June 13, 2026: One Medical—the Amazon-owned primary-care chain—confirmed what ShinyHunters had been advertising on its leak site: someone got into patient data. The twist is where the data lived. Not the live clinics most members use today, but a legacy archive for One Medical Seniors patients, the brand built on Iora Health, which Amazon's subsidiary acquired in 2021.
What One Medical confirmed
Per HIPAA Journal reporting on the company's breach notice, One Medical detected unauthorized access on June 13, 2026, secured the affected third-party file storage platform, and determined an intruder was inside between June 8 and June 11.
The storage system held archived demographic and clinical records for Iora Health / One Medical Seniors patients in:
- Atlanta
- Cape Cod
- Charlotte and the Piedmont Triad
- Denver
- Houston
- Phoenix and Tucson
- Seattle
One Medical was explicit about scope: no other clinics, services, or the main One Medical EMR were accessed in this incident. That matters if you are a standard One Medical member who never used the seniors-focused Iora-style program—you may not be in this dataset at all.
What was exposed
The company has not yet published a field-by-field matrix for every patient, but confirmed the archive contained demographic information and clinical records for the legacy seniors population. In practice that usually means names, contact details, dates of birth, insurance identifiers, and care documentation—exactly the mix that fuels Medicare fraud and medical identity theft.
A victim count has not been disclosed as of catalog time. One Medical said data review and notifications were underway.
ShinyHunters and the 8.8 TB claim
Days before the confirmation, ShinyHunters listed One Medical claiming 8.8 terabytes stolen and set a June 22, 2026 negotiation deadline. One Medical has not attributed the attack to ShinyHunters or verified the actor's volume figure. Treat the terabyte headline as unverified marketing until samples or regulatory filings substantiate it—the company's own description centers on a legacy archival platform, not an entire Amazon health stack.
Who should act
Priority audience: anyone who received care through Iora Health or One Medical Seniors in the listed metros, especially older adults on Medicare Advantage-style senior primary care.
If that is you:
- Watch Explanation of Benefits statements for doctor visits, labs, or durable medical equipment you never received.
- Freeze credit if the notice later cites Social Security numbers—free at all three bureaus.
- Enable MFA on your One Medical portal and the email tied to it.
- Reject "Medicare verification" calls that cite real appointment history—call One Medical on a published number.
Why this breach still matters
One Medical sits inside Amazon's healthcare experiment, but the failure mode is boring and common: forgotten legacy data in a third-party bucket. Acquired practices drag archives forward for years; attackers hunt the storage vendors and flat files that production EMRs no longer touch. Seniors' clinical histories are high-value fraud fuel—and you cannot "reset" a diagnosis someone else plants in your chart.
Canonical record
One Medical 2026 breach on BreachHistory.
Sources: HIPAA Journal, DataBreaches.net.