Almeida Law Group is investigating a data breach at 1Life Healthcare, Inc. The breach occurred on June 8th–11th, 2026 and was discovered on June 17th, 2026. If you were affected, contact Almeida Law Group.
About 1Life Healthcare, Inc.
1Life Healthcare, Inc. operates a membership-based primary care platform under the One Medical brand and is headquartered in San Francisco, California. Amazon acquired the company in February 2023 for approximately $3.9 billion. In 2021, One Medical acquired Iora Health, a Medicare-focused primary care practice for seniors, which was later rebranded as One Medical Seniors in 2023. The breach specifically involved archived patient records from the legacy Iora Health/One Medical Seniors system, making the exposure of health and personal identifying information especially significant for that patient population.
What Happened?
1Life Healthcare, Inc. was listed in a Texas Attorney General data security breach report (record ID BR-0005165). According to that filing, an unauthorized party accessed a third-party file-storage system used to retain archived patient information for One Medical Seniors, formerly Iora Health. The unauthorized access occurred between June 8th, 2026 and June 11th, 2026, and the breach was discovered on June 17th, 2026. A total of 141,075 individuals were affected. The compromised information included names, addresses, Social Security numbers, health insurance information, and dates of birth. One Medical stated the breach was limited to the legacy Seniors file-storage platform and does not affect other One Medical clinics, services, or its main electronic medical record system. Affected patients were at One Medical Seniors/Iora Health clinics in Atlanta, Cape Cod, Charlotte, the Piedmont Triad, Denver, Houston, Phoenix, Tucson, and Seattle. Consumers were notified by U.S. mail.
On June 13th, 2026, One Medical learned of the unauthorized access and immediately deactivated the affected system, revoked all user access, and rotated employee credentials. On June 18th, 2026, the digital extortion group ShinyHunters claimed responsibility on its dark web data leak site, alleging exfiltration of approximately 8.8 terabytes of data and threatening to publish the records unless One Medical responded by June 22nd, 2026. While ShinyHunters’ full claims have not been independently verified, at least one source reports that samples of patient records posted to dark web forums have been verified as authentic. A proposed class-action lawsuit was filed on June 19th, 2026, in the U.S. District Court for the Northern District of California. Five additional lawsuits raising similar claims have since been filed in the same court, and plaintiffs in all six cases have asked the court to consolidate them before a single judge. The plaintiffs allege that One Medical failed to adequately protect patient data, including by not encrypting archived records, failing to implement multi-factor authentication, and not properly overseeing third-party vendors.
Key Facts at a Glance
- Company or Organization: 1Life Healthcare, Inc. (One Medical)
- Industry: Healthcare – Medical Provider (membership-based primary care)
- Location: San Francisco, California
- Incident type: Unauthorized access to a third-party file-storage system
- Date of breach: June 8th, 2026 – June 11th, 2026
- Date breach discovered: June 17th, 2026
- Date of consumer notification: Reported to the Texas Attorney General on July 7th, 2026; notices sent by U.S. mail
- Total persons affected: 141,075
- Prior breach: None identified for 1Life Healthcare or One Medical
- Litigation status: Six proposed class-action lawsuits filed in the U.S. District Court for the Northern District of California as of reporting; additional law firm investigations announced
- Source: Texas Attorney General data security breach report – BR-0005165; HIPAA Journal; Becker’s Hospital Review; Kiteworks
What Should You Do?
If you received a notice from 1Life Healthcare or One Medical, enroll in any identity theft protection offered as soon as possible and note the enrollment deadline stated in your notice. You should also place a fraud alert or credit freeze with the three major credit bureaus — Equifax, Experian, and TransUnion — and monitor your credit reports for unfamiliar accounts or inquiries. You can request free annual credit reports at AnnualCreditReport.com. Because health insurance information and other sensitive personal data were exposed, review your Explanation of Benefits statements and any medical records for services you did not receive, and report any suspicious activity to your insurer. If you believe your information has been misused, visit IdentityTheft.gov for step-by-step guidance on recovering from identity theft.
Your Legal Rights
If your personal or health information was involved in this breach, you may have legal rights depending on the facts of the incident and the law in your state. Almeida Law Group represents consumers in data breach and privacy litigation and can help you evaluate whether you may have a claim. Contact us at (708) 529-5418 or through our contact page for a free case evaluation.