Case Library / Physical Social Engineering (Tailgating & Baiting) / Rite Aid Pharmacy Dumpster Disposal of Patient and Employee Records

Rite Aid Pharmacy Dumpster Disposal of Patient and Employee Records

TV investigative reporters filmed Rite Aid pharmacy dumpsters nationwide overflowing with readable prescription labels, patient records and job applications, leading to a joint FTC/HHS settlement including a $1 million HIPAA payment and a 20-year FTC security-audit order.

Share:

Reviewed by the Social Engineering Examples team.

What Happened

Beginning with a 2006 Indianapolis TV investigation and expanding through 2007-2008, local news teams across the United States, most notably WTHR-13 "13 Investigates" in Indianapolis, filmed open, publicly accessible dumpsters behind Rite Aid pharmacy stores containing pharmacy labels, pill bottles, prescription and refill records bearing patients' names, addresses, phone numbers, birth dates and prescribing physicians, along with employment applications and other employee PII. The FTC's complaint states such findings were reported in "at least 7 cities throughout the United States" but does not itemize them; WTHR's own published accounts of its broader multi-chain investigation (covering CVS, Walgreens, and Rite Aid dumpsters collectively, not Rite Aid alone) cite Phoenix, Denver, Miami, Detroit, and Philadelphia in addition to the originating Indianapolis probe, with the exact cities where Rite Aid dumpsters specifically were documented not itemized in any accessible primary or secondary source. The exposure was not the result of a hack or a con; it was a systemic failure to secure sensitive paper records before physical disposal at scale, across a chain of nearly 4,800 stores. The news coverage prompted the FTC and the HHS Office for Civil Rights to open a joint investigation, which culminated in coordinated settlements announced July 27, 2010.

How the Attack Worked

There was no active "attacker" technique in the conventional social-engineering sense: the exposure was a disposal-security failure that created an ongoing, exploitable opportunity for anyone (identity thieves, opportunists, or in this case journalists) to retrieve sensitive records simply by accessing store dumpsters. Rite Aid pharmacies nationwide discarded pharmacy labels, pill bottles, prescription and refill records containing patients' names, addresses, phone numbers, birth dates and prescribing doctors, plus employee/job-applicant paperwork, directly into industrial trash containers located in store parking areas or loading docks that were physically accessible to the public without needing to breach any lock, badge, or system. The FTC's and HHS/OCR's investigations found the root causes were organizational: no adequate written policies for disposing of protected health information, no employee training on proper disposal, no sanctions for employees who ignored proper procedure, and no internal auditing or risk-assessment process to catch and correct the practice across the chain's nearly 4,800 stores.

The Lure & the Tell

There was no lure aimed at a human victim; the "tell" here was investigative rather than a scam unraveling. Indianapolis TV station WTHR's "13 Investigates" team (reporters Bob Segall, Jim Hall and photojournalist Bill Ditton) ran a 2006 "Prescription Privacy" probe that checked roughly 65 metro-area pharmacies and found unsecured, readable patient records in open dumpsters at many of them. WTHR then expanded to a roughly 12-city nationwide dumpster tour covering CVS, Walgreens, and Rite Aid pharmacies collectively; WTHR's contemporaneous reporting names Boston, Chicago, Cleveland, Dallas, Denver, Detroit, Louisville, Miami, New Haven (Conn.), Philadelphia, and Phoenix as tour stops, and found readable prescription labels and job applications in unsecured trash at pharmacies nationwide. WTHR's own retrospective coverage specifically cites Phoenix, Denver, Miami, and Detroit (in addition to Indianapolis) among the cities where such dumpster findings recurred, but the FTC's complaint states only that Rite-Aid-specific findings occurred in "at least 7 cities" without itemizing which ones, so it is not confirmed from primary sources that every city on WTHR's broader multi-chain tour (e.g., Cleveland, Louisville) specifically involved documented Rite Aid dumpsters. The video evidence, pharmacy trash sitting in unlocked, publicly reachable industrial containers, is what directly triggered the FTC's and HHS/OCR's investigations; the regulators cited the news coverage itself in their public statements as the origin of the probe.

