LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

Recent Breaches › 1Life Healthcare Data Breach Notice (Washington Attorney General)

CRITICAL severityConfirmedHow we verify

1Life Healthcare Data Breach Notice (Washington Attorney General): What Was Exposed & What To Do

RBRecent Breaches Breach Intelligence·July 3, 2026
1Life Healthcare Data Breach Notice (Washington Attorney General)

Occurred June 08, 2026 · publicly disclosed July 3, 2026. Approximately 16884 people affected.

CRITICAL
Severity
16884
People affected
6
Data types exposed
July 3, 2026
Disclosed
ShareXLinkedInFacebookRedditWhatsAppTelegram

On 3 July 2026, Washington’s Attorney General posted a data-breach notice for 1Life Healthcare, stating that a breach affecting 16 884 individuals occurred on 8 June 2026 and exposed names, Social Security numbers, full dates of birth, health-insurance policy or ID numbers, and medical information. Individuals are urged to review the notice to determine whether their data was involved and to follow the recommended protective steps.

Severity & verification
CRITICAL severityConfirmed
Exposes government-ID/medical data.
Corroborated by an official disclosure or a verified breach feed.
Check your exposure
16884 accounts were exposed here. We can’t confirm any single incident against the sources we search — but we can show you every leak and listing tied to your email. 15-sec check, no card.

By running your scan you agree to the Terms and Conditions and the Privacy Policy, and to GalaxyWarden emailing you the results of this scan.

Healthcare organizations remain frequent targets in a threat landscape where stolen identity and clinical data retain long-term value on criminal markets. Against that backdrop, a notice filed with the Washington State Attorney General documents a data breach involving 1Life Healthcare that the company reported on July 03, 2026.

According to that filing, the incident itself is dated June 08, 2026, and approximately 16,884 people are listed as affected. The notice identifies categories of personal and health-related information as exposed. For patients and plan members, the combination of identifiers and protected health information raises concrete identity-theft and privacy risks even when full technical details of the intrusion remain limited in the public record.

Breaking down the breach

1Life Healthcare notified Washington residents of a data breach in a filing reported to the Washington State Attorney General on July 03, 2026. The filing places the incident on June 08, 2026, and states that 16,884 people were affected.

The notice lists the following categories among the information exposed: name, Social Security number, full date of birth, health insurance policy or ID number, medical information, and protected health information owned or licensed by a HIPAA covered entity. Public detail in the available record does not describe the attack method, the systems involved, how long unauthorized access lasted, or whether data were exfiltrated in bulk versus accessed in place. No specific threat actor is attributed in the disclosure.

How a breach like this happens

Incidents that result in notices of this kind often begin with common entry points: stolen or phished credentials, exploitation of a vulnerable remote-access or web-facing system, malware on an endpoint that reaches networked file stores, or a compromised business partner that holds or processes the same data. Once inside, attackers may move laterally, search for repositories containing identity and clinical records, and copy material for later misuse or sale.

Healthcare environments are attractive because they concentrate government identifiers, insurance numbers, and medical details in systems that many staff and vendors must access daily. Defenders typically rely on access controls, logging, encryption, network segmentation, and monitoring; when any of those layers fails or is bypassed, large volumes of sensitive records can be exposed before the intrusion is detected. The public filing for this matter does not state which of these patterns, if any, applied here, so the above remains general background rather than a reconstruction of this event.

Who is 1Life Healthcare?

1Life Healthcare operates in the healthcare sector, where organizations deliver or coordinate medical services and related administrative functions. Entities in this space routinely maintain demographic data, insurance identifiers, clinical notes or summaries, and other protected health information subject to HIPAA and state privacy rules.

A breach affecting such an organization is consequential because the data are both highly identifying and difficult to change. Unlike a password, a Social Security number or a documented medical history cannot be rotated easily, and misuse can affect credit, insurance eligibility, employment background checks, and personal privacy for years. The Washington Attorney General filing indicates that residents of that state were among those notified, underscoring the multi-state reach common to national or regional healthcare operators.

What was likely exposed

The filing explicitly names the exposed data types as name, Social Security number, full date of birth, health insurance policy or ID number, medical information, and protected health information owned or licensed by a HIPAA covered entity. Those categories are reported as fact from the notice.

Beyond that list, the public record does not itemize every field in every record, nor does it confirm whether every affected person had every data element present. Organizations of this type typically also hold addresses, contact details, appointment history, and billing information; whether any of those additional elements were involved in this incident is unconfirmed in the available disclosure. Readers should treat only the named categories as established by the notice.

Why it matters

For affected individuals, the combination of name, date of birth, and Social Security number is sufficient for many forms of identity fraud, including fraudulent credit applications and tax-related scams. Health insurance policy or ID numbers and medical information can enable insurance fraud, improper billing, or targeted social-engineering attempts that reference real clinical details to appear legitimate. Protected health information also carries stigma and confidentiality harms if disclosed further.

For the organization, a breach of this scale triggers notification duties, potential regulatory scrutiny under HIPAA and state law, remediation costs, and lasting trust effects with patients and partners. The filing does not assign fault or describe security shortcomings as established findings; it documents that an incident occurred and that specified data categories were involved for the stated number of people.

What to do if you're exposed

If you believe you may be among those affected, consider placing a fraud alert or credit freeze with the major credit bureaus, and monitor credit reports and explanation-of-benefits statements for unfamiliar activity. Be cautious of unsolicited calls or messages that cite your medical or insurance details. Follow any instructions in an official notice from 1Life Healthcare regarding credit monitoring or other assistance if offered. Keep records of the notice and any correspondence.

You can also run a free exposure scan of your email address to check whether your information has already surfaced in known breach datasets, which can help you prioritize password changes and ongoing monitoring.

AICompiled with AI assistance from public sources and published under our editorial standards.

Editorial & sourcing policy
Recent Breaches is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data, and we do not hold the data claimed in leak-site listings. Incidents are compiled from publicly accessible sources and threat-intelligence platforms and are reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — write to support@galaxywarden.com or press@recentbreaches.com.
Check if you’re exposed →

How this breach connects

Company

Company1Life Healthcare security record
52/100
DoxxScan™ · Elevated doxx risk
D+ 56Weak record

1 reported incident on record.

See 1Life Healthcare’s full breach history →

More recent breaches

Rockwood Retirement Communities (Spokane United Methodist Homes) Data Breach Notice (Washington Attorney General)August 20, 2026Golden Opportunities And Local Support, LLC Data Breach Notice (Washington Attorney General)August 7, 2026Aesto, LLC (Grant County Public Hospital District #2) Data Breach Notice (Washington Attorney General)August 4, 2026The Moody Bible Institute of Chicago Data Breach Notice (Washington Attorney General)July 23, 2026

Latest breaches

Read GalaxyWarden’s full analysis of the 1Life Healthcare Data Breach Notice (Washington Attorney General) →

Source: Washington State Attorney General breach notification

Verified breach

Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.

Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.

ShareXLinkedInFacebookRedditWhatsAppTelegram