Full-Time
Pharmaceuticals and medical supplies distributor.
$79.6k - $132.6k/yr
Iowa, USA + 3 more
More locations: Minnesota, USA | Wisconsin, USA | Missouri, USA
In Person
Field-based remote; travel up to 75% across the Central Midwest; must reside within territory (preferred Minneapolis, MN; Kansas City, MO; Western Wisconsin).
Bachelor's
See people who can refer or advise you
McKesson is a global healthcare distributor and services provider. It buys pharmaceuticals and medical products from manufacturers and distributes them to pharmacies, hospitals, and other healthcare facilities, acting as an intermediary in the supply chain. Its core work includes logistics and supply chain management, ensuring medicines and medical supplies reach customers on time and safely. McKesson also offers technology solutions to help healthcare providers manage operations and procurement. Compared with competitors, it leverages a very large-scale network and integrated services—combining distribution, logistics, and technology—across providers, pharmacies, and manufacturers. The company aims to support the healthcare system by keeping essential medical supplies available and helping healthcare facilities run more efficiently, ultimately improving patient care.
Company Size
10,001+
Company Stage
IPO
Headquarters
Irving, Texas
Founded
1833
See people who can refer or advise you
Help us improve and share your feedback! Did you find this helpful?
Performance Bonus
401(k) Company Match
Supply chain vulnerability isn't just about code. Jason Nickerson has spent years talking about the risks of centralized infrastructure in the hosting world, but the same consolidation that makes cloud computing efficient is creating massive single points of failure in its healthcare system. McKesson, a titan that effectively keeps the lights on for hospitals and pharmacies across the United States, is currently dealing with a massive breach and subsequent service degradation. According to a recent report, hackers are claiming to have walked away with millions of patient records while the company struggles to maintain its normal distribution of medicines and devices. This isn't just a matter of leaked names and dates; it is an operational bottleneck that stops the flow of physical goods to people who actually need them. The cost of consolidation. In the hosting business, if a major control panel or infrastructure provider has an outage, Jason Nickerson see it as a business catastrophe. When it happens to a medical distributor, it becomes a public health crisis. The business implication here is clear: its push toward hyper-efficiency through massive, centralized distributors has created a landscape where one successful breach can paralyze an entire sector. For McKesson, the challenge isn't just the PR nightmare of stolen data - it's the reality that their systems are so intertwined with their logistics that the breach has physically slowed down their ability to deliver products. Jason Nickerson is seeing a trend where attackers no longer just want to encrypt your files for a quick payday. They are targeting the friction points of the economy. If you can disrupt the distribution of medicine, you aren't just holding data hostage; you're holding the supply chain hostage. This puts a level of pressure on a company that a standard database leak simply can't match. It's a calculated move to force a settlement by making the operational pain unbearable. I've seen enough server migrations to know that recovery is never as fast as the initial press release suggests. If they are already admitting to service degradation, the IT teams in those distribution centers are likely having a very long month. The long view. Security is no longer a department you fund just to check a box for your insurance provider. In a world where your digital integrity dictates your physical output, failing to secure the perimeter is the same as locking the front door but leaving the loading dock wide open. Jason Nickerson need to stop treating data breaches as isolated IT incidents and start viewing them as the fundamental business risks they have become.
