2026 One Medical — confirmed breach; legacy One Medical Seniors/Iora archive accessed (Jun)
Data compromised
Legacy Iora Health/One Medical Seniors demographic and clinical records for patients in Atlanta, Cape Cod, Charlotte, Piedmont Triad, Denver, Houston, Phoenix, Tucson, and Seattle per company notice—victim count not yet disclosed; ShinyHunters actor volume unverified
Technical writeup
Verified breach — disclosed June 17, 2026. Amazon-owned One Medical confirmed an unauthorized third party accessed a third-party file storage platform containing archived legacy data for One Medical Seniors patients (formerly Iora Health, acquired 2021). One Medical discovered the activity June 13, 2026, secured the system, and determined access occurred June 8–11, 2026. The company stated the incident was limited to that archival platform—not other clinics, services, or the main One Medical EMR—and contained demographic information and clinical records for Iora/One Medical Seniors patients in nine U.S. metro areas. TechTarget reported June 22 that ShinyHunters claimed 8.8 terabytes stolen with a June 22 deadline; One Medical has not attributed the attack to the group or verified the actor volume. Data review and victim notifications were ongoing at reporting time with no public count. BreachHistory indexes recordsAffected 0 until company or regulator attestation.
Root cause
Unauthorized third party accessed third-party file storage holding archived One Medical Seniors (formerly Iora Health) patient data June 8–11, 2026; discovered June 13; parallel ShinyHunters 8.8TB extortion claim
References
- https://www.onemedical.com/blog/newsworthy/one-medical-seniors-takes-swift-action-to-secure-patient-data/
- https://www.techtarget.com/healthtechsecurity/news/366644917/ShinyHunters-threatens-to-leak-One-Medical-Seniors-patient-data/
- https://www.hipaajournal.com/one-medical-data-breach/
- https://www.ransomware.live/id/QW1hem9uIG93bmVkIE9uZU1lZGljYWwuY29tQHNoaW55aHVudGVycw