1Life Healthcare Data Breach Exposes Patient Health and Personal Information

Healthcare data breach illustration
Breach Discovery: Not Publicly DisclosedBreach Notification: July 2026

What Happened in the 1Life Healthcare Data Breach?

1Life Healthcare, Inc., the company behind the One Medical and Iora Health primary care brands, recently filed a data breach notification with the Washington State Attorney General. This filing confirms that the company identified unauthorized access to sensitive systems containing patient information. As a result, individuals connected to One Medical and Iora Health may now be at risk of identity theft and fraud.

According to the filing, 1Life Healthcare determined that certain patient data had been compromised. The notification does not provide extensive detail about the exact method the attacker used. However, the fact that a formal breach notification was filed confirms that personal information was accessed without authorization.

In response, the company reportedly launched an internal review to determine the scope of the incident. This type of investigation typically involves forensic specialists who trace how the intrusion occurred and which systems were touched. Because healthcare providers store extremely sensitive data, this kind of review is especially important for understanding the full impact.

1Life Healthcare has not publicly disclosed the exact date the unauthorized access began. Therefore, this article focuses on what is confirmed: that a breach occurred and that regulators were formally notified. As more details emerge, affected patients should watch for updates from the company directly.

Who was affected?

The breach notification indicates that patients associated with One Medical and Iora Health may be affected. Because both brands provide primary care and membership-based medical services, this incident could touch a broad range of patients across multiple states. The exact number of impacted individuals has not been publicly disclosed.

Given that One Medical operates in numerous US markets and Iora Health has historically served older adult populations, the affected group could include a wide range of ages. In addition, because these are healthcare providers, both current and former patients may be impacted. Some individuals may have received care years ago and might not expect their information to still be at risk today.

What Information Was Potentially Exposed?

Because 1Life Healthcare operates as a healthcare provider, the data involved in this breach likely includes sensitive medical and personal details. While the filing does not itemize every data element, breaches at healthcare organizations commonly involve the following types of information.

  • Full names
  • Contact information such as addresses and phone numbers
  • Dates of birth
  • Medical record information
  • Health insurance details
  • Patient account or membership identifiers

If this information was indeed exposed, affected patients could face a heightened risk of identity theft. For example, criminals often use stolen medical details to file fraudulent insurance claims or obtain prescription medications under someone else’s name. This is sometimes called medical identity theft, and it can be difficult to detect until a patient reviews their insurance statements closely.

In addition, exposed contact information can lead to targeted phishing attempts. Scammers frequently pose as healthcare providers to trick victims into revealing further personal details. Because the stolen data may include real appointment or membership information, these phishing attempts can appear highly convincing.

What is the company doing?

1Life Healthcare took the step of formally notifying the Washington State Attorney General, which is a legally required action when residents’ personal information is compromised. This notification process typically also requires the company to notify affected individuals directly by mail or email. As a result, patients connected to One Medical or Iora Health should watch for an official notification letter.

Beyond notification, healthcare companies experiencing a breach commonly take additional remediation steps. These often include tightening system access controls, resetting credentials, and working with cybersecurity firms to close any exploited vulnerabilities. While the specific details of 1Life Healthcare’s technical response have not been publicly disclosed, similar organizations frequently offer credit monitoring or identity protection services to affected patients as a goodwill measure.

What Should Affected Individuals Do?

Monitor Your Credit Reports

Affected individuals should request a free copy of their credit report from each of the three major credit bureaus. Reviewing these reports regularly can help you spot unfamiliar accounts or inquiries early. Because medical identity theft can sometimes lead to new financial accounts being opened in your name, this step is especially important.

You can access free weekly credit reports through AnnualCreditReport.com. In addition, consider setting a recurring reminder to check your reports every few months going forward. This habit makes it much easier to catch fraud before it causes lasting damage.

Consider a Credit Freeze or Fraud Alert

Because personal information may have been exposed, placing a credit freeze can prevent criminals from opening new accounts in your name. A freeze restricts access to your credit file until you choose to lift it. This is one of the strongest protections available to consumers.

Alternatively, a fraud alert requires creditors to verify your identity before extending new credit. This option is less restrictive than a freeze but still adds an important layer of protection. Either step can be done directly through Equifax, Experian, or TransUnion.

Protect Against Medical Identity Theft

Because this breach involves a healthcare provider, patients should carefully review any insurance statements or medical bills they receive. If you notice unfamiliar treatments, prescriptions, or provider visits listed, this could indicate medical identity theft. Reporting these discrepancies quickly to your insurer can help limit the damage.

In addition, request a copy of your medical records periodically to confirm accuracy. This step helps ensure that no fraudulent diagnoses or treatments have been added to your file. Correcting these errors early can prevent complications with future medical care or insurance coverage.

Stay Alert for Phishing Attempts

Because your contact information may have been exposed, be cautious of unexpected emails, texts, or phone calls claiming to be from One Medical, Iora Health, or your insurer. Scammers often use real breach events as an opportunity to craft convincing messages. Never click links or share personal details unless you can verify the sender independently.

Instead, if you receive a suspicious message, contact the organization directly using a verified phone number or website. This simple step can prevent you from falling victim to a secondary scam that piggybacks on this breach. When in doubt, it is always safer to verify first.

Consult a Data Breach Attorney

Given the sensitive nature of the data potentially involved, affected individuals may want to speak with a data breach attorney. An attorney can help you understand whether you qualify for compensation through a class action or individual claim. Because deadlines for legal action can be strict, seeking guidance sooner rather than later is advisable.

Many attorneys offer free consultations to evaluate your situation at no cost. This means you can explore your legal options without any upfront financial commitment. Taking this step ensures you fully understand your rights following this breach.



More Information

Official data breach notification from Washington State Attorney General

Related Data Breaches

Check other recent data breach notifications →