Security Magazine logo
search
cart
facebook twitter linkedin youtube
  • Sign In
  • Create Account
  • Sign Out
  • My Account
Security Magazine logo
  • NEWS
    • Security Newswire
    • Technologies & Solutions
  • MANAGEMENT
    • Leadership Management
    • Enterprise Services
    • Security Education & Training
    • Logical Security
    • Security & Business Resilience
    • Profiles in Excellence
  • PHYSICAL
    • Access Management
    • Fire & Life Safety
    • Identity Management
    • Physical Security
    • Video Surveillance
    • Case Studies (Physical)
  • CYBER
    • Cybersecurity News
    • More
  • BLOG
  • COLUMNS
    • Career Intelligence
    • Cyber Tactics
    • Cybersecurity Education & Training
    • Leadership & Management
    • Security Talk
  • EXCLUSIVES
    • Annual Guarding Report
    • Most Influential People in Security
    • The Security Benchmark Report
    • Top Guard and Security Officer Companies
    • Top Cybersecurity Leaders
    • Women in Security
  • SECTORS
    • Arenas / Stadiums / Leagues / Entertainment
    • Banking/Finance/Insurance
    • Construction, Real Estate, Property Management
    • Education: K-12
    • Education: University
    • Government: Federal, State and Local
    • Hospitality & Casinos
    • Hospitals & Medical Centers
    • Infrastructure:Electric,Gas & Water
    • Ports: Sea, Land, & Air
    • Retail/Restaurants/Convenience
    • Transportation/Logistics/Supply Chain/Distribution/ Warehousing
  • EVENTS
    • Industry Events
    • Webinars
    • Solutions by Sector
    • Security 500 Conference
  • MEDIA
    • Interactive Spotlight
    • Photo Galleries
    • Podcasts
    • Polls
    • Videos
      • Cybersecurity & Geopolitical Discussion
      • Ask Me Anything (AMA) Series
  • MORE
    • Call for Entries
    • Classifieds & Job Listings
    • Newsletter
    • Sponsor Insights
    • Store
    • White Papers
  • EMAG
    • eMagazine
    • This Month's Content
    • Advertise
  • SIGN UP!
CybersecuritySecurity NewswireCybersecurity NewsHospitals & Medical Centers

McKesson Confirms Data Breach, Experts Weigh In

By Jordyn Alger, Managing Editor
Medical professional using tablet
Nappy via Unsplash
September 1, 2026

McKesson, an organization specializing in pharmaceuticals, health information technology, medical supplies, and health management tools, experienced a data breach. 

According to the company, an unauthorized user gained “access to certain third-party applications and the exfiltration of certain data was associated with a subset of customers within our Oncology & Multispecialty and Medical-Surgical business units.” 

Security Leaders Weigh In 

Phil Wylie, Senior Consultant & Evangelist, Suzu Labs:

The McKesson incident is another reminder that an organization’s attack surface extends well beyond the systems it directly controls. Third-party applications with access to sensitive data can provide attackers with a path around otherwise mature security controls.

The potential impact is especially concerning in healthcare. When an organization sits at the center of the pharmaceutical and medical supply chain, a cyberattack is no longer just a data-security issue. Disruption can potentially ripple downstream to providers, pharmacies and ultimately patients.

Organizations need to treat third-party access with the same scrutiny as internal access. That means limiting privileges, segmenting critical systems, continuously monitoring vendor connections and having an incident response plan that assumes a trusted third party could eventually be compromised.

The reported 284 million records is a claim from the attackers and should be treated as unverified until McKesson confirms the scope. Regardless of the final number, this incident demonstrates why third-party risk has become one of the most important challenges in defending complex healthcare environments.

John Strand, Owner, Black Hills Information Security, Inc.:

This particular story highlights a major problem that I don’t think enough people spend time thinking about. Complexity is the enemy of computer security.

The more third-party vendors you integrate with, especially SaaS providers, the larger your attack surface becomes. Every integration, API, application, and vendor relationship creates another potential path into your organization.

I also don’t think enough is being done around supply chain security. Organizations should be asking harder questions of their SaaS providers, getting letters of attestation, understanding how these services are secured, and identifying exactly what access those vendors have to their environments.

AI is going to make this problem even bigger.

We’re seeing an explosion of custom-written SaaS applications because AI has dramatically lowered the barrier to building software. That’s fantastic in a lot of ways, but it also means we’re creating more applications, more integrations, more APIs, and ultimately more complexity at an incredible rate.

We’re going to continue seeing vulnerabilities and compromises that originate with third parties. Attackers don’t necessarily need to attack you directly when they can attack something you trust.

Once again, complexity is one of the easiest ways in.

Damon Small, Board of Directors, Xcape, Inc.:

When a third-party application breach hits a healthcare supply chain giant like McKesson, a single vendor integration can escalate into a national patient data crisis. The claim that 284 million records were exfiltrated is alarming, even if core delivery operations remain online. McKesson responded quickly by notifying the Securities and Exchange Commission and engaging external incident response specialists to contain the breach. However, given the company’s central role in drug and supply distribution across North America, organizations supporting critical infrastructure must apply far more rigorous scrutiny to the third-party software partners plugged into their environments. Security teams must enforce least-privilege access, continuously monitor data egress at vendor integration points, and audit partner security controls before a secondary application becomes a primary breach vector.

