Were you recently affected by a data breach?

Texas Oncology Data Breach

A cybersecurity incident involving McKesson, the parent company of Texas Oncology, may have exposed patient names, Social Security numbers, and medical information. Affected patients who received a breach notification letter may have legal options.

Texas Oncology
Date of Breach: Discovered August 25, 2026
CAU logo

Who was affected:

Clients of Texas Oncology

Impacted Data:

Names, addresses, dates of birth, phone numbers, Social Security numbers, medical information

Texas Oncology, one of the largest community-based oncology practices in the country, was affected by a cybersecurity incident involving its parent company, McKesson. The incident, discovered on August 25, 2026, reportedly compromised sensitive patient information belonging to individuals treated through Texas Oncology and other McKesson-affiliated oncology practices.

Healthcare providers and the companies that support them are entrusted with highly sensitive medical and personal information, and they bear a responsibility to protect that data and to promptly notify patients when it is compromised.

Texas Oncology’s Data Breach Investigation

According to a notice published by McKesson and reporting by the HIPAA Journal, a cybersecurity incident was identified involving third-party applications used by the company. McKesson disclosed the incident in a Form 8-K filing with the U.S. Securities and Exchange Commission, confirming that data was exfiltrated from its systems, though the company said the full extent of the data theft had not yet been determined at the time of disclosure. A cybercriminal group known as ShinyHunters has claimed responsibility, listing McKesson on its data leak site and asserting that approximately 284 million records were taken, a figure McKesson has said relates to rows of raw data rather than unique patients.

McKesson stated that the incident appears to involve a subset of customers connected to its Oncology & Multispecialty business unit, which includes Texas Oncology, as well as its Medical-Surgical business unit. According to reporting from BleepingComputer, which said it was in contact with the threat actor, roughly one terabyte of data was reportedly taken between August 21 and August 25, 2026, and a ransom demand exceeding $55 million was made. The group has claimed the stolen data includes patient names, contact information, Social Security numbers, dates of birth, medical record numbers, Medicaid numbers, medication and allergy information, diagnoses, and appointment details, reportedly drawn from McKesson’s Salesforce and Snowflake environments.

McKesson has said it activated incident response protocols and engaged outside cybersecurity experts to investigate the scope of the intrusion and to determine what data was affected. The company has stated that it does not believe customers need to take any immediate action on their own systems and that its distribution network continues to operate. However, patients of Texas Oncology and other affected practices are a separate group from McKesson’s corporate customers, and any patient whose medical and personal information was exposed may be entitled to notice and, potentially, compensation regardless of any operational statements McKesson has made about its business systems.

Because this incident involves a healthcare provider network and reportedly includes medical record numbers, diagnoses, and other protected health information alongside Social Security numbers, it carries an elevated risk of both medical identity theft and traditional financial fraud for those affected.

When Did This Breach Occur?

McKesson stated that the cybersecurity incident was first detected on August 25, 2026. According to reporting from BleepingComputer, the underlying data exfiltration is believed to have occurred over several days, between approximately August 21 and August 25, 2026. McKesson publicly announced the incident on August 28, 2026, and provided a further update on August 29, 2026. As of this writing, individual patient notification letters from Texas Oncology have not been widely confirmed as sent, and the timeline for direct notice to affected patients may follow in the weeks after the initial corporate disclosure.

What Information Was Breached?

The threat actor claiming responsibility has stated that the exposed data includes patient names, addresses, dates of birth, phone numbers, Social Security numbers, medical record numbers, Medicaid numbers, medication and allergy information, diagnoses, and appointment information. McKesson has confirmed that data was exfiltrated but has not yet issued a complete, confirmed list of every data type involved for every affected individual. Patients who receive a formal notification letter from Texas Oncology or McKesson should review it carefully, as it will specify the categories of information confirmed to be involved in their individual case.

What You Can Do

If you are a patient of Texas Oncology or believe your information may have been involved in this incident, consider the following steps:

  • Monitor your credit reports and financial accounts closely for any unfamiliar or suspicious activity.
  • Consider placing a fraud alert or credit freeze with the three major credit bureaus: Equifax, Experian, and TransUnion.
  • Watch for signs of medical identity theft, such as unfamiliar medical bills, insurance claims, or Medicaid activity you did not authorize.
  • Be cautious of phishing emails, texts, or phone calls referencing Texas Oncology, McKesson, or this data breach.
  • Keep any notification letter or communication you receive from Texas Oncology or McKesson, as it may be useful if you decide to pursue legal action.

File a Data Breach Lawsuit Against Texas Oncology

Healthcare providers and their corporate partners that collect and store sensitive medical and personal information are expected to maintain reasonable safeguards to protect that data from unauthorized access. When a data breach occurs, patients whose information was exposed may have legal options, including the ability to pursue compensation through a class action lawsuit.

Contact us at Class Action U, where we’ll connect you with a lawyer skilled in class action lawsuits. If you’ve been contacted about this breach, received notice, or discovered you were impacted, fill out our quick, easy, and secure form to sign up. There is no cost to reach out to our legal partner and no obligation after speaking with someone from our team.

Were you recently affected by a data breach?
Other Data Breaches
Date of Breach: Discovered August 25, 2026
Date of Breach: August 2026 (reported by threat actor; not yet confirmed by the company)
Date of Breach: August 2026 (reported by threat actor; not yet confirmed by the company)
Related News

Frequently Asked Questions

A data breach occurs when sensitive, confidential, or protected information is accessed, stolen, or disclosed without authorization. Data breaches often occur through phishing emails, malware, weak passwords, insider threats, or unsecured databases. Indicators of a data breach can include unexpected password resets, suspicious account activity, unauthorized transactions, or notifications from companies about compromised information.If you suspect your data has been compromised, you must take measures and act quickly. Change passwords, enable two-factor authentication, review your financial accounts for unusual activity and consider freezing your credit.

Once stolen, your personal information may be sold on the dark web or used for identity theft and financial fraud. In some cases, hackers use the data to extort companies or launch further attacks. Victims often face long-term risks, including damage to credit and privacy.

If you receive a data breach notification, don’t ignore it. Immediately change passwords for the affected account and any others that share credentials. Enroll in any free credit monitoring services offered and monitor financial statements closely.

To pursue a data breach claim, you’ll need documentation showing your information was compromised and proof of resulting harm, such as fraudulent charges, credit score damage, or identity theft reports. Notification letters, financial records, and communication with the breached company can help support your claim.

Yes. If a company fails to protect consumer data or delays notifying victims, it may be held liable under state and federal privacy laws. Many victims join class action lawsuits to recover financial losses and hold negligent organizations accountable.

Data breach settlements vary widely depending on the size of the breach, type of data compromised, and damages suffered by victims. Payouts may include cash compensation, identity theft protection, or reimbursement for losses. Many settlements range from a few hundred to several thousand dollars per person. A skilled data breach lawyer can guide victims through the complex legal process, ensuring their rights are protected. If you’ve received a data breach notification or believe your personal data was exposed, you may be eligible for compensation. Contact Class Action U to learn more about how to join a data breach lawsuit and understand the process of filing.