McKesson faces lawsuit probe after 284M records breached in August
- Ademi LLP investigates data privacy claims against McKesson following an August 25 breach
- Reports indicate 284 million patient records were compromised
- Exposed data includes SSNs, medical diagnoses, and predictive health risks
- McKesson to notify impacted individuals; initial materiality was undetermined
- Law firm evaluates compensation claims for affected parties at no cost

*this image is generated using AI for illustrative purposes only.
Law firm Ademi LLP is investigating potential data privacy claims against McKesson following a cybersecurity incident detected on August 25. The firm is assessing whether the company maintained reasonable safeguards to protect personal information.
Reports claim that 284 million records linked to tens of millions of patients were obtained in the breach. McKesson has stated it will notify individuals whose information may have been compromised.
Scope of Data Exposure
The compromised information reportedly includes highly sensitive personal and medical details. Key categories of exposed data include:
- Identity and contact information: full names, home addresses, dates of birth, phone numbers, email addresses, and Social Security numbers.
- Healthcare identifiers: patient IDs, medical record numbers (MRNs), and Medicaid numbers.
- Medical information: illnesses, diagnoses, allergies, medications, disabilities, patient notes, appointment details, and physician information.
- Highly sensitive records: hospice and terminal illness information, causes of death, autopsy details, sexual orientation, and other personal status information.
- Predictive health data: disease-risk assessments, including cancer predictions linked to individual patients.
- Prescription and billing records: medication orders, invoice and billing information, shipment addresses, dates, and tracking numbers.
Legal and Operational Impact
Ademi LLP is evaluating rights and potential claims for damages at no cost to affected individuals. The firm specializes in consumer and investor class actions involving data breaches and cybersecurity incidents nationwide.
McKesson initially disclosed the incident on August 25, stating that the investigation was in its early stages. At that time, the company had not yet determined whether the incident was material or provided further details regarding operational impact.
What the Numbers Show
The scale of the breach, involving 284 million records, significantly expands the scope from the initial disclosure where materiality was undetermined. The inclusion of predictive health data and terminal illness records indicates a high severity level for potential identity theft and financial fraud risks for affected patients.
How might the inclusion of predictive health data and terminal illness records influence the valuation of potential class-action settlements compared to standard identity theft breaches?
What impact could this breach have on McKesson's insurance premiums and its ability to secure cyber liability coverage in the future?
Will regulatory bodies like the FTC or HHS impose specific operational mandates or fines on McKesson given the severity of the exposed medical and social security data?






























