← McKesson

2014 McKesson (PST Services) — patient RCM data reachable via Google dorking; >10k individuals (Dec–Apr)

2014 10.8K records affected Share on X

Data compromised

HIPAA-regulated billing and clinical-administrative composites

Technical writeup

PST Services, then described in trade press as a McKesson revenue-cycle subsidiary servicing physician groups, misconfigured an Internet-facing archive such that PHI—including names, insurance cards, diagnosis codes, billing details, and selective SSNs—became retrievable with search-engine queries between December 1, 2013 and April 17, 2014. Becker’s Hospital Review cataloged >10,000 affected patients across anchor practices like 24 On Physicians and Midwest Orthopaedic Center. DataBreaches.net reproduced the timeline and exposure mechanism as part of its breach archive.

Root cause

Publicly indexed storage / missing access controls on revenue-cycle document repositories

References