Critical Takeaways:

  • Exfiltration claims of 284 million patient records demonstrate how third-party application vulnerabilities turn peripheral software into massive data exposure events.
  • Rapid incident response, including SEC notification and external forensic engagement, is vital to containing blast radius when third-party access is compromised.
  • Supporting critical healthcare infrastructure requires rigorous ongoing security auditing and strict access bounds for all vendor software integrations.

When you deliver one-third of a continent’s medicine, your third-party vendors are no longer optional software; they are critical infrastructure.

KEYWORDS: data breach data breach notification data breaches third-party cybersecurity third-party risk

Share This Story

Looking for a reprint of this article?
From high-res PDFs to custom plaques, order your copy today!

Jordynalger

Jordyn Alger is the managing editor for Security magazine. Alger writes for topics such as physical security and cyber security and publishes online news stories about leaders in the security industry. She is also responsible for multimedia content and social media posts. Alger graduated in 2021 with a BA in English – Specialization in Writing from the University of Michigan. Image courtesy of Alger

Recommended Content

JOIN TODAY
To unlock your recommendations.

Already have an account? Sign In

  • Cyber tech background

    Security’s Top Cybersecurity Leaders 2026

    Security magazine’s Top Cybersecurity Leaders 2026 award...
    Top Cybersecurity Leaders
  • Iintegration and use of emerging tools

    Future Proof Your Security Career with AI Skills

    AI’s evolution demands security leaders master...
    Career Intelligence
    By: Jerry J. Brennan and Joanne R. Pollock
  • The 2025 Security Benchmark Report

    The 2025 Security Benchmark Report

    The 2025 Security Benchmark Report surveys enterprise...
    The Security Benchmark Report
    By: Rachelle Blair-Frasier
Manage My Account
  • Security Newsletter
  • eMagazine Subscriptions
  • Manage My Preferences
  • Online Registration
  • Mobile App
  • Subscription Customer Service

More Videos

Sponsored Content

Sponsored Content is a special paid section where industry companies provide high quality, objective, non-commercial content around topics of interest to the Security audience. All Sponsored Content is supplied by the advertising company and any opinions expressed in this article are those of the author and not necessarily reflect the views of Security or its parent company, BNP Media. Interested in participating in our Sponsored Content section? Contact your local rep!

close
  • Northland Controls sponsored content
    Sponsored byNorthland Controls

    The Execution Gap: Why Great Security Design Doesn't Always Deliver Great Security

Popular Stories

Security's Most Influential people 2026

Security’s Most Influential People in Security 2026

Man in suit looking out window at city

Why GSOCs and Protective Intelligence Are the Cornerstone of Executive Protection

Person working on laptop

When Cyber Meets Physical: Rethinking Data Management for a New Threat Landscape

Open filing cabinet

The Inside Job: Corporate Espionage Never Went Away

Black laptop keyboard with white lighting

Fighting Fire with Fire: How Businesses Are Using AI to Enhance Risk Management


AlertMedia sponsored webinar

Events

September 22, 2026

How to Detect, Verify, and Respond to AI-Driven Disinformation

LIVE: September 22, 2026 at 2 PM EDT Identify emerging threats, validate information with confidence, and coordinate an effective response across your organization. Learn how to build the people, processes, and technology needed to improve speed-to-truth.

September 24, 2026

Physical Security Under the Microscope: The Top 4 Gaps That Fail Compliance Audits

LIVE: September 24, 2026 at 2 PM EDT Security and compliance reviews of physical security devices tend to fail for the same reasons. Learn the gaps that trip up these reviews, and why they're getting harder to ignore as scrutiny on connected devices increase. 

View All Submit An Event

Products

Security Culture: A How-to Guide for Improving Security Culture and Dealing with People Risk in Your Organisation

Security Culture: A How-to Guide for Improving Security Culture and Dealing with People Risk in Your Organisation

See More Products

Related Articles

  • Adidas shoes

    Adidas Confirms Data Breach, Security Leaders Weigh In

    See More
  • Padlock with computer keys

    Breach of FBI Surveillance System Considered a “Major Incident,” Security Experts Weigh In

    See More
  • Trees around The Capitol Building

    CISA Director Jen Easterly to resign, cybersecurity experts weigh in

    See More

Related Products

See More Products
  • Hospitality Security: Managing Security in Today's Hotel, Lodging, Entertainment, and Tourism Environment

  • CASP.jpg.jpg

    CASP+ CompTIA Advanced Security Practitioner Certification All-In-One Exam Guide...

  • s in europe.jpg

    Surveillance in Europe

See More Products
×

Sign-up to receive top management & result-driven techniques in the industry.

Join over 20,000+ industry leaders who receive our premium content.

SIGN UP TODAY!
  • RESOURCES
    • Advertise
    • Contact Us
    • Store
    • Want More
  • SIGN UP TODAY
    • Create Account
    • eMagazine
    • Newsletter
    • Customer Service
    • Manage Preferences
  • SERVICES
    • Marketing Services
    • Reprints
    • Market Research
    • List Rental
    • Survey/Respondent Access
  • STAY CONNECTED
    • LinkedIn
    • Facebook
    • YouTube
    • X (Twitter)
  • PRIVACY
    • PRIVACY POLICY
    • TERMS & CONDITIONS
    • DO NOT SELL MY PERSONAL INFORMATION
    • PRIVACY REQUEST
    • ACCESSIBILITY

Copyright ©2026. All Rights Reserved BNP Media, Inc. and BNP Media II, LLC.

Design, CMS, Hosting & Web Development :: ePublishing