News|Articles|September 4, 2026

Hackers claim 284 million records in McKesson breach; physicians say misinformation is hurting care; Kennedy targets the AMA's CPT codes — Morning Medical Update Weekly Recap

Fact checked by: Keith A. Reynolds

Key Takeaways

  • McKesson reports containment with core systems operational, while attackers claim 1 TB exfiltration and a $55.2M ransom demand; record counts and attribution remain unverified.
  • Vishing-enabled SSO compromise underscores integration and vendor-risk exposure that can implicate practices indirectly; clinics should review BAAs, data flows in ordering/billing, and notification triggers.
SHOW MORE

The top news stories in medicine this week.

Hackers claim 284 million records in McKesson breach

The company confirmed data was taken from its oncology and medical-surgical customers. The 284 million figure comes from the attackers.

McKesson Corp. disclosed a cybersecurity incident Aug. 28, saying attackers gained unauthorized access to third-party applications and exfiltrated data. The company said it discovered the intrusion Aug. 25 and reported it in a Form 8-K filing with the U.S. Securities and Exchange Commission, adding that it had not determined the incident was material or likely to have a material impact on its financial condition or results of operations. McKesson ranked No. 8 on this year's Fortune 500 with $359.05 billion in revenue, third among health care companies behind UnitedHealth Group and CVS Health, and it delivers roughly one-third of prescription medicines to North American hospitals, pharmacies and clinics.

Based on early investigation results, McKesson said the incident appears to involve data relating to a subset of customers of its Oncology & Multispecialty and Medical-Surgical business units. The company said its core systems and services remain available despite intermittent disruptions, that its initial containment steps appear to have worked with no further unauthorized activity detected, and that its investigation remains in the early stages.

The extortion group ShinyHunters claimed responsibility, telling BleepingComputer that it removed roughly 1 terabyte of data between Aug. 21 and Aug. 25 and demanded $55,236,150 with a 72-hour deadline it said went unanswered. The group said the haul covers about 284 million records and listed names, addresses, dates of birth, Social Security numbers, patient IDs, Medicaid numbers, medical record numbers, medication and allergy information and physician information among the data types. ShinyHunters also said the 284 million figure is a raw count of database rows rather than unique individuals, and that it has not finished analyzing what it took. McKesson has not attributed the attack to the group or confirmed the record count, and none of the group's claims have been independently verified.

ShinyHunters said it got in through voice phishing calls to McKesson employees, then used compromised single sign-on credentials to reach cloud data platforms. That makes this a vendor and integration exposure rather than a clinical systems failure, which is what puts it in front of practices that never touched the compromised software. Practices that order through McKesson should confirm whether they have received or should expect a breach notification, review what patient data moves through McKesson-connected ordering and billing workflows, and check their business associate agreement terms in case their own patient notification obligations are triggered.

Related content: The cyber siege of private practices: Are you at risk? and How to protect your practice when a data breach hits a partner

65% of physicians say misinformation is hurting the care they provide

Up from 57% a year ago, and 70% among primary care physicians.

The Physicians Foundation released its 2026 Survey of America's Physicians this week, an online survey of 1,002 U.S. physicians fielded March 4-18. Physicians reporting a moderate or major impact from misinformation on their ability to provide quality care rose to 65% from 57% in 2025. Among primary care physicians the figure was 70%, compared with 61% of specialists. The share encountering patients influenced by misinformation a moderate amount or a great deal over the past year rose to 69% from 61%.

The consequences physicians reported are behavioral. Two-thirds, 66%, said misinformation often or very often drives increased patient anxiety. Nearly half, 49%, reported medication or treatment nonadherence, 45% reported patients refusing recommended care and 43% reported unnecessary tests or procedures. One in three, 34%, reported a breakdown of trust with patients, the same share that reported emergency room and urgent care overuse, and 31% reported increased conflict during visits. Refusal of recommended care ran higher among primary care physicians at 51%, compared with 41% of specialists, and higher among employed physicians at 49%, compared with 37% of independent physicians.

