DataBreachSearch.com
Investigation OpenWashington AG filing · July 3, 2026

1Life Healthcare (One Medical) Reports Data Breach in Washington

1Life Healthcare, operating as One Medical and Iora Health, filed a data breach report with the Washington Attorney General on July 3, 2026. This filing confirms a security incident that may have exposed personal information. Individuals who received notifications should carefully review the information provided by the company.

State
Washington
Reported
July 3, 2026

1Life Healthcare, which includes the brands One Medical and Iora Health, has officially reported a data security incident to the Washington Attorney General. The filing, dated July 3, 2026, confirms that a breach occurred involving personal information.

The report from 1Life Healthcare indicates that an investigation into the specifics of the incident is currently underway. While the public filing does not detail the exact types of data that may have been compromised, the company's notification letters to affected individuals state that personal information was potentially exposed.

Because 1Life Healthcare is a healthcare provider, the organization typically manages a range of sensitive personal data. However, for this specific incident, the types of information involved were not specified in the public record.

If you received a data breach notification letter from 1Life Healthcare, it is crucial to read it thoroughly. This letter should provide direct and specific guidance relevant to your situation, including any protective services the company may be offering.

As a general precaution, it is advisable to remain vigilant for any unusual activity in your personal accounts. Regularly monitoring your financial statements and credit reports can help detect any unauthorized use of your information.

What to do if you were affected

These general steps can help limit the risk of identity theft and fraud after any data breach.

  • Stay alert to targeted scams

    Be cautious of calls, texts, or emails that reference this breach. Legitimate organizations won't ask you to confirm sensitive details through an unsolicited message.

  • Keep your notification letter

    Save the notice you received. It documents that your information was involved and is often needed to enroll in any credit monitoring offered or to join a related legal claim.

Related data breach cases