HCA Healthcare breach exposed data on about 11 million patients

Organization
HCA Healthcare
Exploit
Hacking
Industry
Healthcare

HCA Healthcare, the Nashville-based for-profit hospital operator, disclosed on July 10, 2023 that patient data had been stolen from an external storage location it used to format automated email messages such as appointment reminders and notices about programs and services.

The company said the exposed records included patient names, city, state and ZIP code, email address, telephone number, date of birth and gender, along with the date, location and type of service, including the date of any upcoming appointment. HCA said the stolen data did not include clinical information such as treatment, diagnosis or condition, and did not include payment or account details, passwords, driver's license numbers or Social Security numbers.

Samples of the data were posted to an online forum on July 5, and the person who posted them sought to extort the company. HCA disabled access to the storage location, reported the matter to law enforcement and retained third-party cybersecurity and digital forensics advisers. It offered complimentary credit monitoring and identity protection to those affected and warned patients to verify any unexpected billing request before paying.

Early reporting put the total at roughly 11 million patients across 20 states. HCA subsequently reported the breach to the Department of Health and Human Services Office for Civil Rights as affecting 11,270,000 individuals, placing it among the largest healthcare breaches recorded in the United States.

Sources