• Home
  • News
  • Coins2Day 500
  • Tech
  • Finance
  • Leadership
  • Lifestyle
  • Rankings
  • Multimedia
Healthdata breach

Medical giant HCA Healthcare says personal data of 11 million patients in 20 states may have been stolen in a data breach

By
Frank Bajak
Frank Bajak
and
The Associated Press
The Associated Press
Down Arrow Button Icon
By
Frank Bajak
Frank Bajak
and
The Associated Press
The Associated Press
Down Arrow Button Icon
July 12, 2023, 5:04 AM ET
The Nashville headquarters of Hospital Corporation of America, one of the nation's largest hospital operators.
The Nashville headquarters of Hospital Corporation of America, one of the nation's largest hospital operators. Rusty Russell—Getty Images

Medical giant HCA Healthcare, which operates 180 hospitals in the U.S. And Britain, says the personal data of about 11 million patients in 20 states may have been stolen in a data breach.

Recommended Video

Samples of the data, including addresses, phone numbers, emails and birth dates, were posted to an online forum popular with cybercrooks by a hacker trying to sell them.

The Nashville, Tennessee-based provider said the stolen data was not believed to include Social Security numbers, payment information or clinical info such as diagnoses.

However, the data did include information on scheduled appointments and medical departments involved. A file dumped online by the hacker on Monday following what appeared to be a failed attempt to extort HCA includes nearly 1 million records from the company’s San Antonio division.

If 11 million patients are affected, the breach would rank in the top five as reported by health care institutions to the Department of Health and Human Services Office of Civil Rights. In the worst such hack, affecting the medical insurer Anthem Inc. In 2015, 79 million people. Chinese spies were indicted in that case and there no evidence the stolen data was ever put up for sale.

The hacker, who first posted a sample of stolen data online on July 5, was trying to sell the data and was apparently attempting to extort HCA. They claimed to have 27.7 million records and set a Monday deadline.

A company spokesman did not immediately respond to an email and phone message asking if HCA received an extortion demand.

In a statement posted to its website on Monday, HCA said the data was stolen from “an external storage location” used to “automate the formatting of email messages.” HCA did not say when the data was stolen or when it learned of the theft.

The company said it would offer credit monitoring and identity theft protection “where appropriate.” It cautioned that patients should be wary of phone calls, emails and text messages.

HCA listed facilities in 20 U.S. States from Alaska to Virginia where people who received services might be affected.

In addition to hospitals, HCA Healthcare runs 2,300 ambulatory sites including surgery and urgent care centers and free-standing emergency rooms. It reports treating 37 million patients annually.

Health care is classified by the U.S. Government as one of 16 critical infrastructure sectors, and health care providers are seen as prime targets for hackers.

Coins2Day Brainstorm AI returns to San Francisco Dec. 8–9 to convene the smartest people we know—technologists, entrepreneurs, Coins2Day Global 500 executives, investors, policymakers, and the brilliant minds in between—to explore and interrogate the most pressing questions about AI at another pivotal moment. Register here.
About the Authors
By Frank Bajak
See full bioRight Arrow Button Icon
By The Associated Press
See full bioRight Arrow Button Icon
Rankings
  • 100 Best Companies
  • Coins2Day 500
  • Global 500
  • Coins2Day 500 Europe
  • Most Powerful Women
  • Future 50
  • World’s Most Admired Companies
  • See All Rankings
Sections
  • Finance
  • Leadership
  • Success
  • Tech
  • Asia
  • Europe
  • Environment
  • Coins2Day Crypto
  • Health
  • Retail
  • Lifestyle
  • Politics
  • Newsletters
  • Magazine
  • Features
  • Commentary
  • Mpw
  • CEO Initiative
  • Conferences
  • Personal Finance
  • Education
Customer Support
  • Frequently Asked Questions
  • Customer Service Portal
  • Privacy Policy
  • Terms Of Use
  • Single Issues For Purchase
  • International Print
Commercial Services
  • Advertising
  • Coins2Day Brand Studio
  • Coins2Day Analytics
  • Coins2Day Conferences
  • Business Development
About Us
  • About Us
  • Editorial Calendar
  • Press Center
  • Work At Coins2Day
  • Diversity And Inclusion
  • Terms And Conditions
  • Site Map

© 2025 Coins2Day Media IP Limited. All Rights Reserved. Use of this site constitutes acceptance of our Terms of Use and Privacy Policy | CA Notice at Collection and Privacy Notice | Do Not Sell/Share My Personal Information
FORTUNE is a trademark of Coins2Day Media IP Limited, registered in the U.S. and other countries. FORTUNE may receive compensation for some links to products and services on this website. Offers may be subject to change without notice.