Six Point Four Million Addresses (09/18/2026)

September 18, 2026
Six Point Four Million Addresses (09/18/2026)
Key Intel / TL;DR
  • McKesson said the data stolen in its cyberattack includes 6.4 million unique email addresses.
  • Ambry Genetics agreed to pay a $700,000 penalty to settle HIPAA violations.
  • Democratic senators reintroduced the Health Infrastructure Security and Accountability Act.
  • HHS-OIG urged CMS and Medicare Advantage organizations to do more against durable medical equipment fraud.
  • Community Dental Care settled a class action over a data breach.

A notification population is the number that decides what an incident costs, and it is almost always established weeks after the intrusion by counting rows rather than by anything the attacker did. McKesson has now published its figure, and 6.4 million unique addresses is the scale a distributor reaches without holding a single patient relationship of its own.

Top 5 Critical Compliance Alerts

1. McKesson Puts a Number on the Stolen Data

McKesson disclosed that data taken in its cyberattack includes 6.4 million unique email addresses. A pharmaceutical distributor sits between manufacturers and the pharmacies and providers who dispense, which means it accumulates contact records for an enormous population it never treats. We covered the initial incident and the $55 million demand in late August, and the interval between that and a countable figure is the ordinary shape of these disclosures. HIPAA Journal has the count.

Operator Note: If you hold contact records for people who are somebody else’s customers, work out that population size before an incident, because it is the first question and the slowest one to answer under pressure.

2. Ambry Genetics Pays $700,000 Over HIPAA Violations

The genetic testing company Ambry Genetics agreed to a $700,000 penalty to resolve HIPAA violations. Genetic data is the category where the consequence of exposure extends past the individual to relatives who never contracted with anybody, and the regulatory treatment has not fully caught up with that property. A penalty at this level reads as a finding about compliance, and it does not attempt to price the harm. HIPAA Journal has the settlement.

3. The Health Infrastructure Security Bill Returns

Democratic senators reintroduced the Health Infrastructure Security and Accountability Act, which would impose minimum cybersecurity requirements on healthcare organizations. Reintroduction signals the sponsors think conditions have changed and not that the drafting has, and the run of provider and vendor breaches across this month is the condition being pointed at. Any organization that would be in scope should read the requirements now, while they are still a bill. HIPAA Journal has the legislation.

4. HHS-OIG Presses CMS on Equipment Fraud

The HHS Office of Inspector General urged CMS and Medicare Advantage organizations to increase their efforts against durable medical equipment fraud. An OIG recommendation directed at both the regulator and the plans is a signal that the watchdog considers the existing controls insufficient at both levels. For plans, the practical exposure sits in the claims review process and nowhere technical. HIPAA Journal has the recommendations.

5. Community Dental Care Settles Its Breach Class Action

Community Dental Care agreed to settle a class action over a data breach, the fourth dental or small-provider settlement we have covered this month. The repetition is the finding, since these organizations sit at a size with full clinical records and no dedicated security function, and the litigation arrives at the same reliability regardless. A practice group learns the cost of the gap only once. HIPAA Journal has the settlement.

Operator Note: If your organization is under about two hundred people and holds clinical or financial records, assume litigation follows a breach automatically and reserve on that basis.

Additional Compliance Alerts

Reporting and Filing

  • ACA reporting season exposes the same errors every year: An analysis of where 1095-C compliance actually goes wrong points at data quality upstream of the filing rather than at the filing itself. Corporate Compliance Insights

International

  • Australia advanced its digital duty of care: The online safety reforms continue to move, and Australia remains the clearest preview of platform obligations arriving elsewhere. JD Supra

The Axe Report is a daily briefing from Grab The Axe. Need help assessing your organization’s security posture? Take our free Human Attack Surface Score assessment.

Distribute Intel
Dusten Trounce
Director of Physical Security
Dusten Trounce
The Growth Architect.

A leader defined by a 'bias for action,' Dusten specializes in physical security assessments that impact profitability and facility resilience.

View Profile →
Press & Media

Media Inquiries

For expert commentary, interview requests, or high-res assets regarding this announcement, initialize the terminal.

Initialize Terminal

Initiate
Deployment.

Whether you need a full adversarial facility audit or an executive resilience protocol for your leadership team.

Secure the Facility (Assessments)
Secure the Mind (Coaching/Speaking)