ao link
Menu
Teiss - Cracking Cyber Security
Teiss - Cracking Cyber Security

Amazon One Medical reports security breach involving sensitive patient data

Amazon One Medical said that the data security incident it suffered earlier this year compromised the sensitive personal information of more than 10,000 individuals.

Linked InXFacebook
bookmark_borderSave to Library

Amazon One Medical disclosed that a data security incident earlier this year exposed the sensitive personal information of more than 10,000 individuals.

 

Amazon One Medical, previously operated by parent company 1Life Healthcare, is a technology-enabled primary care provider offering in-person and virtual healthcare services. Headquartered in San Francisco, California, 1Life Healthcare founded and operated the One Medical brand before being acquired by Amazon in 2023. Iora Health, headquartered in Boston, Massachusetts, was a value-based primary care provider focused on older adults. In 2021, 1Life Healthcare acquired Iora Health, integrating its senior-focused care model into One Medical’s broader healthcare platform.

 

In a data security notice published on its website, One Medical said that on June 13, it detected unauthorised access to a third-party file storage system used to retain archived records for One Medical Seniors, formerly known as Iora Health. The healthcare provider immediately launched an investigation, with assistance from external cyber security experts, to determine the nature and scope of the incident.

 

It also took steps to secure the affected systems and notified relevant law enforcement authorities about the incident.

 

“We launched an investigation and determined that between June 8 and June 11, 2026, the unauthorised person was able to access patient files stored in this system. Importantly, this incident is limited to a file-storage platform used to store archived data from One Medical Seniors. It only impacts certain legacy Iora Health and One Medical Seniors patients. It does not impact other One Medical clinics, services, or the One Medical electronic medical record system,” the healthcare provider said.

 

The compromised data included demographic and clinical records belonging to a number of legacy Iora Health and One Medical Seniors patients. The incident was reported to the Texas state regulators where 1Life Healthcare said it has identified 10,041 Texans affected by the incident.

 

The company said it took steps to secure the affected system and prevent further unauthorised access, including revoking user access and rotating credentials for employees who had access to the system. It also implemented additional security measures to reduce the risk of similar incidents in the future.

 

One Medical said it is working to complete its investigation as quickly as possible and will promptly notify affected patients by mail. The company has also established a dedicated call center to address questions from One Medical Seniors patients regarding the incident.

Linked InXFacebook
bookmark_borderSave to Library
Teiss - Cracking Cyber Security

Subscribe to our Weekly Newsletter

Receive the latest insights direct to your inbox, and gain access to our exclusive events.
Teiss - Cracking Cyber Security

Winston House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF

 

020 8349 4363

info@teiss.co.uk

 © 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543