Asked where the misinformation originates, 85% of physicians said social media contributes often or very often, followed by word of mouth and influencers at 74% each, news coverage at 58% and search engines at 57%. Asked to name the single biggest driver, 48% chose social media, more than 2.5 times the next answer, influencers at 17%. Artificial intelligence chatbots ranked near the bottom, named a frequent contributor by 33% and the single biggest driver by 3%, though Gary Price, M.D., MBA, president of The Physicians Foundation, has noted the survey closed in March, before much of this year's public debate about AI.

Government health agencies drew 28%, with primary care physicians more likely than specialists to name them, 33% to 25%, and 6% calling them the single most significant driver. That finding lands alongside a separate Annenberg Public Policy Center survey of 1,904 adults released Aug. 31, which found confidence in the CDC, FDA and NIH has fallen to between 59% and 61% from between 72% and 74% in September 2024, while confidence in one's own doctor, nurse or other primary care clinician held at 87%.

Physicians also reported thin margins for the conversation itself. Just 26% said they are confident or very confident they have the tools and support to engage patients skeptical of modern medicine, down from 37% in 2025, and 34% said they are not at all confident they have the necessary time. Another 43% said they have no confidence their patients know how to find reliable, evidence-based health information online. Rural physicians reported the highest exposure to misinformation-influenced patients at 78%, compared with 67% of urban physicians, though rural physicians were the smallest geographic subgroup in the sample at 91 respondents.

Related content: Medicine under attack: How physicians can help their patients navigate the disinformation age and Doctors report spike in misinformation from patients

Kennedy targets the AMA's control of CPT codes

Comments on the 2027 Medicare Physician Fee Schedule close Sept. 14, and the docket has already drawn more than 19,000 submissions.

Health and Human Services Secretary Robert F. Kennedy Jr. posted a video Aug. 27 urging Americans to comment on a federal request for information about medical billing codes. Kennedy said Current Procedural Terminology (CPT) codes are owned exclusively by the American Medical Association (AMA), that about 20% of U.S. physicians belong to the association and that organizations across health care paid the AMA more than $300 million last year to use the codes. HHS did not present supporting documentation for the membership percentage or the royalty totals, and Kennedy presented both as assertions.

The AMA says licensing revenue funds the editorial process that creates and maintains the code set, and describes CPT as the uniform language of medicine, updated through an open process that reflects evolving clinical care. AMA CEO John Whyte, M.D., wrote to Sen. Bill Cassidy, M.D., R-Louisiana, on Oct. 23, 2025, that CPT license fees run $18.50 per year for each user and that health plans pay 24 cents per member per year.

The docket is the CY 2027 Medicare Physician Fee Schedule proposed rule, file code CMS-1848-P. CMS asks commenters to identify harms tied to AMA licensing of CPT-4 and improvements to patient care the arrangement may have delayed, including the cost of licensure. It asks whether private competition could supplement the standard, what alternatives exist to the AMA/Specialty Society Relative Value Scale Update Committee and whether ICD-10-PCS could serve as a basis for paying physicians. ICD-10-PCS is the procedure code set CMS maintains for hospital inpatient billing and publishes at no cost, though it does not describe office visits or most outpatient care.

CMS mandated CPT for Medicare Part B billing in 1983 and for state Medicaid programs in 1986, and the Health Insurance Portability and Accountability Act established it as the national standard for physician billing in 1996. A request for information is not a proposal, and CMS has set no timeline and is under no obligation to act on what comes in. The same proposed rule leans on the association heavily, proposing to accept close to 100% of the AMA's direct practice expense recommendations for 2027. The arrangement has also drawn scrutiny from Republican lawmakers, and a separate lawsuit asks a court to declare the AMA's CPT copyrights invalid and unenforceable. The AMA says it plans to fight it.

Related content: CMS wants to know if the CPT coding monopoly is hurting patient care