
Michele Garand filed a class action lawsuit against McKesson Corp. in the U.S. District Court for the Northern District of Texas on Aug. 31, 2026.
The lawsuit alleges the pharmaceutical distributor experienced a data breach in August that compromised the Social Security numbers, medical diagnoses and prescription records of patients across the country, It also claims McKesson failed to secure the data, leaving it exposed to cybercriminals.
Data breach details
The data breach reportedly occurred on or around Aug. 25, 2026, and the company says it reported the incident to the Securities and Exchange Commission that same day. McKesson claims it activated its incident response protocols and brought in outside cybersecurity experts.
The complaint alleges ShinyHunters, a cybercriminal group that posted on its dark web leak site on or around Aug. 29, 2026, claimed it hacked McKesson and obtained hundreds of millions of records.
The stolen data reportedly included:
- Names and dates of birth
- Social Security numbers
- Home addresses
- Health insurance information
- Medical records covering prescriptions, diagnoses and treatment
Garand alleges she suffers from anxiety, sleep disruption, stress and fear since the breach and claims her private information lost value one it reached criminals. McKesson had allegedly not mailed individualized data breach notice letters as of the filing date, which the lawsuit claims deprives people of the chance to limit the damage.
The lawsuit's allegations
The proposed class action alleges McKesson's protections did not match the sensitivity of the data it held even though its privacy notice says it has "proper physical, electronic and administrative safeguards." The company failed to train employees on cybersecurity or maintain reasonable safeguards, the complaint claims.
The complaint cites two benchmarks McKesson allegedly missed: the National Institute of Standards and Technology's Cybersecurity Framework Version 2.0 and the Center for Internet Security's Critical Security Controls. The filing also claims violations of Health Insurance Portability and Accountability Act rules governing patient data and Federal Trade Commission data security guidance.
The legal claims
Garand brings eight claims:
- Negligence, which alleges McKesson failed to use reasonable care with the data it collected
- Negligence per se, which treats a violation of a law such as HIPAA as proof of carelessness on its own
- Breach of implied contract, which is a theory that part of what customers paid covered data security
- Invasion of privacy, which applies when a company exposes information a person expected to stay private
- Unjust enrichment, which claims McKesson saved money by spending less on data security than it should have
- Breach of fiduciary duty and breach of confidence, which claim patients paced trust in the company
- Declaratory judgment, which isa ruling spelling out what the parties owe each other going forward
The suit seeks compensatory, punitive and statutory damages, restitution, attorneys' fees and an injunction requiring stronger security.
What the case means for affected individuals
The proposed class covers everyone in the United States whose private information the August breach compromised. No settlement, no claims process and no money exists at this stage.
.png)







.webp)
.webp)
.webp)

.webp)
.webp)
.webp)
.webp)



