Full-Time
Pharmaceuticals and medical supplies distributor.
No salary listed
No H1B Sponsorship
Remote in USA + 1 more
More locations: Tennessee, USA
Remote
Remote within the United States; extensive overnight travel to customers is required, approximately 30% by car and plane.
Bachelor's
See people who can refer or advise you
McKesson is a global healthcare distributor and services provider. It buys pharmaceuticals and medical products from manufacturers and distributes them to pharmacies, hospitals, and other healthcare facilities, acting as an intermediary in the supply chain. Its core work includes logistics and supply chain management, ensuring medicines and medical supplies reach customers on time and safely. McKesson also offers technology solutions to help healthcare providers manage operations and procurement. Compared with competitors, it leverages a very large-scale network and integrated services—combining distribution, logistics, and technology—across providers, pharmacies, and manufacturers. The company aims to support the healthcare system by keeping essential medical supplies available and helping healthcare facilities run more efficiently, ultimately improving patient care.
Company Size
10,001+
Company Stage
IPO
Headquarters
Irving, Texas
Founded
1833
See people who can refer or advise you
Help us improve and share your feedback! Did you find this helpful?
Performance Bonus
401(k) Company Match
McKesson - 6,404,340 breached accounts. 2026-09-10 09:09 In August 2026, healthcare and pharmaceutical company McKesson was targeted in a ShinyHunters "pay or leak" extortion campaign. The group subsequently published a substantial corpus of data they alleged was sourced from the company, which included 6.4M unique email addresses among other personal and corporate data attributes. The impacted data related to a range of individuals and roles, including marketing campaign recipients, patients, staff and healthcare provider contacts. In McKesson's disclosure notice, the company advised it had identified unauthorised access to "certain third-party applications and the exfiltration of certain data was associated with a subset of customers within its Oncology & Multispecialty and Medical-Surgical business units", but had "reasonable assurance of no ongoing unauthorized activity". Read the original article: In May 2026, the dental benefits administrator DentaQuest was the target of a ShinyHunters "pay or leak" extortion campaign that resulted in the group publicly publishing hundreds of gigabytes of data allegedly obtained from the company. The data included 2.6M unique email addresses along with names, addresses and phone numbers... Hacking & Cracking June 4, 2026 Healthcare company McKesson acknowledged a data breach. ShinyHunters claims to have stolen hundred of millions of records August 31, 2026 Healthcare company McKesson disclosed a cybersecurity incident in which hackers got into third-party applications and stole data. McKesson is a major U.S... August 31, 2026
McKesson acquires Precision Medicine from Blackstone. Posted on September 9, 2026 TEXAS and MARYLAND, UNITED STATES - McKesson Corporation signed a definitive agreement to acquire Precision Medicine Group from Blackstone for approximately $2.25 billion. The purchase adds biomarker intelligence, laboratory services, a global contract research organization, market access consulting, and drug commercialization support to McKesson's oncology and specialty care portfolio. Closing is subject to customary regulatory clearances. Oncology capital strategy anchors $2.25 billion deal. According to a report from Lawrence Evans, McKesson said the acquisition of Precision Medicine Group aligns with its strategy of concentrating capital in oncology and specialty care. The company's Oncology and Multispecialty segment posted $14.2 billion in revenue in fiscal first-quarter 2026, a 33% year-over-year increase, and McKesson has committed to this segment as its primary growth axis. The deal gives McKesson an owned global contract research organization (CRO), a biomarker intelligence platform, and laboratory analysis capabilities: knowledge process outsourcing (KPO) functions the company had previously accessed through external partnerships rather than owned assets. Blackstone exit marks precision oncology payoff. Precision Medicine Group said its market access consulting and drug commercialization support services are built to serve pharmaceutical manufacturers across the full clinical-to-commercial lifecycle, extending McKesson's role beyond drug distribution into research and launch strategy. Blackstone's exit at approximately $2.25 billion reflects the premium that large health services acquirers now place on scaled managed services platforms in oncology, where CRO capabilities and biomarker data assets command valuations above those of traditional distribution businesses. McKesson said it does not anticipate any disruption to Precision Medicine Group's existing client relationships through or following the close of the transaction. The McKesson-Precision Medicine Group acquisition reflects accelerating consolidation in oncology services, where distributors and health systems are acquiring clinical research and market access capabilities once confined to standalone CRO firms. For the healthcare outsourcing sector, the transaction signals that pharmaceutical manufacturers increasingly expect outsourced partners to manage the full pathway from laboratory biomarker analysis through drug launch rather than discrete functions delivered by separate vendors. At $2.25 billion, the deal illustrates that precision medicine services platforms carrying robust data assets and commercialization expertise command significant strategic multiples. As oncology drug pipelines grow in complexity, the ability to combine CRO operations with go-to-market strategy is becoming a structural differentiator for companies operating at the intersection of health services and outsourced pharmaceutical support. FREE BPO MATCH Evaluating outsourcing partners after a deal? BPO specialists for due diligence and integration - free match 5,200+ matches made Disclosure: Outsource Accelerator uses AI tools in the backend of its editorial workflow. Every article is reviewed and verified by a human editor before publication. Stay ahead of the outsourcing industry. Join thousands of business leaders who rely on Outsource Accelerator for the news, trends, and expert insights that matter. Subscribe to our free newsletter and never miss an update.
