PrivacySignal
Healthcare

ShinyHunters Claims Theft of 284M Records from Healthcare Giant McKesson

HIPAA Journal · · US Federal · Healthcare Privacy

McKesson, one of the largest healthcare distribution companies in the United States, disclosed a cyberattack in a regulatory filing with the SEC. Hacking group ShinyHunters is claiming responsibility and alleges it stole 284 million records from the company.

Why this matters: 284 million records from a healthcare giant is not an abstract number. Healthcare data is among the most sensitive information that exists about a person — diagnoses, prescriptions, treatment history, insurance details. McKesson sits at the center of drug supply chains and touches enormous amounts of patient-linked data. If ShinyHunters' claim holds up, this could be one of the largest healthcare breaches on record. People affected likely have no idea yet, and they had no real choice about whether McKesson held their information in the first place.

Who should care: Healthcare professionals · Privacy officers · Compliance

This summary is AI-assisted and may contain errors. It is an original briefing to help you gauge significance quickly — not a reproduction of the source. Always read the linked original before relying on it. See our methodology.

Analysis

All analysis →

Weekly Editorial Analysis from Experts and Editors

Related stories

Healthcare
WIRED — AI · · International

Why the Hottest New Wearables Want to Be Ignored

A new category of minimalist wearables is emerging that tracks health data passively, without the constant alerts and screen interactions that have made smartwatches feel intrusive. The pitch is less distraction, but the devices still collect continuous biometric data.

Who should care: Healthcare professionals · Privacy officers · Compliance

#healthcare Read original →
Healthcare
HIPAA Journal · · US Federal

Boston Scientific Cyberattack Impacting Operations

Boston Scientific, a major Massachusetts-based medical device and biomedical engineering company, has disclosed a cyberattack that is disrupting some of its information technology systems. The company has not yet detailed the scope of the breach or what data may be involved.

Who should care: Healthcare professionals · Privacy officers · Compliance

#healthcare Read original →
Healthcare
HIPAA Journal · · US Federal

HIPAA Without a Law Degree

A new guide aims to make HIPAA compliance accessible to small medical practices without requiring legal expertise. The resource is designed to help smaller healthcare providers understand and meet federal patient privacy obligations on their own.

Who should care: Healthcare professionals · Privacy officers · Compliance · Lawyers

#healthcare#regulation Read original →
Healthcare
HIPAA Journal · · US Federal

Health Systems Warn Patients About Epic MyChart Patient Portal Phishing Scam

More than a dozen U.S. health care systems have issued warnings to patients about an ongoing phishing campaign involving emails […] The post Health Systems Warn Patients About Epic MyChart Patient Portal Phishing Scam appeared first on The HIPAA Journal.

Who should care: Healthcare professionals · Privacy officers · Compliance

#healthcare#security Read original →
Healthcare
Nextgov/FCW · · US Federal

Trump administration softens demand for hospitals to share emergency room medical records

The Trump administration has walked back an earlier directive to hospitals requiring participation in a federal injury surveillance system, now telling them the program is voluntary. The shift follows reporting that revealed earlier correspondence had characterized hospital participation as mandatory.

Who should care: Healthcare professionals · Privacy officers · Compliance · Cybersecurity · General readers · Policy

#healthcare#surveillance#privacy Read original →