Norton Healthcare ransomware breach exposed data on 2.5 million people

Organization
Norton Healthcare
Exploit
Ransomware
Industry
Healthcare

Norton Healthcare, a nonprofit hospital system based in Louisville, Kentucky, disclosed in December 2023 that a ransomware attack the previous May had exposed the personal information of about 2.5 million people. The system filed a breach notice with the Maine Attorney General's Office on December 8 and began mailing notification letters the same week.

According to Norton, an unauthorized party had access to its network between May 7 and May 9, 2023, when the activity was detected. The intruders reached network storage devices holding records on patients, employees and employees' dependents. Norton said its electronic medical record system and its MyChart patient portal were not accessed.

The exposed information varied by individual and included names, contact details, dates of birth, Social Security numbers, health and insurance information and medical identification numbers. For some people it also covered driver's licence or other government identification numbers, financial account numbers and digital signatures. The Maine filing listed 385 residents of that state among the total.

Norton said it did not pay a ransom, engaged outside cybersecurity specialists and federal law enforcement, and offered those affected two years of free credit monitoring. It attributed the seven month gap between the attack and notification to the time needed to review the documents taken and identify whose data was in them. The ALPHV/BlackCat group claimed responsibility and posted data it said came from the health system.

Updates

  1. The consolidated class action settled for 11 million dollars, covering roughly 2.5 million people. The court granted preliminary approval on 13 January 2026 and set a final fairness hearing for 15 May 2026.

Sources