Table of Contents
A June hacking incident involving Amazon One Medical affected 153,174 patients in its senior health unit. One Medical first disclosed the cybersecurity incident on June 17, stating that it affected a limited number of patients in its senior care business but did not specify how many.
In July, Amazon-owned One Medical reported the breach to the HHS Office for Civil Rights, identifying 153,174 affected individuals. HHS classifies the breach as a hacking/IT incident involving a network server.
What Happened in the Amazon One Medical Breach?
On June 13, One Medical learned that an unauthorized person had gained access to a third-party file storage system used to retain archived information from Iora Health. One Medical had acquired Iora Health in 2021. Amazon then acquired One Medical in 2023.
The unauthorized access reportedly occurred between June 8 and June 11. After discovering the incident, One Medical deactivated the system, revoked all access and launched an investigation. The investigation determined that certain patient files belonging to legacy Iora Health and One Medical Senior patients had been accessed.
According to One Medical, no other patients were affected, and the incident was isolated to the third-party storage system. No other One Medical or Amazon systems were affected.
“We take the security of patient information seriously and are implementing additional safeguards to prevent similar events in the future,” the company stated.
The ShinyHunters cyber extortion group has claimed responsibility for the attack and alleged that it stole 8.8 terabytes of One Medical data. The group reportedly threatened to publish the stolen information unless One Medical entered into ransom negotiations. However, One Medical has not publicly confirmed the group’s responsibility or verified its claim of obtaining 8.8 TB of data.
Legacy Patient Data Can Create Current Risk
The One Medical incident provides an important reminder for healthcare organizations: old data can create new cybersecurity and privacy risks.
Healthcare mergers and acquisitions can leave organizations responsible for years of inherited patient data, applications, vendors and technology infrastructure—even systems no longer used in day-to-day operations.
Healthcare organizations need to understand not only where current patient information is stored, but also where historical information resides, who can access it, which third parties maintain it, and whether the information still needs to be retained.
What Healthcare Organizations Can Learn
The One Medical breach reinforces several important cybersecurity and HIPAA risk-management practices:
- Inventory systems containing PHI. Include legacy, archived, and infrequently used systems, not just active applications.
- Conduct a Vendor Risk Assessment. Identify vendors that store or access PHI, and evaluate whether appropriate security safeguards are in place.
- Review data-retention practices. Understand what historical information is being maintained, why it is retained, and how it is protected.
- Reassess risks following acquisitions. Incorporate acquired systems, vendors, and data repositories into ongoing privacy and security risk assessments.
- Limit access to sensitive information. Archived data should receive appropriate access controls and security protections throughout its lifecycle.
- Maintain a disaster recovery plan. Organizations should be prepared to identify compromised systems, investigate incidents, and meet applicable breach-notification requirements. The HIPAA Security Rule requires covered entities and their business associates to maintain a comprehensive contingency, emergency mode, data backup, and disaster recovery plan that prepares them for an event such as a natural disaster or a cyberattack.
The One Medical breach demonstrates that cybersecurity risk doesn’t disappear when patient information moves out of an active system. Archived PHI remains sensitive regardless of its age or which organization originally collected it.
To remain HIPAA compliant, identifying and evaluating risks across active systems, legacy data repositories, and third-party platforms should be an essential part of ongoing privacy and security risk management.
FAQs: Amazon One Medical Data Breach
What happened in the Amazon One Medical data breach?
An unauthorized person accessed a third-party file storage system containing archived patient information from legacy Iora Health and One Medical Senior patients.
When did the One Medical breach occur?
Unauthorized access reportedly occurred between June 8 and June 11, 2026. One Medical discovered the incident on June 13 and publicly disclosed it on June 17.
What information was exposed in the One Medical breach?
One Medical said certain patient files were accessed but has not publicly detailed all types of information contained in those files. The incident was isolated to a third-party storage system.
Why can old patient data still pose a cybersecurity risk?
Archived patient data may still contain sensitive PHI even when it is no longer actively used. If legacy systems or storage platforms have outdated security controls or unnecessary access, they can remain targets for cyberattacks.
How should healthcare organizations protect legacy patient data?
Organizations should include legacy and archived data in their HIPAA risk assessments, review who has access to it, assess third-party storage risks, maintain appropriate security safeguards, and determine whether the data still needs to be retained.
Safeguard Confidential Data
Protecting sensitive and private data is paramount in today’s digital age. That’s why PrivaPlan offers comprehensive Privacy Risk Assessments tailored for corporations, healthcare providers, and government agencies that handle vast amounts of personal and confidential data.


