Skip to content
Back to Blog
critical severity July 03, 2026 · 4 min read

1Life Healthcare Data Breach Notice (Washington Attorney General)

If you were named in this filing, here’s what the filing says was exposed, and what to do about it.

1Life Healthcare notified Washington residents of a data breach in a filing reported to the Washington State Attorney General on July 03, 2026, and the notice lists name, social security number, full date of birth, health insurance policy or ID number, medical information and protected health information owned or licensed by a HIPAA covered entity among the information exposed. The filing puts the incident itself on June 08, 2026.

1Life Healthcare Data Breach Notice (Washington Attorney General)

The filing from 1Life Healthcare confirms that the personal information of 16,884 people was exposed in an incident on June 08, 2026. The categories listed are name, Social Security number, full date of birth, health insurance policy or ID number, medical information, and protected health information owned or licensed by a HIPAA covered entity. No passwords were exposed.

Your Social Security Number and Date of Birth Are Now in Play

If you received a notification from 1Life Healthcare, your name, Social Security number, and exact date of birth are among the details now outside the organisation’s control. This specific combination is the foundation for synthetic identity fraud, tax refund fraud, and new account identity theft. These risks do not expire when the news cycle moves on.

The presence of your full date of birth alongside your SSN makes it significantly easier for someone to impersonate you with creditors, government agencies, or healthcare payers. Medical information and your health insurance ID number add another layer: they can be used to file false claims, order prescription services in your name, or request medical records that should remain private.

What the 25-Day Timeline Actually Shows

The incident occurred on June 08, 2026 and the filing reached the Washington Attorney General on July 03, 2026 — an interval of 25 days. This is faster than many breach notifications. The record does not disclose how the incident was discovered or whether data was copied, only that these categories were involved for 16,884 individuals.

Because the filing does not list any passwords, login credentials, or authentication tokens, there is no immediate need to change a password for 1Life Healthcare services. That particular risk does not apply here.

Why Medical and Insurance Details Matter Long-Term

Protected health information and health insurance policy numbers do not lose their value the way a credit card does. A stolen insurance ID can be used repeatedly to submit fraudulent claims, which may later appear on your Explanation of Benefits statements and create administrative headaches or unexpected bills. Medical details can also be leveraged in phishing campaigns that appear highly personalised.

Unlike a credit card number, you cannot simply cancel your Social Security number or date of birth. These identifiers remain tied to you for life. The exposure therefore creates a permanent increase in your risk profile rather than a temporary one.

How to Determine Whether This Affects You

1Life Healthcare is required to notify affected individuals directly, usually by mail. If you have not received a letter, it is likely your records were not part of this incident. However, if you have moved since June 08, 2026 or changed addresses without updating them with the provider, contact 1Life Healthcare directly to confirm whether your information was included.

The Difference Between Reversible and Permanent Exposure

Credit monitoring and fraud alerts address only part of the problem. They are useful for new financial accounts opened in your name, but they do not stop medical identity theft or the misuse of your health insurance ID. Monitoring your credit reports remains worthwhile, yet the health-related consequences require separate attention.

Review every Explanation of Benefits statement from your insurance carriers. Look for claims you did not receive care for. Dispute incorrect entries promptly. This step is more relevant here than in breaches that involve only financial data.

Placing This Incident in Context

The scale — 16,884 people — is substantial but the filing itself offers no comparison to 1Life Healthcare’s total patient population, so no broader conclusion can be drawn. What matters is the permanence of the exposed fields. A Social Security number paired with a date of birth cannot be reissued like a compromised password or credit card. That reality defines the practical impact for anyone whose records were included.

The record is silent on the initial access method, whether encryption was in place, and whether the information was exfiltrated. Those details remain undisclosed. Speculation does not help; the categories that were named do.

Practical Steps That Address This Specific Exposure

  • Place a fraud alert or credit freeze with Equifax, Experian, and TransUnion. This prevents new accounts from being opened in your name using the exposed SSN and date of birth.
  • Review your Explanation of Benefits statements every month for the next year. Look for services you did not receive. False medical claims are a common consequence when health insurance IDs are exposed.
  • Request your free annual credit reports and check for unfamiliar accounts or inquiries. Continue monitoring even after the initial alert period ends.
  • Contact 1Life Healthcare if you have changed addresses since June 2026. Confirm directly whether your records were in the affected group if you have not received a letter.
  • Consider identity theft protection services that include medical identity monitoring. Standard credit monitoring does not catch fraudulent medical claims or unauthorised access to your health records.

The exposure of these six categories creates a higher baseline risk that lasts for years. The absence of password data is genuinely good news — it removes one common vector — but it does not cancel the long-term consequences of SSN, date of birth, and medical information being outside your control. Focus your effort on the monitoring steps that match what was actually lost rather than on actions that would only apply to credential-based breaches.

What to do now

Steps that match what this notice says was exposed

Every step below is free and you do it yourself, and none of it depends on 1Life Healthcare.

  1. Freeze your credit — this is the one that matters. A freeze is free, it takes minutes, and it has to be done separately at all three bureaus: Equifax, Experian and TransUnion. It stops a new account being opened in your name, which is what a Social Security number in the wrong hands is for. You can lift it temporarily whenever you need credit.
  2. Read your next explanation of benefits. Medical identity theft shows up as treatment you did not receive, billed to your policy and written into your medical record. Your insurer can flag the policy, and you can request an accounting of disclosures from the provider named here.
  3. Expect the phone calls to get better. A date of birth is not secret, but it is what call centres use to confirm you are you. Treat any unexpected call that already knows your details as unverified until you call the company back yourself.

One more, whatever was exposed: a breach notice is a favourite disguise for a phishing email. If a message about this arrives, do not use its links — go to the company’s site yourself, or call the number on your statement.

Report details & sourcing

Severity Critical identifiers that cannot be reissued, alongside documents or accounts that can be misused now
Disclosed July 03, 2026
Last reviewed July 22, 2026
Affected 16884
Data exposed NameSocial Security NumberFull Date of BirthHealth Insurance Policy or ID NumberMedical InformationProtected Health Information owned or licensed by a HIPAA covered entity
Editorial & sourcing policy
GalaxyWarden is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data. Breach information is compiled from publicly accessible sources and threat-intelligence platforms, and is reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — see our content & takedown policy or write to support@galaxywarden.com.
Share this Post on X Reddit Email