One Medical, the Amazon-owned primary care provider, disclosed a cybersecurity incident in June 2026 involving unauthorized access to a third-party file-storage system used to retain archived information for One Medical Seniors, formerly known as Iora Health. [onemedical.com]
According to One Medical’s security notice, the incident affected certain legacy Iora Health and One Medical Seniors patients, while other One Medical clinics, services, and the One Medical electronic medical record system were not affected. [onemedical.com]
The attack is important because it highlights a growing cybersecurity risk: archived healthcare data stored in third-party or legacy systems can remain highly sensitive long after a merger, acquisition, or platform migration. Healthcare IT News also reported that the incident shows how inherited legacy systems after acquisitions can create security exposure if not managed carefully. [healthcareitnews.com]
What Happened?
One Medical stated that on June 13, 2026, it learned that an unauthorized person had gained access to a third-party file-storage system used to store archived information for One Medical Seniors. [onemedical.com]
The company’s investigation found that the unauthorized person was able to access patient files between June 8 and June 11, 2026. [onemedical.com]
One Medical said the incident was limited to a file-storage platform used for archived data from One Medical Seniors and legacy Iora Health patients. [onemedical.com]
Healthcare IT News reported that the affected archives included demographic and clinical records stored on certain legacy systems, and that One Medical said its electronic medical record system was not impacted. [healthcareitnews.com]
Why This Breach Matters
Healthcare records are among the most valuable types of data for cybercriminals because they can include personal, demographic, medical, insurance, and clinical information. In this case, One Medical said its review identified files containing demographic and clinical records from a subset of legacy Iora Health and One Medical Seniors patients. [onemedical.com]
The risk is not limited to identity theft. Healthcare data can be used for medical identity fraud, targeted phishing, insurance fraud, and long-term social engineering because medical information cannot be easily changed like a password or payment card. One Medical’s notice confirmed that demographic and clinical records were involved, making the exposure more sensitive than a simple account-access incident. [onemedical.com]
The incident also demonstrates a major challenge for healthcare mergers and acquisitions. One Medical acquired Iora Health in 2021, and Amazon later purchased One Medical in 2023, according to Healthcare IT News. [healthcareitnews.com]
When organizations acquire other companies, they also inherit older systems, stored data, vendor relationships, and security obligations. Healthcare IT News noted that this breach involved an archived third-party file-storage platform connected to legacy One Medical Seniors/Iora Health data. [healthcareitnews.com]
The Reported ShinyHunters Claim
Several reports stated that the ShinyHunters extortion group claimed to have stolen 8.8 terabytes of One Medical data and threatened to leak it. [hipaajournal.com], [healthcareitnews.com]
However, One Medical’s own public notice did not confirm the attacker’s identity or confirm the reported 8.8 TB figure. [onemedical.com]
This distinction is important. In cyber extortion cases, threat groups often make claims to increase pressure on victims, attract attention, or force negotiations. Until a company, regulator, or verified forensic report confirms the exact volume and type of stolen data, such claims should be treated carefully. Reports from HIPAA Journal and Healthcare IT News both noted that the attacker claim had not been verified by One Medical. [hipaajournal.com], [healthcareitnews.com]
How One Medical Responded
One Medical said it immediately secured the affected system and revoked all access after learning of the incident. [onemedical.com]
The company also said it rotated credentials for employees who had access to the system and implemented additional safeguards to help prevent a similar incident in future. [onemedical.com]
One Medical also stated that it is working to complete its investigation and will notify patients whose information was involved by mail. [onemedical.com]
These response steps are standard but important. In a third-party storage breach, organizations must rapidly contain access, revoke credentials, preserve logs, identify affected data, notify impacted individuals, and strengthen controls around the affected platform.
Lessons for Healthcare Organizations
The One Medical incident provides several important cybersecurity lessons for healthcare providers, clinics, insurers, and organizations that hold sensitive patient information.
1. Legacy Systems Must Be Included in Risk Assessments
Archived systems are often overlooked because they are not part of daily operations. However, if those systems still contain patient information, they remain high-value targets. One Medical confirmed that the incident involved an archived file-storage platform used for legacy One Medical Seniors/Iora Health data. [onemedical.com]
2. Third-Party Storage Requires Continuous Monitoring
Third-party systems should be monitored and audited like internal systems. Healthcare IT News reported that the incident involved third-party file-storage systems connected to archived patient data. [healthcareitnews.com]
3. Data Minimization Reduces Breach Impact
Organizations should regularly review whether old data still needs to be retained. If archived records are no longer required by law, policy, or clinical need, secure deletion can reduce future exposure.
4. Mergers and Acquisitions Need Cyber Due Diligence
Every acquisition should include technical security review, data mapping, vendor review, access review, and legacy system remediation. Healthcare IT News connected this breach risk to healthcare acquisitions and inherited IT environments. [healthcareitnews.com]
5. Clinical Records Need Stronger Protection
Clinical information can be extremely sensitive. One Medical said demographic and clinical records were involved in the affected files. [onemedical.com]
What Affected Patients Should Do
Patients who may be affected should watch for mailed notification from One Medical, as the company said impacted individuals will be contacted directly. [onemedical.com]
Affected patients should also monitor healthcare statements, insurance activity, medical account portals, and financial accounts for unusual activity. They should be cautious of phishing emails or phone calls that reference healthcare information, appointments, billing, or insurance claims.
Patients should avoid clicking links in unexpected messages and should contact healthcare providers using official phone numbers or websites.
Conclusion
The One Medical data breach is a reminder that cybersecurity risk does not disappear when data is archived. Legacy records, third-party platforms, and inherited systems can remain attractive targets for attackers, especially in healthcare.
While One Medical stated that the incident was limited to an archived file-storage platform and did not affect its electronic medical record system, the exposure of demographic and clinical records still makes this a serious privacy and security event. [onemedical.com]
For healthcare organizations, the key lesson is clear: protect archived data with the same seriousness as active systems. Strong vendor controls, credential management, access reviews, encryption, data retention policies, and incident response planning are essential for reducing the impact of future breaches.