Healthcare breaches keep stacking up: McKesson, Veradigm, and the vendor API problem
Industry

Healthcare breaches keep stacking up: McKesson, Veradigm, and the vendor API problem

Mathew Potter

Security Analyst

September 10, 2026

Healthcare security news this September is not one incident. It is a pile of related failures: huge supplier breaches, ransomware groups recycling the same extortion playbook, and a quieter pattern where a vendor credential becomes the key to someone else's API.

McKesson and the scale problem

Reporting this week put McKesson's August incident at roughly 6.4 million affected individuals in Have I Been Pwned data published after ShinyHunters leaked records. The group claimed a multi-million-dollar extortion demand that apparently went unpaid. Names, contact details, and roles spanning patients, staff, providers, and even marketing contacts showed up in the dump.

McKesson supports thousands of oncology providers across the US. Even if your organization is Canadian, you may still receive notice letters because partners, insurers, or counsel sit in shared supply chains. Law firms should expect client questions about whether matter data ever transited a compromised vendor.

Veradigm and the API credential angle

Veradigm disclosed to regulators that attackers obtained credentials from a third-party vendor environment and used them to access a company API. Patient data left the building without the dramatic operational shutdown you see in ransomware headlines. The Gentlemen ransomware group claimed roughly 3.5 million records including SSNs.

That pattern is familiar to anyone who reviews SaaS integrations: the breach is not always in your data center. It is in the connector account with too much scope, the long-lived API key nobody rotated, or the vendor support login shared across three environments.

Why Boston Scientific and others still matter

Boston Scientific disclosed an attack around the same window with a different outcome: missed quarterly guidance because systems were down. McKesson is notifying millions. Boston Scientific is explaining revenue impact to shareholders. Same industry, different pain profile. Boards care about both.

Insurers and regulators read these stories together. A firm that handles healthcare clients should assume underwriting questions will ask about vendor access reviews, not just your own MFA policy.

Questions worth answering this month

  • List every vendor with API or SFTP access to PHI or sensitive client data. When did each credential last rotate?
  • Require evidence of MFA and logging from vendors above a data threshold, not checkbox attestations.
  • Run tabletop exercises on "vendor credential leak" separate from ransomware. The playbooks differ.
  • Make breach notification templates current before you need them at 9 p.m. on a Friday.
  • If you are renewing cyber coverage, pull third-party risk into the application with specifics.

Bottom line

Healthcare breaches are loud when millions of records drop. They are expensive when a quiet API key does the same job without taking the EMR offline. Forensic Five assesses web apps, integrations, and access paths for organizations that need a plain-language report for partners and insurers. Based in St. Albert, Alberta. Scoped work, no fear marketing.

Tags

healthcare data breach third-party risk McKesson API security

Share This Article

About the Author

Mathew Potter

Security Analyst

Mathew leads assessments and consulting at Forensic Five from St. Albert, Alberta. His background is Linux systems, networks, and application infrastructure.