HCA Healthcare says data breach may affect 11 mn patients in 20 states

Medical giant HCA Healthcare, which operates 180 hospitals in the U.S. and Britain, says the personal data of about 11 million patients in 20 states may have been stolen in a data breach.

data sharing
Samples of the data, including addresses, phone numbers, emails and birth dates, were posted to an online forum popular with cybercrooks by a hacker trying to sell them.
AP Boston
3 min read Last Updated : Jul 11 2023 | 11:19 PM IST

Medical giant HCA Healthcare, which operates 180 hospitals in the U.S. and Britain, says the personal data of about 11 million patients in 20 states may have been stolen in a data breach.

Samples of the data, including addresses, phone numbers, emails and birth dates, were posted to an online forum popular with cybercrooks by a hacker trying to sell them.

The Nashville, Tennessee-based provider said the stolen data was not believed to include Social Security numbers, payment information or clinical info such as diagnoses.

However, the data did include information on scheduled appointments and medical departments involved. A file dumped online by the hacker on Monday following what appeared to be a failed attempt to extort HCA includes nearly 1 million records from the company's San Antonio division.

If 11 million patients are affected, the breach would rank in the top five as reported by health care institutions to the Department of Health and Human Services Office of Civil Rights. In the worst such hack, affecting the medical insurer Anthem Inc. in 2015, 79 million people. Chinese spies were indicted in that case and there no evidence the stolen data was ever put up for sale.

The hacker, who first posted a sample of stolen data online on July 5, was trying to sell the data and was apparently attempting to extort HCA. They claimed to have 27.7 million records and set a Monday deadline.

A company spokesman did not immediately respond to an email and phone message asking if HCA received an extortion demand.

In a statement posted to its website on Monday, HCA said the data was stolen from an external storage location used to automate the formatting of email messages. HCA did not say when the data was stolen or when it learned of the theft.

The company said it would offer credit monitoring and identity theft protection where appropriate. It cautioned that patients should be wary of phone calls, emails and text messages.

HCA listed facilities in 20 U.S. states from Alaska to Virginia where people who received services might be affected.

In addition to hospitals, HCA Healthcare runs 2,300 ambulatory sites including surgery and urgent care centers and free-standing emergency rooms. It reports treating 37 million patients annually.

Health care is classified by the U.S. government as one of 16 critical infrastructure sectors, and health care providers are seen as prime targets for hackers. 

(Only the headline and picture of this report may have been reworked by the Business Standard staff; the rest of the content is auto-generated from a syndicated feed.)

*Subscribe to Business Standard digital and get complimentary access to The New York Times

Smart Quarterly

₹900

3 Months

₹300/Month

SAVE 25%

Smart Essential

₹2,700

1 Year

₹225/Month

SAVE 46%
*Complimentary New York Times access for the 2nd year will be given after 12 months

Super Saver

₹3,900

2 Years

₹162/Month

Subscribe

Renews automatically, cancel anytime

Here’s what’s included in our digital subscription plans

Exclusive premium stories online

  • Over 30 premium stories daily, handpicked by our editors

Complimentary Access to The New York Times

  • News, Games, Cooking, Audio, Wirecutter & The Athletic

Business Standard Epaper

  • Digital replica of our daily newspaper — with options to read, save, and share

Curated Newsletters

  • Insights on markets, finance, politics, tech, and more delivered to your inbox

Market Analysis & Investment Insights

  • In-depth market analysis & insights with access to The Smart Investor

Archives

  • Repository of articles and publications dating back to 1997

Ad-free Reading

  • Uninterrupted reading experience with no advertisements

Seamless Access Across All Devices

  • Access Business Standard across devices — mobile, tablet, or PC, via web or app

More From This Section

Topics :Data breachhealthcare

First Published: Jul 11 2023 | 11:19 PM IST

Next Story