← NextGen Healthcare

2023 NextGen Healthcare — stolen client credentials; ~1M individuals (Mar–Apr)

2023 1.1M records affected Share on X

Data compromised

Patient PII and related clinical demographics per notification templates cited in trade press

Technical writeup

NextGen Healthcare detected unauthorized access between March 29 and April 14, 2023, and publicly confirmed on April 28 that actors used compromised client credentials to reach databases hosting personal and clinical information for roughly 1.05 million individuals. HIPAA Journal and BankInfoSecurity summarized exposed fields as names, addresses, dates of birth, and Social Security numbers for the affected population. A separate January 2023 BlackCat ransomware event at the vendor was publicly described as not showing evidence of patient exfiltration and is treated as a distinct timeline in press coverage from this database incident.

Root cause

Unauthorized database access using compromised customer/client credentials

References