Back to Exposure Report
Healthcare June 17, 2026 United States

One Medical (Amazon)

ShinyHunters claims 8.8 terabytes of patient data from Amazon's healthcare subsidiary. Legacy systems from a 2021 acquisition become the attack surface.

Patient namesDates of birthInsurance informationDiagnosesTreatment notesClinical records
1

What happened?

Between June 8 and June 11, 2026, an unauthorized third party accessed a file storage system containing legacy patient data from One Medical Seniors (formerly Iora Health). One Medical identified the breach on June 13. ShinyHunters posted the claim to their dark web site on June 17, demanding negotiations by June 22 before publishing.

One Medical operates over 250 clinics serving 830,000+ patients. Amazon acquired the company for $3.9 billion in 2023. The breached system contained archived data from Iora Health, which One Medical acquired in 2021 for $2.1 billion.

2

What data was actually inside?

ShinyHunters claims 8.8 terabytes. Samples posted to dark web forums have been independently verified as authentic patient records. The confirmed data types include patient names, dates of birth, insurance information, diagnoses, and treatment notes.

The breach affected former Iora Health/One Medical Seniors patients in Atlanta, Cape Cod, Charlotte, Piedmont Triad, Denver, Houston, Phoenix, Tucson, and Seattle. This is senior-focused primary care—the patient population skews older and the medical records are comprehensive. Chronic conditions, long treatment histories, detailed health documentation.

3

Who gets hurt and how?

Senior patients whose complete medical histories are now in attacker hands. Names and dates of birth enable identity theft. Insurance information enables medical identity fraud—fake claims, prescription fraud, benefits exhaustion. Diagnosis information is permanent—you cannot change your medical history.

This population is vulnerable. Older patients are prime targets for healthcare-themed phishing and phone scams. An attacker who knows your doctor's name, your diagnoses, and your insurance provider can construct highly convincing fraud attempts. The harm extends beyond financial loss to emotional distress and erosion of trust in healthcare systems.

4

What did they think they were doing right?

One Medical emphasized that their main electronic medical record system was not compromised. The breach was "limited to the file storage platform" containing "legacy data." The core clinical systems remain secure. Current operations continue normally.

But "legacy data" is still patient data. Protected health information doesn't lose its protection because it's old or archived. The file storage system that was breached still fell under HIPAA requirements. The distinction between legacy and current systems matters for business continuity—it doesn't matter at all for the patients whose records were stolen.

5

What did they not know about their own data?

When Amazon acquired One Medical, they inherited a complex data landscape. One Medical had already acquired Iora Health. Each acquisition brought patient databases, file storage systems, and archived records. The breached file storage contained data from a company that was acquired five years ago.

8.8 terabytes is a substantial volume of healthcare data. Did anyone at Amazon or One Medical know exactly what was in that legacy file storage? Did they inventory the PHI accumulated across multiple acquisitions? The attack surface was created by corporate transactions—M&A integration rarely includes comprehensive data inventory of what sensitive information came with the deal.

If you handle patient data, could you identify within 24 hours exactly which records were accessed in a breach?

6

What does attribution look like the morning after?

HIPAA requires notification within 60 days of discovery for breaches affecting 500+ individuals. This breach spans nine geographic markets. Each affected patient must be individually notified. The volume of 8.8 terabytes suggests substantial review is needed to determine exactly whose records were accessed.

Amazon's involvement elevates the visibility. HHS OCR will investigate. State attorneys general may initiate inquiries. Class action attorneys are already advertising. The operational burden of HIPAA breach response—forensic investigation, individual notification, credit monitoring, regulatory reporting—begins immediately and extends for months.

7

What would have changed the outcome?

Comprehensive PHI inventory across acquired entities—knowing exactly what patient data existed in legacy systems before attackers found it.

Healthcare acquisitions create data inheritance. Iora Health's patients became One Medical's patients became Amazon's responsibility. Every file storage system, every archived database, every legacy platform from every acquisition contains PHI that must be secured. The organizations that survive these incidents are the ones that inventoried their inherited data and applied retention policies before the breach, not after.

One Medical found out the hard way.

Your team could spend the next 6 months rebuilding systems, notifying customers, and answering legal questions. Or you could spend 24 hours finding out what's actually at risk.