McKesson, the US pharmaceutical distribution and healthcare technology group, continues to investigate the incident it disclosed in an SEC Form 8-K, telling regulators on 8 September that information potentially exfiltrated likely included names, addresses, phone numbers, email addresses, patient IDs and dates of birth alongside health insurance details such as Medicaid and Medicare numbers, medical information including diagnoses, medications, test results and medical images, billing and payment information, and Social Security numbers. The number of affected individuals is still undetermined, but Troy Hunt of HaveIBeenPwned has reported that the data allegedly stolen included 6.4 million unique email addresses drawn from marketing campaigns, patients, staff and other individuals. ShinyHunters claimed responsibility and asserted it had obtained 284 million rows of raw patient data — a figure that, as HIPAA Journal notes, was unlikely to represent 284 million unique patients and now looks closer to a row count than a victim count. McKesson has engaged third-party cybersecurity experts, implemented additional controls and is monitoring for related activity. The gap between the 284 million headline figure and the 6.4 million unique addresses established by independent analysis is the reason this is written as a confirmed breach with an open scale question rather than a 284-million-record event.
| Attribute | Detail |
|---|---|
| **Sector | Healthcare |
| **Date | 2026-09-20 |
| **Source | HIPAA Journal |
| **Reliability | Tier 2 |