Description

HCA Healthcare, a prominent healthcare facility owner and operator in the United States and United Kingdom, recently experienced a significant data breach impacting approximately 11 million patients. The breach came to light when a hacker leaked some of the stolen data on a hacking forum. HCA Healthcare operates numerous hospitals and clinics across multiple states and countries. Initially, the breach was used as a means of blackmail, with the threat actor demanding undisclosed financial concessions from HCA Healthcare within a specific timeframe. However, as the company did not comply with the demands, the hacker proceeded to sell the complete database, attracting interest from other potential buyers. On July 11, 2023, HCA Healthcare confirmed the authenticity of the leaked data and acknowledged its impact on around 11 million individuals. The stolen database, which consists of 27 million data entries, includes information related to patients associated with HCA Healthcare. According to HCA Healthcare's breach notification, the compromised data was obtained from an external storage location primarily used for managing patient email communications. Despite the breach, HCA Healthcare assures patients that their care and services remain unaffected. Although the stolen data contains personal details like names, addresses, contact information, and appointment records, HCA Healthcare emphasizes that it does not include sensitive clinical information, payment data, passwords, social security numbers, or driver's license details. The company has promptly informed law enforcement agencies and is actively investigating to ensure there are no ongoing malicious activities within their networks and systems by the threat actors.