HCA Healthcare data breach impacts 11 million patients

The organization is facing at least five class action lawsuits related to the data breach

Add bookmark
A doctor in lab safety gear sitting in front of a computer

US-based healthcare company, HCA Healthcare, has suffered a data breach impacting 11 million patients.

The cyber attack was discovered on July 10, after the personal data of patients was posted online. In a statement regarding the breach, HCA Healthcare says the data appears to have been stolen from “an external storage location exclusively used to automate the formatting of email messages”.

As the data stolen during the cyber attack is used for email messages, for example reminders to patients to book appointments, the dataset includes personally identifying information. This information includes:

  • Patient names, cities, states and zip codes.
  • The telephone numbers, email addresses, gender and dates of birth of patients.
  • The service dates, locations and the dates of upcoming appointments.
  • After the unauthorized access and data theft was discovered, HCA Healthcare disabled access to the third-party storage location. The company also contacted all those impacted by the data breach.

The data stolen and posted online did not include any clinical information, payment information or sensitive information, e.g. social security numbers. HCA Healthcare assured its patients that the cyber attack had not impacted the company’s processes and does not believe it will “materially impact its business, operations or financial results”.

HCA Healthcare said that it had launched an investigation into the data breach and had reported it to the relevant authorities.

While the investigation in the data breach is ongoing, HCA Healthcare reported that during initial investigations the company had “not identified evidence of any malicious activity on HCA Healthcare networks or systems related to this incident”.

Following the cyber attack and subsequent data breach, HCA Healthcare patients have filed no less than five class action lawsuits related to the cyber security incident. The lawsuits have been filed in Nashville, where HCA Healthcare is based, Florida, California and Texas.

The class action lawsuits allege that HCA Healthcare was negligent and failed to properly protect patients’ data.

In one of the cases, plaintiffs Gary Silvers and Richard Marous say that due to the data breach they now face “a lifetime risk of identity theft due to the nature of the information lost, and a diminishment in the value of their private data”. They allege that HCA Healthcare should have known the value the data had to cyber criminals and implemented better security measures.

Plaintiffs also allege that the data security guidelines followed by HCA Healthcare failed to comply with those set by the Federal Trade Commission or in the Health Insurance Portability and Accountability Act. 


Upcoming Events

Automotive Cyber Security, Connectivity & SDV Week 2025

18th - 20th November, 2025

Van der Valk Hotel Berlin Brandenburg, Germany

Automotive Cyber Security, Connectivity & SDV Week 2025

Digital Identity Week

1st - 2nd September 2026

Sydney, Australia

Digital Identity Week

Latest Webinars

From Dependencies to Defences: Navigating Software Supply Chain Security

2025-09-24

11:00 AM - 12:00 PM SGT

Learn how to defend your software supply chain from dependency threats and build resilient security...

Unpacking global regulatory frameworks to enhance third-party operational resilience

2024-11-14

11:00 AM - 12:00 PM EST

Join this webinar to explore the resilience-focused requirements of DORA, NIS2 and other global regu...

Preventing financial and reputational risk with process intelligence

2024-05-23

11:00 AM - 12:00 PM EDT

Learn how to manage risk stemming from poorly controlled processes in a collaborative way

Recommended