HealthEC breach exposed records of about 4.5 million patients
- Organization
- HealthEC LLC
- Exploit
- Hacking
- Industry
- Healthcare Technology
HealthEC LLC, a New Jersey company that sells a population health management platform to healthcare providers and health plans, said an unauthorized party accessed parts of its systems between July 14 and July 23, 2023 and copied files. Its review of what those files contained concluded on October 24, 2023, and it began telling its healthcare clients about the incident two days later.
The entry on the U.S. Department of Health and Human Services Office for Civil Rights breach portal was updated on January 3, 2024 to roughly 4.5 million individuals. Infosecurity Magazine reported that HealthEC's original filing on December 21, 2023 had listed 112,005 people. The tally was revised again in August 2025 to 4,786,241.
The exposed data varied by person and included names, addresses, dates of birth, Social Security numbers, taxpayer identification numbers, medical record numbers, diagnoses and diagnosis codes, mental and physical condition information, prescription details, provider names, and health insurance and billing identifiers.
Because HealthEC processes data on behalf of others, the exposure reached patients of its client organizations rather than its own direct customers. Reporting put the number of affected client organizations at 17 to 19, among them Corewell Health, HonorHealth, Beaumont ACO and Community Health Care Systems. HealthEC notified the Maine Attorney General and federal law enforcement and said it was reviewing its security policies. Consolidated class action litigation later settled for $5.48 million.
Updates
-
HealthEC filed an updated report with the HHS Office for Civil Rights raising the number of affected individuals to 4,786,241, up from 4,452,782. A $5.48 million class action settlement received preliminary approval on June 12, 2025.