Six Point Four Million Addresses (09/18/2026)
- › McKesson said the data stolen in its cyberattack includes 6.4 million unique email addresses.
- › Ambry Genetics agreed to pay a $700,000 penalty to settle HIPAA violations.
- › Democratic senators reintroduced the Health Infrastructure Security and Accountability Act.
- › HHS-OIG urged CMS and Medicare Advantage organizations to do more against durable medical equipment fraud.
- › Community Dental Care settled a class action over a data breach.
A notification population is the number that decides what an incident costs, and it is almost always established weeks after the intrusion by counting rows rather than by anything the attacker did. McKesson has now published its figure, and 6.4 million unique addresses is the scale a distributor reaches without holding a single patient relationship of its own.
Top 5 Critical Compliance Alerts
1. McKesson Puts a Number on the Stolen Data
McKesson disclosed that data taken in its cyberattack includes 6.4 million unique email addresses. A pharmaceutical distributor sits between manufacturers and the pharmacies and providers who dispense, which means it accumulates contact records for an enormous population it never treats. We covered the initial incident and the $55 million demand in late August, and the interval between that and a countable figure is the ordinary shape of these disclosures. HIPAA Journal has the count.
Operator Note: If you hold contact records for people who are somebody else’s customers, work out that population size before an incident, because it is the first question and the slowest one to answer under pressure.
2. Ambry Genetics Pays $700,000 Over HIPAA Violations
The genetic testing company Ambry Genetics agreed to a $700,000 penalty to resolve HIPAA violations. Genetic data is the category where the consequence of exposure extends past the individual to relatives who never contracted with anybody, and the regulatory treatment has not fully caught up with that property. A penalty at this level reads as a finding about compliance, and it does not attempt to price the harm. HIPAA Journal has the settlement.
3. The Health Infrastructure Security Bill Returns
Democratic senators reintroduced the Health Infrastructure Security and Accountability Act, which would impose minimum cybersecurity requirements on healthcare organizations. Reintroduction signals the sponsors think conditions have changed and not that the drafting has, and the run of provider and vendor breaches across this month is the condition being pointed at. Any organization that would be in scope should read the requirements now, while they are still a bill. HIPAA Journal has the legislation.
4. HHS-OIG Presses CMS on Equipment Fraud
The HHS Office of Inspector General urged CMS and Medicare Advantage organizations to increase their efforts against durable medical equipment fraud. An OIG recommendation directed at both the regulator and the plans is a signal that the watchdog considers the existing controls insufficient at both levels. For plans, the practical exposure sits in the claims review process and nowhere technical. HIPAA Journal has the recommendations.
5. Community Dental Care Settles Its Breach Class Action
Community Dental Care agreed to settle a class action over a data breach, the fourth dental or small-provider settlement we have covered this month. The repetition is the finding, since these organizations sit at a size with full clinical records and no dedicated security function, and the litigation arrives at the same reliability regardless. A practice group learns the cost of the gap only once. HIPAA Journal has the settlement.
Operator Note: If your organization is under about two hundred people and holds clinical or financial records, assume litigation follows a breach automatically and reserve on that basis.
Additional Compliance Alerts
Reporting and Filing
- ACA reporting season exposes the same errors every year: An analysis of where 1095-C compliance actually goes wrong points at data quality upstream of the filing rather than at the filing itself. Corporate Compliance Insights
International
- Australia advanced its digital duty of care: The online safety reforms continue to move, and Australia remains the clearest preview of platform obligations arriving elsewhere. JD Supra
The Axe Report is a daily briefing from Grab The Axe. Need help assessing your organization’s security posture? Take our free Human Attack Surface Score assessment.
A leader defined by a 'bias for action,' Dusten specializes in physical security assessments that impact profitability and facility resilience.
View Profile →Media Inquiries
For expert commentary, interview requests, or high-res assets regarding this announcement, initialize the terminal.