McKesson Data Breach: What Florida Patients Should Know About Notification Rights
One of the largest pharmaceutical distributors in the country has confirmed a data breach. According to a TechCrunch report dated August 31, 2026, McKesson confirmed that hackers breached several of its cloud-hosted accounts and stole data. The hacking group claiming responsibility told TechCrunch it stole millions of rows of patient data. McKesson has not said how many patients are affected. Here is what happened, and what rights Florida residents have if their information is involved.
What Happened
McKesson supplies medicines and medical devices to hospitals and healthcare practices across the United States, according to TechCrunch. Per a SecurityWeek report updated September 1, 2026, the incident was discovered on August 25, 2026. The HIPAA Journal reports that data was exfiltrated between August 21 and August 25, 2026.
TechCrunch reports that a hacking group called ShinyHunters took credit for the attack. The group gained access through phishing and social engineering, tricking several employees into granting them access. ShinyHunters demanded 55 million dollars in exchange for not releasing the stolen files, according to TechCrunch. SecurityWeek reports the extortion deadline was September 1, 2026.
McKesson confirmed unauthorized access and exfiltration of data and said initial containment actions appear to have been successful, per the HIPAA Journal. A company spokesperson told TechCrunch that McKesson continues to operate in all lines of business and believes it has no ongoing unauthorized activity in its systems. SecurityWeek reports the investigation was ongoing as of September 1, 2026.
What Data May Be Involved
ShinyHunters claims it stole 284 million records, according to SecurityWeek. That number needs context. The HIPAA Journal reports that the 284 million figure represents rows of raw data, not unique patients, and that about 1 terabyte of data was taken. The hackers themselves told TechCrunch they were unsure how many individuals are ultimately affected, and McKesson has not specified a total number of patients affected, per SecurityWeek.
Per the hackers’ claims reported by TechCrunch and the HIPAA Journal, the stolen data includes names, contact information, addresses, Social Security numbers, dates of birth, medical record numbers, Medicaid numbers, diagnoses, medications, allergies, patient notes, appointment information, and employee home addresses. SecurityWeek reports the affected business units are McKesson’s Oncology and Multispecialty unit and its Medical-Surgical unit, and that the exposed data claims cover personal information, protected health information, prescription and billing records, employee data, and physician and clinic information.
To be clear, these are the attackers’ claims. The full scope will not be known until the investigation concludes.
Florida’s Breach Notification Law
Florida residents whose data is involved in a breach have specific notification rights under the Florida Information Protection Act, Fla. Stat. 501.171. According to a summary of the statute by the law firm Davis Wright Tremaine, businesses must notify affected Florida residents no later than 30 days after determining a breach occurred. A 15-day extension is possible for good cause provided to the Florida Department of Legal Affairs.
The same summary explains that if a breach affects 500 or more Florida residents, the business must also notify the state within 30 days of the breach determination. If more than 1,000 residents are notified, the business must alert the nationwide consumer reporting agencies as well.
The statute covers personal information such as a name combined with a Social Security number, a government ID number, financial account or card numbers with security codes, medical history or treatment information, health insurance policy or subscriber ID numbers, or usernames and emails paired with passwords or security answers, per the Davis Wright Tremaine summary. Several of those categories match the data types the hackers claim to have taken here.
One limit worth knowing: the Davis Wright Tremaine summary notes that the statute does not provide a private right of action. Individuals cannot directly sue under this specific law. It authorizes civil penalties for violations instead. That does not mean affected consumers have no options after a breach. It means this particular statute is enforced by the state rather than by individual lawsuits.
What McKesson Is Offering and What Comes Next
SecurityWeek reports that McKesson has offered complimentary credit monitoring and identity protection services to impacted individuals. If Florida residents’ data is determined to be involved, the notification timelines described above would apply, and affected patients should hear from the company.
The claimed data includes Social Security numbers and medical information, per TechCrunch and the HIPAA Journal. Identity theft and credit reporting errors are areas where consumers have separate legal protections, and our firm regularly represents Florida consumers in those matters.
This story is still developing. McKesson’s investigation was ongoing as of September 1, per SecurityWeek, and the number of affected patients has not been announced. Florida patients who receive a breach notification letter from McKesson should read it carefully, including any offer of credit monitoring.
This article is for informational purposes only and is not legal advice. If you are dealing with a data breach, identity theft, or credit reporting errors, contact Ethan Babb Law Firm at 321-529-2222 or intake@babblaw.com.