Medtronic Data Breach Impacts 3.8 Million: Social Security Numbers and Health Records Exposed

Published
April 27, 2026
Updated
July 23, 2026
Medtronic Data Breach Impacts 3.8 Million: Social Security Numbers and Health Records Exposed
Medtronic

Medtronic, the world's largest medical device company by revenue, disclosed on April 24, 2026, that an unauthorized party accessed data in certain corporate IT systems. The total number of individuals affected by the breach was determined to be 3,834,294, including 297,307 Texas residents, 90,889 Indiana residents, 64,035 Washington residents, 63,534 Massachusetts residents, 12,215 New Hampshire residents and 8,668 Vermont residents were impacted.

On April 17, 2026, a threat actor known as ShinyHunters posted a claim on the dark web's Tor network alleging they had breached Medtronic's database. The threat actor claimed to have obtained over 9 million records containing personally identifiable information (PII), along with additional terabytes of internal corporate data.

One week later, on April 24, 2026, Medtronic publicly confirmed that an unauthorized party had accessed data within certain corporate IT systems through a notice on its website. The company filed disclosures with the U.S. Securities and Exchange Commission and with the California Attorney General.

The company emphasized that the networks supporting its corporate IT systems are separate from those supporting its medical device products and its manufacturing and distribution operations.

The specific types of personal information that may have been exposed include names, dates of birth, Social Security numbers, medical information and health records.

Medtronic has not publicly verified the claims made by ShinyHunters regarding the volume or nature of the compromised data. The investigation into the full scope of the breach remains ongoing.

Medtronic's response to the breach

Upon identifying the unauthorized access, Medtronic stated that it took steps to contain the incident. The company activated its incident response protocols and engaged leading cybersecurity experts to support its investigation and remediation actions.

The company is working to identify any personal information that may have been accessed during the breach.

Medtronic stated it will provide notifications and support services as needed to individuals whose data may have been affected. It also said it will continue to provide updates to impacted individuals as it learns more about the scope of the incident.

Types of INFORMATION affected
  • Names
    Names
  • Social security numbers
    Social Security Numbers
  • Dates of birth
    Dates of Birth
  • Addresses
    Addresses
  • Government IDs
    Government IDs
  • Medical Information
    Medical Info
  • Financial Info
    Financial Info
  • Affected information types not yet disclosed

Notice Letter

This browser does not support inline PDFs. Please download the PDF to view it: Download PDF

Affected Entity
Medtronic
Consumers Notification date
June 29, 2026
Date of Breach
April 13, 2026
Breach Discovered Date
April 15, 2026
Total People Affected
3834294
Information Types Exposed
  • Address
  • Date of birth
  • Full name
  • Health Records
  • Health Savings Account information
  • Healthcare Insurance Plan ID
  • Medical Record Number
  • Medical Records
  • Medicare Beneficiary Identifier ID numbers
  • Name of individual
CTA Image
CTA Image
CTA Image
CTA Image
CTA Image
CTA Image
CTA Image
CTA Image
CTA Image