies for disposing of protected health information, no employee training on proper disposal, no sanctions for employees who ignored proper procedure, and no internal auditing or risk-assessment process to catch and correct the practice across the chain's nearly 4,800 stores.
There was no lure aimed at a human victim; the "tell" here was investigative rather than a scam unraveling. Indianapolis TV station WTHR's "13 Investigates" team (reporters Bob Segall, Jim Hall and photojournalist Bill Ditton) ran a 2006 "Prescription Privacy" probe that checked roughly 65 metro-area pharmacies and found unsecured, readable patient records in open dumpsters at many of them. WTHR then expanded to a roughly 12-city nationwide dumpster tour covering CVS, Walgreens, and Rite Aid pharmacies collectively; WTHR's contemporaneous reporting names Boston, Chicago, Cleveland, Dallas, Denver, Detroit, Louisville, Miami, New Haven (Conn.), Philadelphia, and Phoenix as tour stops, and found readable prescription labels and job applications in unsecured trash at pharmacies nationwide. WTHR's own retrospective coverage specifically cites Phoenix, Denver, Miami, and Detroit (in addition to Indianapolis) among the cities where such dumpster findings recurred, but the FTC's complaint states only that Rite-Aid-specific findings occurred in "at least 7 cities" without itemizing which ones, so it is not confirmed from primary sources that every city on WTHR's broader multi-chain tour (e.g., Cleveland, Louisville) specifically involved documented Rite Aid dumpsters. The video evidence, pharmacy trash sitting in unlocked, publicly reachable industrial containers, is what directly triggered the FTC's and HHS/OCR's investigations; the regulators cited the news coverage itself in their public statements as the origin of the probe.
On July 27, 2010, the FTC and HHS/OCR announced coordinated settlements with Rite Aid Corporation, only the second such joint FTC/HHS action, after CVS Caremark in February 2009. Rite Aid and its 40 affiliated entities agreed to pay $1,000,000 to HHS/OCR to resolve potential HIPAA Privacy Rule violations, with a 3-year corrective action plan (revised disposal policies, workforce training, sanctions policy, internal monitoring, independent third-party compliance assessor). Separately, Rite Aid entered an FTC consent order (FTC File No. 072-3121, Docket No. C-4308) resolving FTC Act Section 5 charges of deceptive privacy claims and unfair security practices; the FTC vote to approve was 5-0, followed by a 30-day public comment period (through August 27, 2010), with the final order issued November 12, 2010 and approved November 22, 2010. The FTC order requires a comprehensive written information security program, accountable personnel, risk assessment and safeguards, service-provider vetting, and independent biennial third-party audits for 20 years (through at least November 12, 2030). No individual identity-theft losses tied to the exposed records were confirmed in the settlement documents; the action was based on the disposal practice and privacy-claim misrepresentation itself, not proven downstream fraud.
This case, alongside CVS Caremark's near-identical 2009 settlement, established that failing to secure protected health information and PII during physical disposal is independently actionable, not merely a hypothetical risk, and that regulators would coordinate across HIPAA (HHS/OCR) and general consumer-protection (FTC Act) authority to police it. It shows that "dumpster diving" risk isn't only about a lone attacker rummaging through trash for a specific target; large-scale, systemic disposal failures can expose an entire national customer and employee base simultaneously, and can be uncovered by journalists as easily as by criminals. It underscores that companies making public privacy promises ("we protect your health information") can be held to those promises as a matter of law when their actual physical handling practices contradict them, and that the fix, proper training, sanctions, monitoring, and independent audits, has to be operationalized at store level, not just written into corporate policy.
The case became a template for U.S. regulators pairing HIPAA and FTC Act enforcement over paper-record disposal. The FTC order mandated: a comprehensive written information security program covering both paper and electronic personal information; designation of accountable employees; documented risk assessment covering physical/paper handling as an explicit control category, not just IT systems; employee training and enforced sanctions for improper disposal; vetting and contractual safeguards for any service providers (e.g., waste haulers); and independent third-party audits every two years for 20 years (order runs through at least November 12, 2030). The parallel HHS corrective action plan (3 years) required revised written disposal policies/procedures, workforce training, a sanctions policy for violators, internal monitoring, and an independent compliance assessor reporting to HHS. Practically, organizations handling patient or employee PII were pushed toward locked/shredded disposal bins, cross-cut shredding or incineration of labels and prescriptions before disposal, restricted dumpster access, and documented chain-of-custody for records destruction: the standard defenses against dumpster-diving exposure. The case (the second joint FTC/HHS action after CVS Caremark in Feb 2009) established that discarding identifiable patient/employee records in publicly accessible trash is itself an actionable, sanctionable privacy and security failure even absent proof any specific individual's data was misused.
A Kansas City TV station found intact consumer home-loan applications with Social Security and account numbers tossed in a title…
A nation-state cyberweapon crossed an air gap into Iran's Natanz nuclear facility on infected USB drives carried in by trusted…
Two unencrypted TD Bank backup tapes carrying data on 260,000 customers vanished in transit between Massachusetts offices in 2012; a…