2023 NextGen Healthcare — stolen client credentials; ~1M individuals (Mar–Apr)
Data compromised
Patient PII and related clinical demographics per notification templates cited in trade press
Technical writeup
NextGen Healthcare detected unauthorized access between March 29 and April 14, 2023, and publicly confirmed on April 28 that actors used compromised client credentials to reach databases hosting personal and clinical information for roughly 1.05 million individuals. HIPAA Journal and BankInfoSecurity summarized exposed fields as names, addresses, dates of birth, and Social Security numbers for the affected population. A separate January 2023 BlackCat ransomware event at the vendor was publicly described as not showing evidence of patient exfiltration and is treated as a distinct timeline in press coverage from this database incident.
Root cause
Unauthorized database access using compromised customer/client credentials