Texas Oncology, one of the largest community-based oncology practices in the country, was affected by a cybersecurity incident involving its parent company, McKesson. The incident, discovered on August 25, 2026, reportedly compromised sensitive patient information belonging to individuals treated through Texas Oncology and other McKesson-affiliated oncology practices.
Healthcare providers and the companies that support them are entrusted with highly sensitive medical and personal information, and they bear a responsibility to protect that data and to promptly notify patients when it is compromised.
Texas Oncology’s Data Breach Investigation
According to a notice published by McKesson and reporting by the HIPAA Journal, a cybersecurity incident was identified involving third-party applications used by the company. McKesson disclosed the incident in a Form 8-K filing with the U.S. Securities and Exchange Commission, confirming that data was exfiltrated from its systems, though the company said the full extent of the data theft had not yet been determined at the time of disclosure. A cybercriminal group known as ShinyHunters has claimed responsibility, listing McKesson on its data leak site and asserting that approximately 284 million records were taken, a figure McKesson has said relates to rows of raw data rather than unique patients.
McKesson stated that the incident appears to involve a subset of customers connected to its Oncology & Multispecialty business unit, which includes Texas Oncology, as well as its Medical-Surgical business unit. According to reporting from BleepingComputer, which said it was in contact with the threat actor, roughly one terabyte of data was reportedly taken between August 21 and August 25, 2026, and a ransom demand exceeding $55 million was made. The group has claimed the stolen data includes patient names, contact information, Social Security numbers, dates of birth, medical record numbers, Medicaid numbers, medication and allergy information, diagnoses, and appointment details, reportedly drawn from McKesson’s Salesforce and Snowflake environments.
McKesson has said it activated incident response protocols and engaged outside cybersecurity experts to investigate the scope of the intrusion and to determine what data was affected. The company has stated that it does not believe customers need to take any immediate action on their own systems and that its distribution network continues to operate. However, patients of Texas Oncology and other affected practices are a separate group from McKesson’s corporate customers, and any patient whose medical and personal information was exposed may be entitled to notice and, potentially, compensation regardless of any operational statements McKesson has made about its business systems.
Because this incident involves a healthcare provider network and reportedly includes medical record numbers, diagnoses, and other protected health information alongside Social Security numbers, it carries an elevated risk of both medical identity theft and traditional financial fraud for those affected.
When Did This Breach Occur?
McKesson stated that the cybersecurity incident was first detected on August 25, 2026. According to reporting from BleepingComputer, the underlying data exfiltration is believed to have occurred over several days, between approximately August 21 and August 25, 2026. McKesson publicly announced the incident on August 28, 2026, and provided a further update on August 29, 2026. As of this writing, individual patient notification letters from Texas Oncology have not been widely confirmed as sent, and the timeline for direct notice to affected patients may follow in the weeks after the initial corporate disclosure.
What Information Was Breached?
The threat actor claiming responsibility has stated that the exposed data includes patient names, addresses, dates of birth, phone numbers, Social Security numbers, medical record numbers, Medicaid numbers, medication and allergy information, diagnoses, and appointment information. McKesson has confirmed that data was exfiltrated but has not yet issued a complete, confirmed list of every data type involved for every affected individual. Patients who receive a formal notification letter from Texas Oncology or McKesson should review it carefully, as it will specify the categories of information confirmed to be involved in their individual case.
What You Can Do
If you are a patient of Texas Oncology or believe your information may have been involved in this incident, consider the following steps:
- Monitor your credit reports and financial accounts closely for any unfamiliar or suspicious activity.
- Consider placing a fraud alert or credit freeze with the three major credit bureaus: Equifax, Experian, and TransUnion.
- Watch for signs of medical identity theft, such as unfamiliar medical bills, insurance claims, or Medicaid activity you did not authorize.
- Be cautious of phishing emails, texts, or phone calls referencing Texas Oncology, McKesson, or this data breach.
- Keep any notification letter or communication you receive from Texas Oncology or McKesson, as it may be useful if you decide to pursue legal action.
File a Data Breach Lawsuit Against Texas Oncology
Healthcare providers and their corporate partners that collect and store sensitive medical and personal information are expected to maintain reasonable safeguards to protect that data from unauthorized access. When a data breach occurs, patients whose information was exposed may have legal options, including the ability to pursue compensation through a class action lawsuit.
Contact us at Class Action U, where we’ll connect you with a lawyer skilled in class action lawsuits. If you’ve been contacted about this breach, received notice, or discovered you were impacted, fill out our quick, easy, and secure form to sign up. There is no cost to reach out to our legal partner and no obligation after speaking with someone from our team.