Hall Attorneys and co-counsel file class action following McKesson healthcare data breach. McKesson says the incident involved data associated with a subset of customers in its Oncology & Multispecialty and Medical-Surgical units; a threat actor claims approximately one terabyte and 284 million raw patient-related records. September 1, 2026 Dallas, Texas Attorney Advertising. The complaint contains allegations only; the defendants have not yet had an opportunity to respond, no findings have been made, and no class has been certified. Do not send medical records or identification through an ordinary contact form. Dallas, Texas - September 1, 2026 - Hall Attorneys, P.C. and co-counsel filed a putative class action on August 31, 2026 against McKesson Corporation and CoverMyMeds LLC in the U.S. District Court for the Northern District of Texas, Dallas Division. The matter is Hall v. McKesson Corporation et al., No. 3:26-cv-02958-D, ECF No. 1. The complaint arises from the August 2026 cybersecurity incident McKesson says involved unauthorized access to third-party applications and data exfiltration. It alleges the defendants failed to reasonably safeguard personally identifiable information and protected health information. McKesson identifies two affected business units. In an August 29 customer update, McKesson said its investigation confirmed that unauthorized access to certain third-party applications and the exfiltration of certain data was associated with a subset of customers within its Oncology & Multispecialty and Medical-Surgical business units. McKesson said it had reasonable assurance there was no ongoing unauthorized activity, but that its investigation remained open and it was still determining the nature and scope of the information involved. The company said it expects to provide complimentary credit monitoring and identity-protection services, together with a dedicated information line, to partners, customers, and their patients whose data was exfiltrated. McKesson has not publicly named every affected customer or application, identified all data elements involved, or announced a final number of affected people. The alleged scale and sensitivity of the data. The complaint discusses contemporaneous reporting that attributes the incident to ShinyHunters. According to that reporting, the group claimed it removed approximately one terabyte of data over four days and obtained approximately 284 million raw patient-related records or database rows. The group reportedly said those rows do not represent 284 million unique patients and that it had not completed a unique-person count. The actor reportedly claims the data includes combinations of: * names, addresses, dates of birth, Social Security numbers, telephone numbers, and email addresses; * patient identifiers, Medicaid numbers, and medical-record numbers; * medications, prescriptions, allergies, illnesses, disabilities, appointments, and physician information; and * medication shipments, invoices, and information about healthcare providers and clinics. McKesson has not confirmed the threat actor's volume or asserted data fields. If confirmed, however, the reported data would be exceptionally sensitive because it could connect a patient's identity and government or benefit identifiers to detailed information about treatment, medical conditions, and care providers. Who should check with a healthcare provider? Patients may want to make an inquiry if they received care from a facility that may be a customer of either identified business unit. McKesson says its Oncology & Multispecialty operations support health systems, independent community practices, specialty pharmacies, and specialty practices, including oncology and other complex-care providers. McKesson says its Medical-Surgical operations serve physician offices, health systems, laboratories, ambulatory surgery centers, urgent-care and community clinics, oncology clinics, home-health and hospice agencies, home-infusion pharmacies, skilled-nursing facilities, assisted-living facilities, and other long-term-care settings. Receiving care at one of these facilities does not establish that the facility used McKesson, and a McKesson customer relationship does not establish that the customer was within the affected subset or that any particular patient's data was exfiltrated. A supply relationship by itself also does not show that patient data was present in an affected application. How to verify whether your provider used the impacted lines. * Contact the office responsible for privacy. Ask for the HIPAA privacy officer, compliance office, health information management or medical-records department, patient relations office, or facility administrator. Front-desk and clinical staff may not know which vendors or applications the organization uses. * Ask a two-part question in writing.First ask whether the facility was a customer of McKesson's Oncology & Multispecialty or Medical-Surgical business unit. Then ask whether McKesson identified the facility, any application it used, or any patient data associated with the facility as part of the August 2026 incident. * Ask whether McKesson-linked information included your data. If the provider confirms that it was among the affected customers, ask whether its review shows your information was stored in or transmitted through an affected third-party application, what categories were involved, and when you should expect written notice. * Check for vendor clues, but treat them only as clues. Search the provider's website, privacy notices, patient portal, bills, infusion paperwork, home-care or supply records, and shipment labels for "McKesson," "McKesson Medical-Surgical," "The US Oncology Network," "Ontada," or "iKnowMed." Those names may justify a follow-up question, but none proves that the provider or patient was affected. * Request and preserve the response.Keep the name and title of the person contacted, the date, the exact question, and any written answer. If the provider is still waiting for McKesson's determination, ask which office will issue patient notices and how to update your mailing and email addresses. The filed case. The complaint proposes a Nationwide Class of people in the United States whose private information was accessed, acquired, exfiltrated, or otherwise compromised in the incident McKesson discovered on or about August 25, 2026. It also proposes an Iowa Subclass and a McKesson Pharmacy-Technology Subclass. The lawsuit asserts negligence, breach of implied contract, and unjust enrichment. Requested relief includes damages and restitution; remediation of proven security deficiencies; stronger identity and access controls; appropriate independent security assessment; data minimization and protection; improved monitoring and data-loss prevention; and meaningful identity and medical-identity protection services. Information for patients and caregivers. Patients and caregivers may contact Hall Attorneys if a provider confirms it used one of the two McKesson business units and was within the affected subset, if they receive an incident notice, or if they experience healthcare-themed phishing, medical-identity misuse, prescription fraud, identity theft, expense, or substantial lost time. In an initial message, provide your state, the name of the healthcare provider, which McKesson business unit the provider identified, whether the provider said it was within the affected subset, whether you received notice, and a short description of any suspicious activity or loss. Do not send passwords, full account numbers, Social Security numbers, medical records, or identification documents through ordinary email or a standard contact form. Preserve the complete incident notice and envelope or email; your written questions to the provider and its answers; documents showing the provider's relationship to either identified McKesson business unit; suspicious messages; account, insurance, or benefit statements; fraud reports; monitoring records; receipts; and a dated log of time spent responding. Important documents. - Attorney Nicholas Hall is with Hall Attorneys, a Texas-based law firm focused on complex litigation. He can be found on X at @nicholashall or at www.hallattorneys.com.
