One Medical Seniors legacy records breach (ShinyHunters extortion claim)
Amazon-owned primary care provider One Medical disclosed that an unauthorized party accessed a third-party file storage system holding archived records of One Medical Seniors (formerly Iora Health) patients; ShinyHunters claimed 8.8 TB of data, and HHS records list 153,174 people affected.
- Victim
- One Medical (Amazon)
- users
- 153.2K
On 17 June 2026, One Medical, the membership-based primary care provider owned by Amazon, posted a notice disclosing that an unauthorized party had accessed a third-party file storage system containing archived information about patients of One Medical Seniors, the senior care business formerly known as Iora Health, which One Medical acquired in 2021. The company said it identified the access on 13 June and determined that it took place between 8 and 11 June 2026.
One Medical said the incident was limited to legacy One Medical Seniors data, did not affect its other patients, its main electronic medical record or Amazon systems, and that it had revoked all access to the system, rotated employee credentials and added safeguards. Affected records relate to One Medical Seniors locations in nine areas: Atlanta, Cape Cod, Charlotte, Piedmont Triad, Denver, Houston, Phoenix, Tucson and Seattle. According to the HHS Office for Civil Rights breach portal, as reported by HIPAA Journal, 153,174 individuals had protected health information exposed.
Extortion claim
Days after the notice, the extortion group ShinyHunters claimed responsibility and said it had stolen 8.8 terabytes of data, issuing a "final warning" for the company to make contact by 22 June 2026 before the data was leaked. One Medical did not confirm that ShinyHunters was behind the intrusion, and the group's volume claim was not independently verified at the time.
Why it matters
The breach illustrates the risk carried by archived data inherited through acquisitions: years-old clinical files from Iora Health sat in an external storage platform outside One Medical's live clinical systems, yet still held regulated health information. It also adds a healthcare target to the long list of 2026 ShinyHunters "pay-or-leak" campaigns aimed at third-party platforms rather than core networks.
Timeline
An unauthorized party begins accessing a third-party file storage system holding archived One Medical Seniors records; access continues until 11 June.
One Medical identifies the unauthorized access, revokes system access and rotates credentials.
One Medical posts a website notice about the incident and begins notifying affected patients.
Deadline set by ShinyHunters, which claims 8.8 TB of stolen data, before threatened publication.
Sources
- hipaajournal.comhttps://www.hipaajournal.com/one-medical-data-breach/
- techtarget.comhttps://www.techtarget.com/healthtechsecurity/news/366644917/ShinyHunters-threatens-to-leak-One-Medical-Seniors-patient-data