One Medical disclosed that an unauthorized party accessed third‑party file storage systems owned by its One Medical Seniors unit (formerly Iora Health) between June 8 and June 11. The vendor‑managed repository held legacy patient and operational data inherited through acquisition; One Medical said core One Medical systems were not implicated. The incident illustrates how legacy and third‑party systems remain a frequent vulnerability following healthcare mergers.
Security experts warn such breaches directly affect AI in healthcare: exposed records can contaminate training datasets, undermine privacy protections, and expand attack surfaces for extortion groups seeking protected health information. The event reinforces the need for HIPAA‑aligned governance of inherited data, robust third‑party vetting, and AI‑driven monitoring and anomaly detection to safeguard patient data as providers consolidate datasets for clinical AI applications.