McKesson cyberattack hits oncology data as pharma giant warns of service problems. McKesson, the Texas pharmaceutical giant that delivers about one-third of all prescriptions in North America, is investigating a cyberattack that already put customer data in crooks' hands. The company posted a public notice and filed with the Securities and Exchange Commission on Friday evening. It said it is in the early stages of looking into a cybersecurity incident involving an unnamed third-party application. Hackers got into that application and started pulling data out. If you fill a prescription, sit in a cancer clinic, or run a small medical practice, this is not some distant IT story. This is the plumbing of American healthcare taking a hit. What McKesson is telling customers. Chief technology officer Francisco Fraga used the usual corporate fog. "At this time, customers may experience intermittent service degradation that we believe may be related to this incident," he said. "We are aware of these issues and continue to monitor the situation closely." That means some systems are acting up, and they think the breach is why. On Saturday, McKesson said the attackers took data associated with customers in the oncology and surgical business units. Fraga said the company will provide credit monitoring and identity protection to customers whose data was stolen. McKesson also said it has "reasonable assurance" the hackers are no longer inside its systems. "Customers can continue to connect to and use our systems and services as intended," Fraga said. The company is not proactively disconnecting systems, the step outfits usually take when ransomware is spreading and they need to contain the mess. He told customers to contact McKesson if they hit technical problems. The company said it is still investigating and did not answer questions about the incident when reached for comment. ShinyHunters claims the job. The ShinyHunters cybercriminal group took credit for the attack on Friday night and threatened leaks on their blog. This crew has spent more than two years attacking and extorting some of the largest companies in the world. Earlier this year, the FBI warned that hackers linked to ShinyHunters were demanding substantial ransom payments from companies after stealing data through compromises involving Salesforce environments. The same group caused chaos across the U.S. in May with an attack on a widely used educational software suite. In April, they stole the information of more than four million people after attacking the world's largest medical device company. Other victims named in that reporting include Carnival Cruises, Ticketmaster, AT&T, McGraw Hill, ADT, and gaming company Rockstar. A company that moves a third of North America's prescriptions. McKesson reported $106 billion in revenue last quarter. About one-third of all prescriptions in North America are delivered by the company. It distributes pharmaceuticals, produces drugs for oncology patients, and manufactures medical-surgical supplies and laboratory equipment. This is also not a one-off in healthcare. McKesson is the latest large healthcare company attacked this year after medical device giants Boston Scientific and Medtronic both reported cybersecurity incidents. Another large medical device firm, Stryker, was hit earlier this year too. The pattern is ugly and simple. Healthcare has to stay online because people need medicine and surgery. Attackers know that. Vendors and third-party apps sit on the same network as the stuff that actually matters. When that link fails, patients and small clinics eat the risk while the giant talks about "service degradation." What you should do if this touches you. You do not need a security team to take a few practical steps. The hole was a third-party application. The stolen records sit in oncology and surgical customer data. Credit monitoring is the standard offer, and it is not the same as locking things down yourself. * If you are a pharmacy, hospital, or clinic that uses McKesson, watch for odd outages and call them if a service misbehaves. * If your information may have been in the oncology or surgical units, enroll in the identity protection they offer, then freeze your credit with the bureaus anyway. * Read your explanation of benefits and pharmacy records for charges or refills you did not authorize. * Treat "reasonable assurance" the attackers are gone as an update, not a finish line. Investigations move. So do leak sites. * Ask your providers which vendors hold your data. The weak door is often a tool nobody on the floor has ever heard of. Big healthcare companies will keep filing SEC notices and offering monitoring. Regular people still have to watch their own accounts. That is the system NOSMH has right now, and it is not working for the folks who actually get the chemo and the stitches.
