Medtronic Data Breach: Notifications Issued to 3.8M Individuals

The medical device giant Medtronic has started issuing notification letters to individuals affected by an April 2026 cyberattack. While the incident is not currently listed on the website of the HHS’ Office for Civil Rights, the Oregon Attorney General was informed that 3,834,294 individuals have been affected. The affected individuals include 297,307 Texas residents, 63,534 Massachusetts residents, and 8,668 Vermont residents, according to data breach notifications to other state attorneys general.

With more than 3.8 million people affected, it is the largest healthcare data breach of the year to date, ahead of the 3,433,965-record data breach at Trizetto Provider Solutions, and the 3,117,874-record data breach at QualDerm Partners, LLC. Medtronic had previously announced that it was the victim of a hacking incident that was detected on April 15, 2026. Its investigation determined that an unnamed threat actor had access to certain corporate systems between April 13, 2026, and April 19, 2026, potentially obtaining files containing names, contact information, dates of birth, Social Security numbers, and health-related information.

While the threat group behind the attack was not named, a group claimed responsibility. The notorious hacking group ShinyHunters added Medtronic to its dark web data leak site on April 18, 2026, claiming to have exfiltrated more than 9 million records. ShinyHunters threatened to publish the stolen data if the ransom was not paid. The listing has since been removed from the data leak site, which suggests that Medtronic paid the ransom, although the medical device company has not confirmed whether payment was made.

The notification letters include an offer of 24 months of complimentary credit monitoring and identity theft protection services, stating that Medtronic found no evidence to suggest that any customer data was publicly exposed as a result of the incident.

April 28, 2026: Medtronic Announces Cyberattack and Data Breach

Medtronic, the world’s largest medical device manufacturer, has announced a cybersecurity incident involving the theft of company data. What is currently unclear is whether the Medtronic data breach involved protected health information. As such, it is unclear whether the incident is a reportable breach under the Health Insurance Portability and Accountability Act (HIPAA), although it is reportable under the U.S. Securities and Exchange Commission’s (SEC) public company cybersecurity disclosure rules.

On April 24, 2026, Medtronic announced the incident and confirmed in a Form 8-K filing with the SEC that there had been a cyber intrusion involving the theft of corporate data. Medtronic has engaged a leading cybersecurity firm to assist with the investigation and is working to identify any personal information that may have been exposed or stolen in the incident. Should that prove to be the case, notifications will be issued, and resources will be made available to assist the affected individuals.

HIPAA
Compliance
Checklist

Simple Guidelines
Immediate PDF Download

Immediate Access

Privacy Policy

Download Free Checklist

Medtronic said the incident affected only parts of its network and confirmed that the networks that support its corporate IT systems, products, manufacturing, and distribution operations are separate, as are the systems that support hospital customer networks, which are secured and managed by its customers’ IT teams. According to the SEC filing, Medtronic does not believe the incident will have any material impact on its operations or financial position. Medtronic is continuing to meet customer needs, and its products, patient safety, customers’ connections, manufacturing and distribution operations, and financial reporting systems are all fully operational.

While investigating the incident and reviewing the data, Medtronic is simultaneously assessing its current security measures and working on ways to optimize security to prevent similar incidents in the future. Medtronic has not released any information about the nature of the incident, such as how access was gained, only that the intrusion was detected on April 14, 2026, and that corporate data was exfiltrated.

This has the potential to be a colossal healthcare data breach, given that Medtronic’s products are used by around 79 million individuals worldwide. It is unclear if ransomware was used in the attack, although there has been a claim from a threat group. ShinyHunters, a group well known for extortion and ransom attacks, added Medtronic to its data leak site and threatened to leak the stolen data if the ransom was not paid by April 21, 2026. The listing has since been removed, which, if the group’s claim is legitimate, suggests that a ransom was paid. ShinyHunters claimed that the data exfiltrated in the incident included around 9 million records, including personally identifiable information, and that terabytes of data were exfiltrated in the attack.

Medical device manufacturers store large volumes of patient data and are an attractive target for cybercriminals. So far this year, at least 3 other medical device companies have announced cyberattacks and data breaches – UFP Technologies, TriMed, and Stryker.

About Liam Johnson

Liam Johnson has produced articles about HIPAA for several years. He has extensive experience in healthcare privacy and security. With a deep understanding of the complex legal and regulatory landscape surrounding patient data protection, Liam has dedicated his career to helping organizations navigate the intricacies of HIPAA compliance. Liam focusses on the challenges faced by healthcare providers, insurance companies, and business associates in complying with HIPAA regulations. Liam has been published in leading healthcare publications, including The HIPAA Journal. Liam was appointed Editor-in-Chief of The HIPAA Guide in 2023. Contact Liam via LinkedIn: https://www.linkedin.com/in/liamhipaa/