A data breach at Medtronic has exposed the sensitive information of approximately 9 million individuals, prompting a federal investigation by the law firm Schubert Jonckheer & Kolbe LLP. The breach, which occurred through a vulnerability in the company's cloud-based Epic Systems electronic health record platform, involved unauthorized access to patient data including medical histories and device information.
What happened
On April 18, 2026, an attacker known as ShinyHunters claimed to have compromised "terabytes of internal corporate data" and listed Medtronic among its targets. Medtronic publicly confirmed the data breach of its corporate IT systems on April 24, 2026. The company has not reported the attack to state attorney general offices, which may have violated federal or state laws.
Data exposed
The following data may have been compromised:
- Personally identifiable information
- Internal corporate data
- Medical histories
- Device data
The breach exploited a vulnerability in the API of Medtronic's Epic Systems electronic health record platform, which stores patient information in the cloud.
Who is affected
The breach affects individuals affiliated with Medtronic, a Minnesota-based medical technology firm specializing in cardiovascular, neuroscience, surgical, and diabetes technologies. If you received notification of this data breach or are affiliated with Medtronic, you may be at risk of identity theft and other serious privacy violations.
Legal implications
Schubert Jonckheer & Kolbe LLP is investigating potential violations of federal or state laws, particularly regarding Medtronic's failure to report the attack to state attorney general offices. Affected individuals may be entitled to money damages and an injunction requiring changes to Medtronic's cybersecurity practices.
What to do
If your personal information was impacted, you should:
- Monitor your accounts for suspicious activity
- Consider placing a fraud alert on your credit reports
- Contact Schubert Jonckheer & Kolbe LLP for information about your legal rights
- Visit https://www.classactionlawyers.com/medtronic for updates
Bottom line
The Medtronic breach underscores the risks of interconnected medical devices and cloud-based health records. With 9 million records exposed and a federal investigation underway, affected individuals should take immediate steps to protect their identity and monitor for potential misuse of their data.