2014 McKesson (PST Services) — patient RCM data reachable via Google dorking; >10k individuals (Dec–Apr)
Data compromised
HIPAA-regulated billing and clinical-administrative composites
Technical writeup
PST Services, then described in trade press as a McKesson revenue-cycle subsidiary servicing physician groups, misconfigured an Internet-facing archive such that PHI—including names, insurance cards, diagnosis codes, billing details, and selective SSNs—became retrievable with search-engine queries between December 1, 2013 and April 17, 2014. Becker’s Hospital Review cataloged >10,000 affected patients across anchor practices like 24 On Physicians and Midwest Orthopaedic Center. DataBreaches.net reproduced the timeline and exposure mechanism as part of its breach archive.
Root cause
Publicly indexed storage / missing access controls on revenue-cycle document repositories