One Medical, the Amazon-owned primary care provider, has notified more than 153,000 individuals that their personal information may have been exposed after an unauthorized party accessed a legacy third-party file storage system. The affected system held archived records inherited through One Medical’s 2021 acquisition of Iora Health.
Companies that hold sensitive patient information, whether generated by their own current operations or inherited through a corporate acquisition, have a legal and ethical responsibility to secure that data for as long as they retain it.
One Medical’s Data Breach Investigation
According to a notice filed with the U.S. Department of Health and Human Services Office for Civil Rights, One Medical Group, Inc. reported that an unauthorized party gained access to a third-party file storage system between approximately June 8 and June 11, 2026. The company said it discovered the intrusion on June 13, 2026, and launched an investigation with the help of outside cybersecurity specialists. The system in question was not part of One Medical’s current, active electronic medical record platform. Instead, it was a legacy archive holding demographic and clinical records for patients of Iora Health, a primary care group Amazon-owned One Medical acquired in a $2.1 billion deal completed in September 2021. Reporting has indicated the archived data may relate to former Iora clinic locations in cities including Atlanta, Denver, Houston, Phoenix, Tucson, and Seattle, as well as patients in Massachusetts and North Carolina.
News outlets have reported that a data extortion group calling itself ShinyHunters claimed responsibility for the intrusion and added One Medical to its dark web leak site, asserting that it had obtained roughly 8.8 terabytes of data and threatening to publish the files unless a ransom was paid. As of this writing, the group’s claims about the scope of the stolen data have not been independently verified by One Medical or by federal regulators, and the company has stated that its current clinics, services, and electronic medical record system were not affected by the incident.
Incidents like this one illustrate a recurring problem in healthcare cybersecurity: legacy systems inherited through mergers and acquisitions are frequently left under-monitored long after the deal that brought them into a company’s environment has closed. Security researchers who have reviewed this incident have noted that the compromised storage system had effectively been carried through three separate corporate transitions, from Iora Health’s original ownership, through One Medical’s 2021 acquisition, to Amazon’s subsequent $3.9 billion purchase of One Medical in 2023, without necessarily receiving the same level of ongoing security review as a company’s primary, active systems.
Under the Health Insurance Portability and Accountability Act, a healthcare organization’s obligation to safeguard protected health information does not pause or transfer away simply because the data originated with a company that has since been acquired, merged, or restructured. Federal regulators require covered entities like One Medical to conduct risk assessments across all systems that store electronic protected health information, including data inherited from prior corporate owners and information held by third-party vendors and business associates. When that obligation is not fully met, archived records from years-old clinical relationships can remain exposed long after patients might reasonably assume the information had been properly secured or disposed of.
Breaches involving archived demographic and clinical data are also attractive targets for cybercriminals because they often combine multiple categories of information, such as names, contact details, dates of birth, and treatment-related records, into a single compromised dataset. That kind of combination can be more valuable on the black market and more useful for identity theft or targeted phishing than a single data point on its own, which is part of why organizations that store this type of information face outsized reporting obligations when a breach occurs.
One Medical has stated that it is notifying affected individuals directly and is providing more information through a dedicated notice posted on its own website. Regulatory investigations into breaches of this size, particularly those affecting more than 500 individuals, typically remain open with the HHS Office for Civil Rights for an extended period while the agency reviews the company’s security practices and its response to the incident.
When Did This Breach Occur?
One Medical reported that unauthorized access to the affected third-party file storage system occurred between approximately June 8, 2026, and June 11, 2026. The company says it identified the unauthorized access on June 13, 2026, and subsequently launched an investigation. The breach was formally reported to the HHS Office for Civil Rights on July 17, 2026, with 153,174 individuals listed as affected in that filing.
What Information Was Breached?
One Medical has described the exposed data as archived demographic and clinical records tied to former patients of Iora Health, the primary care group it acquired in 2021. The company has not published an itemized, universal list of every specific data element involved. Demographic and clinical records of this kind can typically include information such as patient names, contact information, dates of birth, and details related to medical care or treatment history, though the exact scope may vary by individual. One Medical’s current, active electronic medical record system was not affected by this incident.
What You Can Do
If you have received a notification letter from One Medical, or believe you may have been a patient of an Iora Health clinic prior to 2021, consider taking the following steps:
- Read any notification you receive carefully and follow the specific guidance it provides.
- Monitor your financial accounts, insurance statements, and credit reports for unfamiliar activity.
- Consider placing a fraud alert or credit freeze with the major credit bureaus.
- Be cautious of unexpected calls, texts, or emails claiming to be from a healthcare provider or insurer asking you to verify personal information.
- Keep any documentation you receive about the breach in case it is needed later.
File a Data Breach Lawsuit Against One Medical
If you were notified that your personal or medical information was compromised in the One Medical data breach, you may have legal options available to you. Companies that store sensitive patient data, including records inherited through a corporate acquisition, are expected to maintain reasonable safeguards to protect that information for as long as they hold it.
Contact us at Class Action U, where we’ll connect you with a lawyer skilled in class action lawsuits. If you’ve been contacted about this breach, received notice, or discovered you were impacted, fill out our quick, easy, and secure form to sign up. There is no cost to reach out to our legal partner and no obligation after speaking with someone from our team.