Get all your news in one place.
100's of premium titles.
One app.
Start reading
Medical Daily
Medical Daily
Dorothy Brooks

McKesson Narrows Confirmed Data Theft from Its Cyberattack to Oncology and Multispecialty Customers, Promises Patient Notices

McKesson's September 21 update says it has found no sign that data from its drug distribution business or CoverMyMeds was involved, but it has not said how many patients are affected.

McKesson has narrowed the confirmed data theft from its August cyberattack to certain third-party applications serving a subset of customers in its Oncology & Multispecialty business, according to a September 21 company update reported by Becker's Hospital Review. Data tied to its Medical-Surgical business mainly involved business contact and order information, the company said.

The Irving, Texas-based company said it will notify affected individuals as required by law. It also pointed people who believe they may be affected to a substitute notice with details about the incident and available resources. No official count of affected individuals has been released.

The update matters for patients. The people most likely to receive a letter are those treated at cancer centers and specialty practices that use McKesson's oncology and multispecialty services, not everyone who fills a prescription at a pharmacy McKesson supplies. The investigation remains open, and the full scope is still being determined.


Cancer Care Families at the Center of the Update

According to Becker's, McKesson said its investigation, supported by outside cybersecurity experts, has found no indication so far that data from its other business units was affected, including its North American Pharmaceutical Distribution business and CoverMyMeds, its prescription-access service. The company keeps updates on its customer cybersecurity information center and says it continues to serve customers across all of its lines of business.

That is a meaningful narrowing. McKesson distributes a large share of the country's prescription drugs, and early reports left many pharmacy customers wondering whether they were exposed.

McKesson's oncology footprint is still large. According to the company's website, as reported by The Register, McKesson supports about 3,300 oncology providers in 29 states. Those practices range from community cancer networks to smaller specialty offices, and patients rarely know which vendors their clinic relies on.

Households with a family member in active cancer care should watch the mail most closely. Those families are already juggling appointments, bills, and insurance calls, which can make them targets for scammers posing as a pharmacy, insurer, or clinic.


Data Types at Risk and Claims Still Unverified

An earlier McKesson update dated September 8, summarized by The HIPAA Journal, said the information potentially taken likely included names, addresses, phone numbers, email addresses, patient IDs, and dates of birth. Depending on the person, it may also include health insurance details such as Medicare or Medicaid ID numbers, diagnoses, medications, test results, billing and payment information, and Social Security numbers.

That list describes possible exposure, not confirmed exposure for every individual. Notification letters should state what was involved in each person's record.

The largest numbers circulating online come from the attackers. The extortion group ShinyHunters has claimed it took about 284 million rows of raw patient data, which is not the same as 284 million people. After the group published data it said came from McKesson, security researcher Troy Hunt's Have I Been Pwned service counted 6.4 million unique email addresses belonging to patients, staff, health care providers, and marketing contacts. McKesson has not confirmed either figure, and extortion groups have reasons to inflate their totals.

MedicalDaily first noted McKesson's confirmation of the intrusion in its coverage of the Novocure cyberattack and other health care breaches. At that point, the company had named its oncology, multispecialty, and medical-surgical units without describing the data. Since then, McKesson has listed the likely data types and narrowed the patient-facing scope mainly to oncology and multispecialty customers.


Protecting a Household While Notices Are Pending

No one needs to wait for a letter to take basic steps. Review explanation of benefits statements from Medicare, Medicaid, or a private insurer for services you did not receive, because medical identity theft often shows up there rather than on a credit report. Treat unexpected calls, texts, or emails about prescriptions, cancer treatment, or overdue bills with caution, and call back using the number on your insurance card or your clinic's website.

If a notice confirms that Social Security or financial account numbers were involved, a free credit freeze with the three major credit bureaus is a reasonable step. McKesson has said it expects to offer free credit monitoring and identity protection services to people whose data was taken, according to HME News. Enrollment details usually arrive with the notification letter.

Nobody should delay or stop cancer treatment, switch pharmacies, or change medications because of this breach. Anyone unsure whether their practice uses McKesson can ask the clinic's billing office directly.

Major questions remain open, including how many people are affected, which practices were involved, and when letters will go out. Under federal rules, breaches affecting 500 or more people must be reported to the HHS Office for Civil Rights, and that filing would provide the first official count. MedicalDaily will report the figure when it becomes public.


Key Questions Answered

What changed in McKesson's latest update? On September 21, McKesson said confirmed data theft was limited to certain third-party applications affecting a subset of its Oncology & Multispecialty customers, with Medical-Surgical data mainly business contacts and orders.

Was my pharmacy data exposed? McKesson says it has found no indication so far that data from its North American Pharmaceutical Distribution business or CoverMyMeds was affected. Its investigation is ongoing.

Who is most likely to be notified? Patients of cancer centers and specialty practices that use McKesson's oncology and multispecialty services. The company has not named specific practices.

What information may have been taken? McKesson said the data likely included names, contact details, patient IDs, and dates of birth, and for some people, insurance, medical, billing, or Social Security information.

Is the 284 million figure accurate? That number comes from the hackers and refers to rows of data, not people. McKesson has not confirmed it.

What should I do now? Review insurance statements for unfamiliar services, be cautious with unexpected calls about prescriptions or bills, and read any notice carefully. Do not stop or delay treatment.

Will McKesson offer help? The company has said it expects to provide free credit monitoring and identity protection to people whose data was taken.

Published by Medicaldaily.com

Sign up to read this article
Read news from 100's of titles, curated specifically for you.
Already a member? Sign in here
Related Stories
Top stories on inkl right now
One subscription that gives you access to news from hundreds of sites
Already a member? Sign in here
Our Picks
Fourteen days free
Download the app
One app. One membership.
100+ trusted global sources.