Outcome

On July 27, 2010, the FTC and HHS/OCR announced coordinated settlements with Rite Aid Corporation, only the second such joint FTC/HHS action, after CVS Caremark in February 2009. Rite Aid and its 40 affiliated entities agreed to pay $1,000,000 to HHS/OCR to resolve potential HIPAA Privacy Rule violations, with a 3-year corrective action plan (revised disposal policies, workforce training, sanctions policy, internal monitoring, independent third-party compliance assessor). Separately, Rite Aid entered an FTC consent order (FTC File No. 072-3121, Docket No. C-4308) resolving FTC Act Section 5 charges of deceptive privacy claims and unfair security practices; the FTC vote to approve was 5-0, followed by a 30-day public comment period (through August 27, 2010), with the final order issued November 12, 2010 and approved November 22, 2010. The FTC order requires a comprehensive written information security program, accountable personnel, risk assessment and safeguards, service-provider vetting, and independent biennial third-party audits for 20 years (through at least November 12, 2030). No individual identity-theft losses tied to the exposed records were confirmed in the settlement documents; the action was based on the disposal practice and privacy-claim misrepresentation itself, not proven downstream fraud.

Why It Matters

This case, alongside CVS Caremark's near-identical 2009 settlement, established that failing to secure protected health information and PII during physical disposal is independently actionable, not merely a hypothetical risk, and that regulators would coordinate across HIPAA (HHS/OCR) and general consumer-protection (FTC Act) authority to police it. It shows that "dumpster diving" risk isn't only about a lone attacker rummaging through trash for a specific target; large-scale, systemic disposal failures can expose an entire national customer and employee base simultaneously, and can be uncovered by journalists as easily as by criminals. It underscores that companies making public privacy promises ("we protect your health information") can be held to those promises as a matter of law when their actual physical handling practices contradict them, and that the fix, proper training, sanctions, monitoring, and independent audits, has to be operationalized at store level, not just written into corporate policy.

Defenses

The case became a template for U.S. regulators pairing HIPAA and FTC Act enforcement over paper-record disposal. The FTC order mandated: a comprehensive written information security program covering both paper and electronic personal information; designation of accountable employees; documented risk assessment covering physical/paper handling as an explicit control category, not just IT systems; employee training and enforced sanctions for improper disposal; vetting and contractual safeguards for any service providers (e.g., waste haulers); and independent third-party audits every two years for 20 years (order runs through at least November 12, 2030). The parallel HHS corrective action plan (3 years) required revised written disposal policies/procedures, workforce training, a sanctions policy for violators, internal monitoring, and an independent compliance assessor reporting to HHS. Practically, organizations handling patient or employee PII were pushed toward locked/shredded disposal bins, cross-cut shredding or incineration of labels and prescriptions before disposal, restricted dumpster access, and documented chain-of-custody for records destruction: the standard defenses against dumpster-diving exposure. The case (the second joint FTC/HHS action after CVS Caremark in Feb 2009) established that discarding identifiable patient/employee records in publicly accessible trash is itself an actionable, sanctionable privacy and security failure even absent proof any specific individual's data was misused.

