1 SEP 2026 — McKesson has now been described as losing diagnoses, medications, allergies, patient notes and Social Security numbers from its Oncology & Multispecialty and Medical-Surgical units. Under HIPAA, a business associate does not notify patients. It notifies the practices, and each of those practices then owns its own notification duty.
What is new since the disclosure
When McKesson confirmed the incident on 28 August it said only that third-party applications were involved and that data had been accessed and taken. It did not say how many people were affected or what categories of information were involved.
Those categories have now been described. The data is reported to include names, addresses, dates of birth, Social Security numbers, medical record numbers, Medicaid numbers, diagnoses, medication and allergy information, appointment information and patient notes, together with employee home addresses. It is reported to come from cloud-hosted Salesforce and Snowflake environments serving a subset of customers of two business units.
McKesson says it continues to operate in all lines of business and believes there is no ongoing unauthorised activity. It has declined to give a total number of affected individuals or to address the ransom.
Records are not people
The figure being repeated is 284 million records. The population of the United States is about 335 million, and McKesson does not hold clinical data on a number of Americans approaching that.
A record in a database export is a row. One patient with a chronic condition generates a row per prescription, per appointment, per note and per claim, so a few dozen rows for one person over a few years is unremarkable. The count is a measure of how much data left, not of how many people are in it, and the two figures can differ by an order of magnitude.
The point is not to be relaxed about the number, but to expect the eventual notification count to be far smaller than 284 million, and to understand that the gap is not evidence anyone downplayed the incident.
The part that changes the timeline
For most of this data McKesson is a business associate rather than a covered entity. It handles protected health information on behalf of the oncology and multispecialty practices that use its systems, and those practices are the covered entities.
The HIPAA breach notification rule splits the duty accordingly. A business associate must notify the covered entity without unreasonable delay and no later than 60 days from discovery. The covered entity then notifies the individuals, the Department of Health and Human Services, and in incidents affecting 500 or more residents of a state, prominent media in that area.
Anyone waiting for McKesson to notify patients directly is waiting for something the rule does not, for the most part, require. What McKesson owes each affected practice is a list of whose data was in the export. What each practice then owes is a letter to every one of those patients, on its own clock and in its own name.
Why that lands hardest on small practices
An oncology group with four physicians has no breach-response function. It has a practice manager, an outsourced IT provider and a compliance consultant it calls when something goes wrong. Receiving a list of several thousand affected patients from a supplier means finding current addresses, drafting a notice that satisfies the content requirements, standing up a response line, deciding whether to offer credit monitoring and filing with HHS.
None of that is optional and none of it is funded by the supplier whose systems were breached, unless the business associate agreement says so. Those agreements vary widely on indemnification, and the ones signed by small practices are usually the supplier's standard form.
A single intrusion at one distributor thus becomes thousands of separate compliance projects at organisations that had no part in the failure. This cascade, not the headline record count, is what makes the incident expensive.
What patients and practices can do now
Practices should not wait. Find out whether you are a customer of either named business unit, ask your McKesson contact in writing whether your patient data was in the affected environments, and ask when to expect the individual-level list. The 60-day outer limit runs from discovery, and a practice that starts assembling its notification process on the day the list arrives has already lost most of its own window.
Pull the business associate agreement and read what it says about breach costs, notification support and indemnification before the list arrives rather than after.
For patients, a password change does not address this kind of exposure. Social Security numbers and dates of birth support identity theft that surfaces years later, and diagnoses and medication histories cannot be reissued. A credit freeze, which is free, is the measure that matches this kind of theft. We reported earlier this week that the attackers say they reached these environments by telephoning employees and using stolen Okta credentials, which is worth knowing for a second reason: the same technique produces convincing follow-up calls to the people whose records were taken.