Hackers claim millions of patient records stolen during data breach at healthcare giant McKesson. The company, which distributes medicines and medical devices to hospitals and healthcare practices across the U.S., said it was hacked and expects int A prolific hacking group has taken credit for last week's cyberattack against U.S. pharmaceutical distribution giant McKesson, leading to the latest spill of highly sensitive health data by an American healthcare company in recent months. McKesson confirmed Friday in a statement on its website that hackers broke into several of its cloud-hosted accounts earlier in the week and exfiltrated data, and that the company expected "intermittent service degradation" related to the incident. In a separate notice to customers, the company's chief technology officer, Francisco Fraga, said the stolen data relates to its oncology & multispecialty and medical-surgical units. The Texas-based company is one of the largest American distributors of pharmaceuticals, medicines, medical supplies, and technology to hospitals and healthcare providers across the United States, and as such handles a large amount of patient data. The ShinyHunters hacking group - one of the most active data-extortion crews of the past two years - told TechCrunch that it hacked the company's cloud environment by tricking several employees into granting the hackers access to McKesson's network by using phishing and social engineering tricks, which the group is known for. The hackers said they stole a range of personal information, such as names, addresses, and Social Security numbers, as well as protected health information, including diagnoses, medications, allergies, and patient notes. The hackers say they took millions of rows of patient data from the company's cloud-hosted Snowflake and Salesforce environments, but that they are unsure of how many individuals are ultimately affected. The stolen data also included McKesson employees' information, such as home addresses. ShinyHunters shared screenshots and a sample of the stolen data with TechCrunch, and IntelPro verified a small subset of it against public records. Bleeping Computer, which first reported the link to the ShinyHunters hacking group, said the hackers demanded a $55 million ransom from the company in exchange for not publicly releasing the stolen files. In a statement, McKesson spokesperson Kristina Chang said the company "continues to operate in all lines of business," and reiterated its public statement, and noted that McKesson believes it has no ongoing unauthorized activity in its systems. The company would not answer TechCrunch's questions about the incident, such as what the hackers demanded or how many individuals had data affected by the incident. McKesson is the latest healthcare company or medical device maker to be targeted in a string of cyberattacks in recent months, as hackers aim to steal large amounts of sensitive medical and health data that they can use to extort the companies into paying a ransom to keep it from being published. Last week, medical device maker Boston Scientific was hit by a cyberattack that knocked much of the company's network offline. The cyberattack had a similar effect to an incident earlier this year at another medical device maker Stryker, in which hackers abused a company's internal tools to remotely wipe thousands of employee devices. Abbott Laboratories and Medtronic have also experienced cyberattacks, while electronic patient records provider CareCloud and health tech company TriZetto had breaches affecting over 3 million patients each. The ShinyHunters hackers have also taken credit for sizable data breaches at Amazon-owned One Medical and dental insurance company DentaQuest following cyberattacks on their systems. _Lorenzo Franceschi-Bicchierai contributed reporting._ _Updated with comment from a McKesson spokesperson._
McKesson data breach exposes patient information after cloud attack. McKesson confirms a cloud security breach after hackers claim to have stolen millions of patient records, including sensitive health data. Aug 31, 2026 - 14:49 McKesson, one of the largest pharmaceutical distributors in the United States, has confirmed a cyberattack after hackers claimed to have stolen millions of patient records from the company's cloud environment. Discover more Discovering Emerging Tech Newsletters Implementing Enterprise AI And Machine Learning Tools Subscribing To Digital Newspaper Outlets McKesson said attackers accessed several cloud-hosted accounts and removed data from its systems. The company warned customers that some services could experience intermittent disruptions related to the incident. Hackers claim theft of sensitive healthcare data. The ShinyHunters hacking group claimed responsibility for the attack, saying it gained access through phishing and social engineering techniques targeting employees. The group said it obtained data from McKesson's cloud-hosted environments, including systems connected to Snowflake and Salesforce. The attackers claimed that the stolen information includes names, addresses, Social Security numbers, and protected health information such as diagnoses, medications, allergies, and patient notes. They said the breach involved millions of rows of data but could not confirm how many individuals were affected. McKesson said the affected information relates to its oncology, multispecialty, and medical-surgical business units. The company also said employee information, including home addresses, was among the potentially exposed data. Registering An LLC Online Healthcare sector faces continued cybersecurity pressure. BleepingComputer reported that the attackers demanded a $55 million ransom in exchange for not publishing the stolen files. McKesson has not confirmed the ransom demand. The incident follows a series of cyberattacks targeting healthcare companies and medical technology providers, in which criminals have focused on sensitive medical information for extortion. ShinyHunters has previously claimed responsibility for major healthcare-related breaches, including incidents involving Amazon-owned One Medical and dental insurance provider DentaQuest. Other healthcare organisations have also reported significant cyber incidents in recent months, increasing concerns about the protection of patient data across the medical industry.