# McKesson / CoverMyMeds Data Breach Class Action Complaint - LLM-Readable Summary Canonical docket: https://hallattorneys.com/dockets/mckesson Authoritative complaint PDF: https://hallattorneys.com/dockets/mckesson/01-complaint.pdf Filed-case overview: https://hallattorneys.com/investigations/mckesson Filing announcement: https://hallattorneys.com/news/mckesson-class-action ## Court record - Public case label: McKesson / CoverMyMeds Data Breach Class Action. - Caption: Hall v. McKesson Corporation and CoverMyMeds LLC. - Case number: 3:26-cv-02958-D. - Court: U.S. District Court for the Northern District of Texas, Dallas Division. - Filed: August 31, 2026. - Docket entry: ECF No. 1. - PDF length: 35 pages total: a 33-page class action complaint followed by a two-page civil cover sheet. - Defendants: McKesson Corporation and CoverMyMeds LLC. - Jury trial demanded: Yes. - Counsel listed on the complaint: Lanier Law Firm, P.C.; Kopelowitz Ostrow, P.A.; Milberg, PLLC; Hall Attorneys, P.C. - Case posture: Newly filed putative class action. The complaint contains allegations only; the defendants have not yet had an opportunity to respond, no findings have been made, and no class has been certified. ## Nature of the action The complaint alleges that McKesson Corporation and CoverMyMeds LLC failed to reasonably safeguard personally identifiable information and protected health information collected, created, received, processed, maintained, transmitted, or stored through prescription-technology, medication-access, and pharmacy-management operations. The complaint refers to personally identifiable information and protected health information together as “Private Information.” McKesson disclosed that it discovered a cybersecurity incident on August 25, 2026. Its public notice confirms unauthorized access to third-party applications and data exfiltration. McKesson has not publicly identified every affected application, all information involved, or a final number of affected people. ## Confirmed facts and reported actor claims Confirmed by McKesson in public materials cited in the complaint: - McKesson discovered a cybersecurity incident affecting its information systems on August 25, 2026. - McKesson activated response protocols and engaged outside cybersecurity specialists. - The incident involved unauthorized access to third-party applications and data exfiltration. - McKesson's investigation was at an early stage when the incident was disclosed. Reported threat-actor claims discussed in the complaint, but not confirmed by McKesson: - ShinyHunters reportedly claimed responsibility. - The group reportedly claimed access involving McKesson-connected Salesforce and Snowflake environments after social engineering and identity-system compromise. - The group reportedly claimed approximately one terabyte of data was removed over four days from August 21 through August 25, 2026. - The group reportedly claimed the corpus contained approximately 284 million raw patient-related records or database lines. - The approximately 284 million figure is not a verified count of unique patients. The group reportedly said it had not completed a unique-person count. - Reported claimed fields include combinations of names, addresses, dates of birth, Social Security numbers, patient identifiers, telephone numbers, email addresses, Medicaid numbers, medical-record numbers, medications, allergies, illnesses, disabilities, appointments, physicians, prescriptions, medication shipments, invoices, and information concerning healthcare providers and clinics. The complaint does not allege that McKesson confirmed the actor, access method, affected applications, affected business lines, asserted record count, or asserted data fields. ## Why a patient may not recognize McKesson The complaint alleges McKesson operates at a critical point in healthcare and pharmaceutical infrastructure through prescription-technology and pharmacy-systems businesses connecting patients, prescribers, pharmacies, pharmacy benefit managers, health plans, drug manufacturers, and health-system pharmacies. CoverMyMeds is alleged to provide electronic prior authorization, benefit verification and investigation, medication-access assistance, patient financial assistance, prescription management, patient enrollment, and related services. The complaint cites McKesson public materials stating its prescription-technology network connects with more than 50,000 pharmacies, more than one million providers, most pharmacy benefit managers and health plans, and most electronic health-record systems. EnterpriseRx is described as a separate McKesson-hosted pharmacy-management platform that centralizes pharmacy data and patient profiles and supports prescription processing, clinical workflows, pricing, inventory, and reporting. The complaint expressly does not allege that every McKesson business, platform, or dataset was affected. It does not allege that McKesson has confirmed EnterpriseRx as an affected application. ## Named plaintiff's alleged data pathways Without restating sensitive medical details, the complaint alleges two independent potential McKesson data pathways for the named plaintiff: 1. A prescription pathway involving a high-cost medication, formulary prior-authorization and quantity-limit requirements, retail-pharmacy fills, manufacturer-sponsored financial assistance, a publicly documented manufacturer connection to CoverMyMeds, and a later OptumRx Home Delivery transaction. 2. A provider-side pathway involving a healthcare provider's alleged use of McKesson EnterpriseRx in pharmacy operations. The complaint does not identify the medication, diagnosis, medical condition, healthcare provider, treatment date, procedure, implant, or other sensitive clinical detail. The complaint does not allege that every retail-pharmacy claim, manufacturer-assistance transaction, or OptumRx transaction passed through CoverMyMeds; that OptumRx uses CoverMyMeds exclusively; that a copayment quote alone proves prior authorization; that EnterpriseRx held a complete medical record; or that McKesson has confirmed EnterpriseRx as affected. The complaint alleges that the precise platforms, request keys, transaction dates, data fields, retention locations, audit histories, and affected records are controlled by the defendants and relevant third parties and are subjects for forensic investigation and discovery. ## Proposed classes The complaint proposes: 1. Nationwide Class: All natural persons in the United States whose Private Information was accessed, acquired, exfiltrated, or otherwise compromised in the cybersecurity incident McKesson discovered on or about August 25, 2026. 