McKesson
Medical records run on two clocks, and only one of them is yours: retention law keeps the clinical file for years or decades whatever you ask. Around it, what you looked up can become an advertising interest, and a deletion request usually comes back half done.
Reported incidents
Patient and customer data taken from third-party apps it uses
2026-08-28Affected Third-party cloud applications (Salesforce and Snowflake, per reports) for its Oncology & Multispecialty and Medical-Surgical units
McKesson, the US drug and medical supply distributor, disclosed on 28 August 2026 a cybersecurity incident involving third-party applications and the theft of data. It found the intrusion on 25 August. The extortion group ShinyHunters claimed 284 million records, which BleepingComputer reports are data rows, not people, and demanded about $55 million. On 8 September McKesson said the data could include names, addresses, phone numbers, email addresses, patient IDs and dates of birth. On 21 September it said the access affected a subset of customers in its oncology business and mainly business contact and order data in its medical-surgical business.
People affected typically ask McKesson to confirm whether their information was included, and which categories.
The verified route
DÆTRAX is a personal data accountability ledger: a dated record of which companies hold your personal data, what you asked them to do about it, and what they claimed in reply.