Amazon's One Medical Breach Leaks Seniors' Medicare and Social Security Data
Amazon-owned One Medical confirmed a June 2026 breach of its Seniors division, exposing Medicare numbers, Social Security data, and treatment records of elderly patients. Here's what happened and what to do.
The Breach In June 2026, One Medical — the primary care company Amazon acquired for nearly $4 billion — confirmed that unauthorized parties accessed patient data held by One Medical Seniors, its division serving Medicare-eligible patients, formerly known as Iora Health. The notification process began after the company identified unusual access to systems holding protected health information (PHI). What makes this breach different from the routine stream of healthcare incidents is who was affected: elderly patients, a population that is disproportionately harmed by identity theft and medical fraud, and least equipped to unwind the damage. What Was Exposed Reports and class-action investigations point to a broad set of records, including: Social Security numbers
Medicare identification numbers
Demographic and contact details
Treatment plans and prescription information
Diagnostic and imaging data That last category matters. Medical records can't be "changed" the way a credit card can. A leaked Social Security number or Medicare ID follows a person for life, and a falsified or sold medical record can poison future care decisions — a denied claim, a wrong diagnosis, a mistaken allergy listed on a file you never saw. Why Healthcare Breaches Keep Happening One Medical is far from alone. The healthcare sector has accounted for the largest share of reported breaches in the United States for years running, and the reasons are structural: Consolidation. Amazon buying One Medical, which had absorbed Iora Health, means patient data now lives in systems that change owners — and security postures — faster than patients ever learn about it.
Legacy infrastructure. Medical systems run decades-old software that hospitals and clinics are slow to patch.
Data density. A single healthcare record is worth more on the black market than a credit card because it contains everything needed to commit identity theft and insurance fraud. What Seniors (and Everyone Else) Should Do Check for a notification letter. Legitimate breach notices come in writing; be skeptical of any call or text claiming to be from One Medical that asks you to "verify" details.
Freeze your credit. A credit freeze is free, stops new accounts being opened in your name, and doesn't hurt your credit score. Do it at all three bureaus.
Watch Medicare statements. Review Medicare Summary Notices for charges you don't recognize. Report suspected fraud to Medicare's fraud line.
Assume phishing is coming. Breached data fuels targeted scams — including voice-cloned "grandparent" calls. Agree on a family code word.
Get your records and audit access. Under HIPAA you can request an accounting of disclosures for your records from any covered provider. The Pattern Healthcare is where the "they didn't ask" problem stops being abstract. Nobody consents to their Medicare number being bundled with their prescriptions and sold down a chain of acquisitions. The sector's answer is always a press release, a year of credit monitoring, and a quiet settlement. The real fix is structural: stricter data-minimization rules for health data, meaningful penalties for slow disclosure, and enforcement that doesn't depend on whoever controls the FTC this quarter. On that last point, see our explainer on the Supreme Court ruling that just gutted FTC independence — and why healthcare enforcement is about to get even more volatile. Related reading: HIPAA in 2026: Why Healthcare Data Still Leaks and State Health Exchange Data Leaks.