CVS ends Web site feature over privacy concerns
An unauthorized person could track other customers' purchases by e-mail
June 23, 2005 12:00 PM ETComputerworld -
Retail drugstore chain CVS Corp. has temporarily disabled a feature on its Web site that allowed an unauthorized person to improperly obtain customer purchase records via e-mail.
In a statement yesterday, Woonsocket, R.I.-based CVS acknowledged that it had disabled a feature that allows registered users of its CVS ExtraCare loyalty cards to track purchases made under "flexible spending accounts" (FSA) set up through their employers. The loyalty cards offer discounts to shoppers who register for the cards and allow CVS to gather information about their purchases.
More than 50 million customers use its ExtraCare loyalty cards, CVS said.
The problem with the ExtraCare cards, said Katherine Albrecht, founder and director of the Web-based consumer group CASPIAN (Consumers Against Supermarket Privacy Invasion and Numbering), is that anyone can access a cardholder's purchase records if they have the user's 11-digit account number, ZIP code and the first three letters of their last name. Such scenarios could occur, she said, when an ExtraCare cardholder takes his car to a mechanic and hands over their keys -- including the ExtraCare key ring card that has a printed account number on it.
As part of its ExtraCare FSA records, CVS collects and stores data about a cardholder's purchases, including the time and date of the purchase, items purchased, store location, universal product code and the customer's name, Albrecht said. Cardholders could go to the CVS ExtraCare Web page and request a copy of their FSA purchases via e-mail, but the feature was disabled this week.
"The biggest issue is why does CVS have all this data on the site in the first place?" Albrecht said.
CVS didn't respond to several requests for comment. But in its statement, the company said the online feature was designed to provide customers with "easy access to their own purchase information for purposes of filing FSA claims for over-the-counter items."
The information on the Web site doesn't include prescription purchases, nor does it include Social Security numbers or credit card numbers that could lead to identity theft, the company said.
"The security procedures implemented to protect information ... accessed for FSA-related customer needs have been carefully designed, and we believe are effective," the statement said. "We have received absolutely no indication from any of our ExtraCare cardholders that this information had been improperly accessed."
CVS said it won't bring the FSA feature back until it has created "additional security hurdles for accessing this purchase information" online.
CASPIAN is a grass-roots consumer group that has opposed retail surveillance efforts since 1999.
Additional Resources



Learn the important issues you must consider before starting your next mobility initiative. Get your mobility white paper from IDC now, compliments of Sybase.
White Papers & Webcasts
Accelerate SSL Encrypted Applications
The amount of SSL traffic is growing in the enterprise. Because it is encrypted, it cannot be properly controlled and accelerated. Blue Coat...
Data Protection and Disaster Recovery with iSCSI and VMware
Data protection and disaster recovery are top of mind for any IT manager, and the challenges of complexity and cost remain as obstacles....
ESG Lab Field Audit
Many companies have successfully implemented Riverbed WAN optimization solutions within their Cisco networks. This ESG Lab Field Audit document explores the success that...
Usability Is Everything
Learn what sets Workday's HR and Payroll solutions apart from the competition....
Shape Your Apps Strategy to Reflect New SaaS Licensing and Pricing Trends
Why are smart companies choosing software-as-a-service? Find out in the complimentary Forrester Research report...
The Value of Real SaaS at Workday
Cost savings, speed to value, and innovation brought to the enterprise by Workday's software-as-a-service solutions for HR and Payroll....
Natural User Interface for Enterprise Applications
Learn how a revolutionary user interface can make a complex enterprise application so intuitive even casual users can jump right in....
SaaS at Flextronics, Inc.
Dave Smoley, CIO of Flextronics, discusses the real value of software-as-a-service and why he chose Workday for his HR solution....
A Truly Global HCM System
Learn about a system built with advanced object-oriented technology that support multi-national requirements and costs less to implement, maintain and upgrade....
Why Compliance Pays
This OnDemand webcast explores the relationship that firms with best compliance records have higher revenue, greater customer retention, lower financial losses from data...
Subscribe to Computerworld
