← Blog

HCA Healthcare Data Breaches: Full Timeline Through 2026

Share on X

People search HCA Healthcare data breach timeline because regulated data and trust are existential—one incident triggers class actions and regulator exams. BreachHistory indexes 2 HCA Healthcare-linked incidents (1 company-confirmed), with headline counts up to 11.3M+ in catalog rows. This page maps every attested event through 2026 with internal links to canonical records.

Why HCA Healthcare breach history matters

HCA Healthcare operates in Healthcare (United States). Across indexed rows, recurring themes include unverified actor or scraping claims. Understanding the chronological pattern helps security teams, customers, and regulators separate confirmed disclosures from forum marketing.

Full timeline through 2026

2023 — external storage breach; 11.27M patients; contact data on forum

Verified breach. Verified hospital-system disclosure — July 2023. HCA Healthcare, the largest U.S. for-profit health system, said an unauthorized party accessed an external storage location used to format patient emails (appointment reminders and program notices). Forensics found data lists with approximately 27 million rows covering about 11.27 million patients who received care at HCA hospitals and clinics across 20 states; HHS OCR lists 11,270,000 individuals affected. Exposed fields included name, city/state/ZIP, email, phone, Exposed categories include Names, addresses (city/state/ZIP), email, phone, DOB, gender, dates/locations of service, next appointment date; no clinical, financial, or SSN per HCA. BreachHistory cites approximately 11.3M+ affected records in this row. See the hca-healthcare2023 and canonical BreachHistory entry.

2023 — — HCA Healthcare: Hacking, 11,270,000 records

Cataloged incident. Data breach reported. healthcare organization. Method: hacked. Source: Wikipedia List of data breaches. Exposed categories include Personal and demographic data. BreachHistory cites approximately 11.3M+ affected records in this row. See the hca-healthcare2023-11270000-wiki2 and canonical BreachHistory entry.

Patterns and analysis

  • Unverified actor or scraping claims — appears across multiple HCA Healthcare catalog entries; prioritize controls that address this class of failure.
  • Record-count hygiene — BreachHistory indexes actor-cited figures separately from company-confirmed totals; read each row's technicalWriteup before treating counts as fact.
  • 2026 monitoring — New disclosures roll into this timeline as they are verified or labeled unverified per catalog policy.

What to do if you may be affected

  1. Step 1: Enable phishing-resistant MFA on every account tied to this brand.
  2. Step 2: Use unique passwords and a password manager—breach rows often involve credential reuse.
  3. Step 3: Monitor official company breach notices and regulator filings, not dark-web downloads.
  4. Step 4: Watch for medical-ID theft and billing fraud after health-data incidents.
  5. Step 5: Bookmark the HCA Healthcare company page for new 2026+ disclosures.

Canonical BreachHistory hub

Explore every indexed row: breachhistory.com/hca-healthcare · Latest: hca-healthcare2023.

Sources: BreachHistory catalog (2 rows for HCA Healthcare), company and regulator disclosures cited in individual breach records.