← HCA Healthcare

2023 HCA Healthcare — external storage breach; 11.27M patients; contact data on forum

2023 11.3M records affected Share on X

Data compromised

Names, addresses (city/state/ZIP), email, phone, DOB, gender, dates/locations of service, next appointment date; no clinical, financial, or SSN per HCA

Technical writeup

Verified hospital-system disclosure — July 2023. HCA Healthcare, the largest U.S. for-profit health system, said an unauthorized party accessed an external storage location used to format patient emails (appointment reminders and program notices). Forensics found data lists with approximately 27 million rows covering about 11.27 million patients who received care at HCA hospitals and clinics across 20 states; HHS OCR lists 11,270,000 individuals affected. Exposed fields included name, city/state/ZIP, email, phone, date of birth, gender, dates and locations of service, and next appointment date. HCA stated no clinical records, financial data, or Social Security numbers were in the compromised lists. An actor listed samples on a hacking forum ahead of HCA's July 10 announcement. Despite the absence of clinical/financial data, contact-rich rows remain valuable for phishing, vishing, and appointment-themed social engineering.

Root cause

Unauthorized access to external email-formatting storage; data listed on hacking forum

References