Wire Observer.
Business

McKesson Confirms Massive Data Breach, Millions of Patient Records Exposed

McKesson Confirms Massive Data Breach, Millions of Patient Records Exposed

McKesson Corp., one of the United States' largest distributors of pharmaceuticals and medical devices, disclosed that a cyber intrusion has resulted in the theft of millions of patient records, while also warning of intermittent disruptions to its services.

The breach, reported by the company on Tuesday, was attributed to an unidentified group of hackers who claimed responsibility for extracting the data. McKesson, which supplies medicines and equipment to hospitals, clinics, and other health‑care providers nationwide, said the attack compromised information that could include personal identifiers, treatment histories, and insurance details.

According to the company's statement, the attackers gained access to internal systems sometime in the preceding weeks, although the exact timeline and method of entry have not been disclosed. The firm emphasized that the breach is ongoing and that it expects “intermittent service degradation” as it works to contain the incident and restore normal operations.

The exposure of patient data raises serious privacy concerns, especially in a sector already grappling with a surge in ransomware and other cyber‑crime activity. Health‑care organizations store highly sensitive information, making them attractive targets for financially motivated actors seeking to sell or ransom the data on underground markets.

McKesson has initiated its incident‑response protocol, involving third‑party cybersecurity experts and notifying relevant federal authorities. While the company has not provided a precise figure, it acknowledged that “millions” of records may have been accessed. Affected parties are being advised to monitor their accounts for suspicious activity and to consider additional security measures such as credit monitoring.

The breach adds to a growing list of high‑profile attacks on health‑care supply chains, prompting regulators and industry groups to call for stronger cybersecurity standards. Analysts suggest that the fallout could include increased scrutiny from the U.S. Department of Health and Human Services and potential penalties under the Health Insurance Portability and Accountability Act (HIPAA) if the breach is deemed to result from inadequate safeguards. McKesson has indicated that it will provide updates as more information becomes available and that it is committed to reinforcing its defenses to prevent future incidents.

Source: techcrunch
Christina Kyriasoglou — Bloomberg (Berlin, Germany)

Comments (0)

Be the first to comment.

Join the discussion

Protected by reCAPTCHA v3

Related