Custom IT Solutions for All Types of Industries

Data Collaboration Services empowers industry-specific transformation through secure, scalable, and intelligent data solutions.

Cloud Solutions

Finance

Financial institutions in New York are not only bound by national regulations like PCI-DSS, SOX, and GDPR, but also face local regulatory demands, such as those set by the NYDFS.
Data Backup & Recovery

Healthcare

Healthcare providers today face the dual challenge of improving patient care while navigating complex technological and regulatory requirements.

Amazon Owns It. The Data Still Walked Out the Door.

Amazon-owned One Medical suffered a breach involving a third-party storage system containing archived senior patient records inherited from Iora Health. ShinyHunters claims to have stolen 8.8TB of data, highlighting the risks of forgotten healthcare archives and legacy systems.

Published

What Happened

A breach in a system most patients didn’t know existed

On June 13, 2026, One Medical the Amazon-owned primary-care company identified unauthorized activity in a third-party file storage system. The system wasn’t part of its main electronic medical record or its clinics. It was an archive: a place where the company kept legacy records for One Medical Seniors, the business it knows today as the former Iora Health, which One Medical acquired in 2021.

Investigators determined an unauthorized third party had access to that storage platform between June 8 and June 11, 2026 several days before anyone noticed. When the breach was discovered, One Medical secured the system, revoked all access, and began rotating credentials for every employee who could reach it. The company says no other clinics, services, or its electronic medical record were touched.

Then the threats started. Days earlier, on June 18, the data-extortion group ShinyHunters had already added One Medical to its dark-web leak site, claiming it had stolen 8.8 terabytes of data. Its message was blunt: “This is a final warning to reach out by 22 June 2026 before we leak.” One Medical has not confirmed who was behind the attack, and the group has not yet posted proof but the demand, and the deadline, are real.

By the Numbers

The shape of the extortion

8.8 TB
Data ShinyHunters claims to have stolen from the archive
June 8–11
Window attackers had access before the breach was detected
June 22
Ransom deadline set by ShinyHunters to negotiate or leak
9
U.S. metro markets whose senior-patient records were in the system
2021
Year Iora Health was acquired its data lived on in an archive
2+
Other healthcare names ShinyHunters has already hit this year
Key Facts

What was exposed

Demographic and clinical data on a vulnerable population

  • Demographic information of One Medical Seniors (legacy Iora Health) patients
  • Clinical records and medical histories
  • Patients across nine markets: Atlanta, Cape Cod, Charlotte, Piedmont Triad, Denver, Houston, Phoenix, Tucson, and Seattle
  • Archived “legacy” data held in a third-party file storage system
  • Exact data fields still under review; affected count not yet disclosed
  • The records belong to seniors the demographic most aggressively targeted for medical and financial fraud

Note what this wasn’t: a dramatic ransomware shutdown that froze a hospital. It was quieter and, in some ways, more dangerous a data-theft extortion of an archive that wasn’t front-of-mind for anyone. The patients whose records were taken had, in many cases, been Iora Health patients years ago. They had no idea their data was still sitting in a storage system, let alone one a vendor was hosting.

The Cascade

Old data and outside vendors: the two risks every practice underestimates

This breach is a case study in the two things that quietly sink healthcare organizations of every size. The first is legacy data. When you acquire a practice, replace an old EHR, or simply keep “everything just in case,” the data doesn’t disappear it gets parked somewhere and forgotten. Forgotten data can’t be protected, because nobody is watching it. ShinyHunters didn’t break into One Medical’s modern, well-funded clinical systems. It walked into the attic.

The second is third-party risk. The compromised system was a third-party file storage platform a vendor One Medical trusted to hold sensitive records. Your practice almost certainly relies on similar outside services: a cloud backup, a billing company, a transcription vendor, an old document-storage tool. Every one of them is a door into your patients’ data, and you are responsible for what comes through it, even when the failure is theirs.

And the leverage attackers hold has changed. Groups like ShinyHunters increasingly skip the encryption entirely and go straight to extortion: steal the data, then threaten to publish it. There’s no system to “restore from backup.” Once the files are gone, the only question is whether they end up on a leak site which is exactly the threat One Medical is staring at right now.

Legal & Regulatory Fallout

A confirmed breach is the start of the bill, not the end

One Medical has confirmed the incident publicly, which sets a familiar and expensive chain in motion. Under HIPAA, exposure of protected health information triggers breach-notification obligations to affected patients, the U.S. Department of Health and Human Services, and for larger breaches the media. A patchwork of state breach-notification laws adds its own deadlines and penalties on top.

Plaintiffs’ firms are already circling. Data-breach class actions now follow healthcare disclosures almost automatically, and “legacy data we forgot we had” is precisely the kind of fact that reads badly to a jury. Add the involvement of a third-party vendor, and you get the cross-finger-pointing that drives up legal costs for everyone named.

Being owned by Amazon changes none of this. Deep pockets don’t shrink a HIPAA notification list or make a leak-site post go away. Regulators and patients judge the breach, not the balance sheet and for a smaller practice without Amazon’s resources, the same breach can be existential rather than embarrassing.

Action Steps

What your practice should do this week

  1. Find your “attic.” Inventory every place old patient data still lives former EHRs, acquired-practice archives, retired billing systems, that external drive in the back office. You cannot protect data you’ve forgotten you have.
  2. Purge or properly secure legacy data. If you no longer have a clinical or legal reason to keep old records, securely dispose of them per your retention policy. What you must keep should be encrypted and access-restricted not parked in an open archive.
  3. Audit every third-party vendor that touches PHI. List your cloud storage, backup, billing, and transcription providers. Confirm each has a signed Business Associate Agreement and ask, in writing, how they secure and monitor your data.
  4. Turn on monitoring and MFA everywhere patient data lives. The attackers had three days inside One Medical’s archive before detection. Multi-factor authentication and active monitoring shrink that window from days to minutes.
  5. Have a tested breach-response and notification plan. Know in advance who you call, how you preserve evidence, and how you meet HIPAA and state notification deadlines including for data held by your vendors.
The Bottom Line

The data you forgot is the data they’ll find

The most uncomfortable lesson of the One Medical breach is that the company’s strongest, best-funded systems weren’t the problem. The problem was an old archive of patients from a business it had absorbed years earlier, sitting on a third-party platform, out of sight. Attackers go looking for exactly that the soft, unwatched corner where valuable data is stored and nobody is paying attention.

Your practice has corners like that too. Every clinic does. The patients whose records ShinyHunters is now holding for ransom did nothing wrong and had no idea their data was still out there and that’s the part that turns a quiet archive into a lawsuit and a headline. If you can’t say, with confidence, exactly where your old patient data lives and who is guarding it, that’s the gap to close now before someone else finds it first.

Stay Ahead of Threats

Get weekly insights on the latest vulnerabilities, breach analysis, and defense strategies delivered directly to your inbox.

End-to-end encrypted delivery