AWKO Law LLP is investigating a data breach that led to unauthorized access to the sensitive information of 284 million patient records affiliated with McKesson Corporation (“McKesson”), a Texas-based distributor of pharmaceuticals and provider of health information technology, medical supplies, and health management tools.

On August 28, 2026, McKesson disclosed to the Securities and Exchange Commission (“SEC”) that it had been the subject of a cybersecurity incident targeting employee corporate accounts. That same day, the cybercriminal group ShinyHunters claimed that it exfiltrated 284 million patient records from McKesson.

On September 8, 2026, McKesson confirmed that the following data may have been compromised in the breach: first and last name, address, phone number, email, patient IDs, dates of birth, Social Security numbers, health insurance information (such as primary, secondary or other health plans/policies, insurance companies, member/group ID numbers, and Medicaid-Medicare-government payor ID numbers); health or medical information (such as dates of service, medical record numbers, providers, diagnoses, medicines, test results, images, care and treatment); billing, claims and payment information (such as claim numbers, account numbers, billing codes, credit or debit card numbers, financial and banking information, payments made, and balance due).

If your personal information was impacted by this incident, you may be at risk of identity theft and other serious violations of your privacy. As a result, you may be entitled to money damages and an injunction requiring changes to McKesson’s cybersecurity practices.

If you received notification of this data breach or are affiliated with McKesson and wish to obtain additional information about your legal rights, please contact us today at (415) 251-6804 or sdixit@awkolawllp.com.

Media gallery

About The Author