Mathew Potter
Security Analyst
Healthcare security news this September is not one incident. It is a pile of related failures: huge supplier breaches, ransomware groups recycling the same extortion playbook, and a quieter pattern where a vendor credential becomes the key to someone else's API.
Reporting this week put McKesson's August incident at roughly 6.4 million affected individuals in Have I Been Pwned data published after ShinyHunters leaked records. The group claimed a multi-million-dollar extortion demand that apparently went unpaid. Names, contact details, and roles spanning patients, staff, providers, and even marketing contacts showed up in the dump.
McKesson supports thousands of oncology providers across the US. Even if your organization is Canadian, you may still receive notice letters because partners, insurers, or counsel sit in shared supply chains. Law firms should expect client questions about whether matter data ever transited a compromised vendor.
Veradigm disclosed to regulators that attackers obtained credentials from a third-party vendor environment and used them to access a company API. Patient data left the building without the dramatic operational shutdown you see in ransomware headlines. The Gentlemen ransomware group claimed roughly 3.5 million records including SSNs.
That pattern is familiar to anyone who reviews SaaS integrations: the breach is not always in your data center. It is in the connector account with too much scope, the long-lived API key nobody rotated, or the vendor support login shared across three environments.
Boston Scientific disclosed an attack around the same window with a different outcome: missed quarterly guidance because systems were down. McKesson is notifying millions. Boston Scientific is explaining revenue impact to shareholders. Same industry, different pain profile. Boards care about both.
Insurers and regulators read these stories together. A firm that handles healthcare clients should assume underwriting questions will ask about vendor access reviews, not just your own MFA policy.
Healthcare breaches are loud when millions of records drop. They are expensive when a quiet API key does the same job without taking the EMR offline. Forensic Five assesses web apps, integrations, and access paths for organizations that need a plain-language report for partners and insurers. Based in St. Albert, Alberta. Scoped work, no fear marketing.