Supply chain vulnerability isn't just about code. Jason Nickerson has spent years talking about the risks of centralized infrastructure in the hosting world, but the same consolidation that makes cloud computing efficient is creating massive single points of failure in its healthcare system. McKesson, a titan that effectively keeps the lights on for hospitals and pharmacies across the United States, is currently dealing with a massive breach and subsequent service degradation. According to a recent report, hackers are claiming to have walked away with millions of patient records while the company struggles to maintain its normal distribution of medicines and devices. This isn't just a matter of leaked names and dates; it is an operational bottleneck that stops the flow of physical goods to people who actually need them. The cost of consolidation. In the hosting business, if a major control panel or infrastructure provider has an outage, Jason Nickerson see it as a business catastrophe. When it happens to a medical distributor, it becomes a public health crisis. The business implication here is clear: its push toward hyper-efficiency through massive, centralized distributors has created a landscape where one successful breach can paralyze an entire sector. For McKesson, the challenge isn't just the PR nightmare of stolen data - it's the reality that their systems are so intertwined with their logistics that the breach has physically slowed down their ability to deliver products. Jason Nickerson is seeing a trend where attackers no longer just want to encrypt your files for a quick payday. They are targeting the friction points of the economy. If you can disrupt the distribution of medicine, you aren't just holding data hostage; you're holding the supply chain hostage. This puts a level of pressure on a company that a standard database leak simply can't match. It's a calculated move to force a settlement by making the operational pain unbearable. I've seen enough server migrations to know that recovery is never as fast as the initial press release suggests. If they are already admitting to service degradation, the IT teams in those distribution centers are likely having a very long month. The long view. Security is no longer a department you fund just to check a box for your insurance provider. In a world where your digital integrity dictates your physical output, failing to secure the perimeter is the same as locking the front door but leaving the loading dock wide open. Jason Nickerson need to stop treating data breaches as isolated IT incidents and start viewing them as the fundamental business risks they have become.
Hall Attorneys and co-counsel file class action following McKesson healthcare data breach. McKesson says the incident involved data associated with a subset of customers in its Oncology & Multispecialty and Medical-Surgical units; a threat actor claims approximately one terabyte and 284 million raw patient-related records. September 1, 2026 Dallas, Texas Attorney Advertising. The complaint contains allegations only; the defendants have not yet had an opportunity to respond, no findings have been made, and no class has been certified. Do not send medical records or identification through an ordinary contact form. Dallas, Texas - September 1, 2026 - Hall Attorneys, P.C. and co-counsel filed a putative class action on August 31, 2026 against McKesson Corporation and CoverMyMeds LLC in the U.S. District Court for the Northern District of Texas, Dallas Division. The matter is Hall v. McKesson Corporation et al., No. 3:26-cv-02958-D, ECF No. 1. The complaint arises from the August 2026 cybersecurity incident McKesson says involved unauthorized access to third-party applications and data exfiltration. It alleges the defendants failed to reasonably safeguard personally identifiable information and protected health information. McKesson identifies two affected business units. In an August 29 customer update, McKesson said its investigation confirmed that unauthorized access to certain third-party applications and the exfiltration of certain data was associated with a subset of customers within its Oncology & Multispecialty and Medical-Surgical business units. McKesson said it had reasonable assurance there was no ongoing unauthorized activity, but that its investigation remained open and it was still determining the nature and scope of the information involved. The company said it expects to provide complimentary credit monitoring and identity-protection services, together with a dedicated information line, to partners, customers, and their patients whose data was exfiltrated. McKesson has not publicly named every affected customer or application, identified all data elements involved, or announced a final number of affected people. The alleged scale and sensitivity of the data. The complaint discusses contemporaneous reporting that attributes the incident to ShinyHunters. According to that reporting, the group claimed it removed approximately one terabyte of data over four days and obtained approximately 284 million raw patient-related records or database rows. The group reportedly said those rows do not represent 284 million unique patients and that it had not completed a unique-person count. The actor reportedly claims the data includes combinations of: * names, addresses, dates of birth, Social Security numbers, telephone numbers, and email addresses; * patient