July 10, 2023: HCA Healthcare confirmed that an unauthorized party stole lists covering 11.27 million patients from an external storage location used to format appointment-reminder emails. HCA said no clinical records, financial data, or Social Security numbers were in the files—per HIPAA Journal and the company's privacy update. That narrow scope did not stop criminals from listing samples on a hacking forum days earlier.
What was actually exposed
The compromised lists contained roughly 27 million rows mapping to about 11.27 million individuals who received care at HCA hospitals and clinics across 20 U.S. states. Fields included:
- Name, city, state, ZIP
- Email address and phone number
- Date of birth and gender
- Dates and locations of service
- Next appointment date
HCA disabled the storage location, brought in forensics, and reported 11,270,000 individuals to HHS OCR—making it one of the largest HIPAA breaches on record despite the absence of diagnosis or billing data.
Why contact-only breaches still rank high
Security teams sometimes breathe easier when a breach notice omits SSNs and clinical charts. Attackers do not share that relief. A row that pairs your phone number with your next oncology follow-up and the hospital name is a finished script for vishing and SMS phishing—no medical record required.
Real appointment metadata defeats the "how did they know that?" skepticism that stops people from clicking generic bank spam. HCA-scale contact lists also enable credential-stuffing against patient portals where people reuse passwords.
What HCA said it was not
HCA's public statements emphasized that highly sensitive categories—clinical notes, payment cards, SSNs—were not believed compromised. That matters for identity-theft monitoring decisions: you are not automatically in Equifax-breach territory. You are in "convincing hospital impersonation" territory for years.
What patients should do
- Hang up on callers asking you to "confirm" appointment details then read a one-time code.
- Open patient portals by typing the URL, not links in SMS about rescheduling.
- Use unique passwords on MyHealthOne and other HCA-linked portals; turn on MFA if offered.
- Enroll in credit monitoring if HCA offered it in your notification letter—optional for SSN-free rows but harmless.
Canonical record
HCA Healthcare 2023 on BreachHistory.
Sources: BleepingComputer, HIPAA Journal, HCA privacy update.