Sources
Attack Chain & Defense
The sequence the attacker ran
How it could have been stopped
1
Location reconnaissance: Identifying pharmacy locations whose outdoor trash containers sit unlocked and reachable from a public parking lot or loading dock, something this case shows required no special tools or technical skill, just walking a store's back lot, the same low-effort canvassing method WTHR's reporters used openly across dozens of drugstores.
Countering Stage 1: Removing public accessibility to pharmacy trash, locked or enclosed dumpsters, gated compounds, and no-trespassing signage, eliminates the payoff from location scouting; this is the physical hardening step Rite Aid, CVS, and Walgreens all adopted after the investigations (locked bins, brick enclosures, warehouse-return programs).
2
Physical retrieval (dumpster diving): Physically pulling trash bags from the open industrial container to search for readable pharmacy labels, pill bottles, prescription and refill records, and employment applications, an act that, per the FTC's complaint, required no lock-picking, badge, or system breach because Rite Aid's own disposal practice left the material in clear, unshredded text.
Countering Stage 2: Rendering the paper unreadable before it ever reaches the dumpster, cross-cut shredding or incineration of labels and prescriptions at the point of disposal, defeats retrieval even if a container is accessed; this was the core requirement of both the FTC order and the HHS corrective action plan.
3
Profiling from retrieved records: Sorting the recovered paperwork into a usable profile on a specific patient or employee, name, address, phone number, date of birth, medication, and prescribing physician, detailed enough to convincingly impersonate that person or fabricate a plausible pharmacy-related pretext.
Countering Stage 3: Written disposal policies, mandatory employee training, and enforced sanctions for workers who skip proper destruction, all of which the FTC and HHS found Rite Aid lacked, reduce how often a usable, information-rich document ever reaches the trash intact.
4
In-person pretext execution: Approaching the target directly using the harvested details for credibility, as in the Bloomington, Indiana case cited in WTHR's reporting, where a man posed as a pharmacy technician claiming a prescription-filling error to convince a 76-year-old victim to hand over her Oxycontin.
Countering Stage 4: In-person pretext contact exploiting inside-looking knowledge is hard to intercept at the moment it happens; the realistic control sits with the pharmacy and patient verifying any unsolicited request to hand over medication or personal information through a known, independently-dialed pharmacy number rather than trusting a visitor who already seems to know prescription details.
5
Objective completion (exploitation): Obtaining the controlled substance or other value directly from the deceived victim, or separately reusing the harvested PII for identity theft or fraud elsewhere, completing the actor's objective without ever breaching a Rite Aid computer system or facility.
Countering Stage 5: Once the deception succeeds and medication or data changes hands, the loss is largely realized; the residual controls are rapid victim and pharmacy reporting to police, prescription drug monitoring programs, and credit/identity monitoring so any resulting fraud or diversion is caught quickly rather than a control that reverses the handoff itself.
Quick Facts
Victim
Rite Aid Corporation (and, downstream, the patients and employees whose prescription, personal, and application records were exposed to the public)
Location
Multiple U.S. cities nationwide. The FTC's complaint against Rite Aid states that "in late 2006 and continuing into 2007 and 2008, television stations and other media outlets reported finding personal information in unsecured dumpsters used by Rite Aid pharmacies in at least 7 cities throughout the United States," but the complaint does not itemize which cities, and that exact list is not quoted in any accessible secondary source. WTHR's own published accounts of its broader, multi-chain (CVS/Walgreens/Rite Aid) dumpster investigation identify Indianapolis IN as the originating probe, with the roughly 12-city nationwide follow-up tour (covering all three chains collectively, not Rite Aid alone) reported as running through Boston, Chicago, Cleveland, Dallas, Denver, Detroit, Louisville, Miami, New Haven CT, Philadelphia, and Phoenix; WTHR's later retrospective reporting specifically calls out Phoenix, Denver, Miami, and Detroit (alongside Philadelphia in earlier coverage) among the recurring dumpster-finding locations. Because the FTC complaint itself does not name cities, Cleveland and Louisville, while part of WTHR's general multi-chain tour, are not independently confirmed as Rite-Aid-specific documented sites. Settlement covered Rite Aid's nearly 4,800 (per the FTC complaint, "approximately 4,900") retail pharmacies chain-wide (headquartered Camp Hill, Pennsylvania).
Date
Conduct discovered/reported 2006-2008 (originating with WTHR's 2006 Indianapolis investigation and continuing media exposes through 2007-2008); joint FTC/HHS settlement announced July 27, 2010; FTC final order issued November 12, 2010, approved November 22, 2010
Impact
$1,000,000 paid by Rite Aid Corporation to HHS/OCR under the HIPAA resolution agreement (July 27, 2010). The FTC consent order imposed no separate civil monetary penalty but required a 20-year compliance program with independent biennial third-party security assessments (through at least November 12, 2030), a substantial ongoing compliance cost not separately quantified in public filings.
Status
Confirmed
Case Type
Real-World Incident
Sector
Healthcare, Retail & E-commerce
Related

Related Cases

Nations Title Agency / Nations Holding Company Dumpster Diving and Hack Exposure (FTC Settlement, 2006)

A Kansas City TV station found intact consumer home-loan applications with Social Security and account numbers tossed in a title…

Incident 2006Read →

Stuxnet: USB-borne sabotage of Iran's air-gapped Natanz enrichment plant

A nation-state cyberweapon crossed an air gap into Iran's Natanz nuclear facility on infected USB drives carried in by trusted…

Incident 2010Read →

TD Bank Lost Unencrypted Backup Tapes - Multistate and Massachusetts AG Settlements

Two unencrypted TD Bank backup tapes carrying data on 260,000 customers vanished in transit between Massachusetts offices in 2012; a…

Incident 2012Read →