identifiers, Medicaid numbers, and medical-record numbers; * medications, prescriptions, allergies, illnesses, disabilities, appointments, and physician information; and * medication shipments, invoices, and information about healthcare providers and clinics. McKesson has not confirmed the threat actor's volume or asserted data fields. If confirmed, however, the reported data would be exceptionally sensitive because it could connect a patient's identity and government or benefit identifiers to detailed information about treatment, medical conditions, and care providers. Who should check with a healthcare provider? Patients may want to make an inquiry if they received care from a facility that may be a customer of either identified business unit. McKesson says its Oncology & Multispecialty operations support health systems, independent community practices, specialty pharmacies, and specialty practices, including oncology and other complex-care providers. McKesson says its Medical-Surgical operations serve physician offices, health systems, laboratories, ambulatory surgery centers, urgent-care and community clinics, oncology clinics, home-health and hospice agencies, home-infusion pharmacies, skilled-nursing facilities, assisted-living facilities, and other long-term-care settings. Receiving care at one of these facilities does not establish that the facility used McKesson, and a McKesson customer relationship does not establish that the customer was within the affected subset or that any particular patient's data was exfiltrated. A supply relationship by itself also does not show that patient data was present in an affected application. How to verify whether your provider used the impacted lines. * Contact the office responsible for privacy. Ask for the HIPAA privacy officer, compliance office, health information management or medical-records department, patient relations office, or facility administrator. Front-desk and clinical staff may not know which vendors or applications the organization uses. * Ask a two-part question in writing.First ask whether the facility was a customer of McKesson's Oncology & Multispecialty or Medical-Surgical business unit. Then ask whether McKesson identified the facility, any application it used, or any patient data associated with the facility as part of the August 2026 incident. * Ask whether McKesson-linked information included your data. If the provider confirms that it was among the affected customers, ask whether its review shows your information was stored in or transmitted through an affected third-party application, what categories were involved, and when you should expect written notice. * Check for vendor clues, but treat them only as clues. Search the provider's website, privacy notices, patient portal, bills, infusion paperwork, home-care or supply records, and shipment labels for "McKesson," "McKesson Medical-Surgical," "The US Oncology Network," "Ontada," or "iKnowMed." Those names may justify a follow-up question, but none proves that the provider or patient was affected. * Request and preserve the response.Keep the name and title of the person contacted, the date, the exact question, and any written answer. If the provider is still waiting for McKesson's determination, ask which office will issue patient notices and how to update your mailing and email addresses. The filed case. The complaint proposes a Nationwide Class of people in the United States whose private information was accessed, acquired, exfiltrated, or otherwise compromised in the incident McKesson discovered on or about August 25, 2026. It also proposes an Iowa Subclass and a McKesson Pharmacy-Technology Subclass. The lawsuit asserts negligence, breach of implied contract, and unjust enrichment. Requested relief includes damages and restitution; remediation of proven security deficiencies; stronger identity and access controls; appropriate independent security assessment; data minimization and protection; improved monitoring and data-loss prevention; and meaningful identity and medical-identity protection services. Information for patients and caregivers. Patients and caregivers may contact Hall Attorneys if a provider confirms it used one of the two McKesson business units and was within the affected subset, if they receive an incident notice, or if they experience healthcare-themed phishing, medical-identity misuse, prescription fraud, identity theft, expense, or substantial lost time. In an initial message, provide your state, the name of the healthcare provider, which McKesson business unit the provider identified, whether the provider said it was within the affected subset, whether you received notice, and a short description of any suspicious activity or loss. Do not send passwords, full account numbers, Social Security numbers, medical records, or identification documents through ordinary email or a standard contact form. Preserve the complete incident notice and envelope or email; your written questions to the provider and its answers; documents showing the provider's relationship to either identified McKesson business unit; suspicious messages; account, insurance, or benefit statements; fraud reports; monitoring records; receipts; and a dated log of time spent responding. Important documents. - Attorney Nicholas Hall is with Hall Attorneys, a Texas-based law firm focused on complex litigation. He can be found on X at @nicholashall or at www.hallattorneys.com.