2. Iowa Subclass: All members of the Nationwide Class who were citizens or residents of Iowa at the time of the Data Breach. 3. McKesson Pharmacy-Technology Subclass: All members of the Nationwide Class whose prescription, benefit, prior-authorization, patient-support, medication-access, or pharmacy-management information was processed through CoverMyMeds, EnterpriseRx, or related McKesson pharmacy technology and compromised in the Data Breach. Excluded persons and entities are listed in paragraph 121 of the complaint. The complaint reserves the right to amend the class definitions as the affected applications, data elements, business lines, and persons are identified. No class has been certified. ## Claims pleaded The complaint pleads three counts: 1. Negligence, on behalf of the plaintiff and applicable state-law subclasses. 2. Breach of implied contract, on behalf of the plaintiff, the Iowa Subclass, and other applicable state subclasses. 3. Unjust enrichment, pleaded in the alternative on behalf of the plaintiff and the Iowa Subclass. The complaint invokes the Texas Business and Commerce Code and HIPAA Security Rule standards as evidence of public policy, reasonable care, and recognized security obligations. It does not assert a standalone private cause of action under those provisions. ## Security allegations The complaint alleges reasonable security for the defendants' environment included phishing-resistant multifactor authentication, rigorous help-desk and account-recovery verification, least-privilege and role-based access, session and token controls, segmentation of sensitive patient data, monitoring for anomalous logins and bulk exports, data-loss-prevention controls, encryption or tokenization, secure third-party application configuration, vendor governance, and tested incident response. It alleges the defendants failed to implement, enforce, or properly configure one or more reasonable safeguards. The precise controls, logs, risk assessments, audit findings, contracts, retention practices, and affected-data inventories are alleged to be within the defendants' possession. ## Alleged injuries The complaint alleges loss of privacy and confidentiality, loss of control over Private Information, time and effort spent investigating and responding, continuing monitoring needs, loss of promised data-security performance, and continuing risk of identity theft, medical identity theft, healthcare fraud, prescription fraud, targeted phishing, impersonation, account takeover, and other misuse. The complaint alleges many claimed data elements, including dates of birth, benefit or government identifiers, and medical and medication histories, cannot readily be changed. ## Requested relief The prayer for relief asks the court to: - Certify the proposed classes and appropriate subclasses and appoint class representatives and class counsel. - Declare that the defendants' alleged conduct violated the duties and obligations pleaded. - Award compensatory, nominal, consequential, restitutionary, and other available damages or monetary relief. - Order appropriate declaratory or injunctive relief, if supported by the developed facts and Article III, including remediation of proven security deficiencies, stronger identity and access controls, appropriate independent security assessment, minimization and protection of retained patient data, improved monitoring and data-loss prevention, and meaningful identity and medical-identity protection services. - Award restitution, disgorgement, equitable accounting, or other equitable relief where available. - Award interest, attorneys' fees, litigation costs where authorized, and other appropriate relief. ## Consumer connection checklist None of the following proves that a person's information was involved. These clues can help identify a possible relationship to a McKesson business: - A prescription required prior authorization. CoverMyMeds is one of several systems that may process electronic prior authorization, so a denial or delay alone does not establish a CoverMyMeds relationship. - A CoverMyMeds account, email, text, portal message, prior-authorization key, support exchange, or medication-access record exists. - Biologics by McKesson filled or managed a prescription. Direct pharmacy labels, shipment materials, emails, or statements are a stronger connection than the medication type alone. - Records exist for copay assistance, patient-assistance programs, insurance verification, benefit review, reimbursement, prior authorization, or specialty-medication access. A program may carry a drug or manufacturer name rather than the McKesson name. - Records exist for oncology, rare-disease, cell or gene therapy, or another complex treatment involving specialty-pharmacy delivery, insurance approval, financial assistance, or manufacturer support. - Specialty-pharmacy bottles, shipment labels, packing slips, emails, texts, payment records, or patient-portal records name McKesson, CoverMyMeds, or Biologics. McKesson has not published a final affected-person list or public lookup tool for this incident. A possible connection does not establish breach inclusion. ## Important notice This summary is provided for public access and machine readability. The filed PDF is the authoritative complaint. The complaint contains allegations only; the defendants have not yet had an opportunity to respond, no findings have been made, and no class has been certified. Nothing in this summary is a court finding or a guarantee of any result.