McKesson cyberattack hits oncology data as pharma giant warns of service problems. McKesson, the Texas pharmaceutical giant that delivers about one-third of all prescriptions in North America, is investigating a cyberattack that already put customer data in crooks' hands. The company posted a public notice and filed with the Securities and Exchange Commission on Friday evening. It said it is in the early stages of looking into a cybersecurity incident involving an unnamed third-party application. Hackers got into that application and started pulling data out. If you fill a prescription, sit in a cancer clinic, or run a small medical practice, this is not some distant IT story. This is the plumbing of American healthcare taking a hit. What McKesson is telling customers. Chief technology officer Francisco Fraga used the usual corporate fog. "At this time, customers may experience intermittent service degradation that we believe may be related to this incident," he said. "We are aware of these issues and continue to monitor the situation closely." That means some systems are acting up, and they think the breach is why. On Saturday, McKesson said the attackers took data associated with customers in the oncology and surgical business units. Fraga said the company will provide credit monitoring and identity protection to customers whose data was stolen. McKesson also said it has "reasonable assurance" the hackers are no longer inside its systems. "Customers can continue to connect to and use our systems and services as intended," Fraga said. The company is not proactively disconnecting systems, the step outfits usually take when ransomware is spreading and they need to contain the mess. He told customers to contact McKesson if they hit technical problems. The company said it is still investigating and did not answer questions about the incident when reached for comment. ShinyHunters claims the job. The ShinyHunters cybercriminal group took credit for the attack on Friday night and threatened leaks on their blog. This crew has spent more than two years attacking and extorting some of the largest companies in the world. Earlier this year, the FBI warned that hackers linked to ShinyHunters were demanding substantial ransom payments from companies after stealing data through compromises involving Salesforce environments. The same group caused chaos across the U.S. in May with an attack on a widely used educational software suite. In April, they stole the information of more than four million people after attacking the world's largest medical device company. Other victims named in that reporting include Carnival Cruises, Ticketmaster, AT&T, McGraw Hill, ADT, and gaming company Rockstar. A company that moves a third of North America's prescriptions. McKesson reported $106 billion in revenue last quarter. About one-third of all prescriptions in North America are delivered by the company. It distributes pharmaceuticals, produces drugs for oncology patients, and manufactures medical-surgical supplies and laboratory equipment. This is also not a one-off in healthcare. McKesson is the latest large healthcare company attacked this year after medical device giants Boston Scientific and Medtronic both reported cybersecurity incidents. Another large medical device firm, Stryker, was hit earlier this year too. The pattern is ugly and simple. Healthcare has to stay online because people need medicine and surgery. Attackers know that. Vendors and third-party apps sit on the same network as the stuff that actually matters. When that link fails, patients and small clinics eat the risk while the giant talks about "service degradation." What you should do if this touches you. You do not need a security team to take a few practical steps. The hole was a third-party application. The stolen records sit in oncology and surgical customer data. Credit monitoring is the standard offer, and it is not the same as locking things down yourself. * If you are a pharmacy, hospital, or clinic that uses McKesson, watch for odd outages and call them if a service misbehaves. * If your information may have been in the oncology or surgical units, enroll in the identity protection they offer, then freeze your credit with the bureaus anyway. * Read your explanation of benefits and pharmacy records for charges or refills you did not authorize. * Treat "reasonable assurance" the attackers are gone as an update, not a finish line. Investigations move. So do leak sites. * Ask your providers which vendors hold your data. The weak door is often a tool nobody on the floor has ever heard of. Big healthcare companies will keep filing SEC notices and offering monitoring. Regular people still have to watch their own accounts. That is the system NOSMH has right now, and it is not working for the folks who actually get the chemo and the stitches.