Breach report
HealthcareHCA Healthcare
HCA Healthcare reports breach of 11 million patients' personal data
A hacker stole 27 million rows of patient data from a storage system HCA Healthcare used to format appointment emails, affecting roughly 11 million patients across 20 states at America's largest hospital operator.
Reported by TechCrunch
Records exposed
11.3M
About 11.27 million patients
Scale vs. largest on file
- When
- 2023
- How they got in
- Theft from an external storage location used for automated patient email formatting
- Sector
- Healthcare
On July 10, 2023, HCA Healthcare, the Nashville-based operator of more than 180 hospitals and roughly 2,300 care sites, disclosed that patient information had been stolen and was being advertised on a cybercrime forum. The company later reported that about 11.27 million people were affected, making it one of the largest health data breaches filed with federal regulators that year.
According to HCA, the data was taken from an external storage location used exclusively to automate the formatting of email messages, such as appointment reminders and outreach about health programs. The seller claimed to hold about 27 million rows of data and had contacted HCA with a deadline to meet demands before releasing it. HCA did not detail how the storage location was compromised or whether a vendor managed it, and it said it disabled user access to the system as soon as it learned of the theft. HCA said it had reported the incident to law enforcement, hired outside forensic experts and did not expect a material impact on its operations or finances.
The exposed fields were largely demographic and scheduling data: patient names, cities, states and ZIP codes, email addresses, phone numbers, birthdates, gender, and service dates, locations and upcoming appointments. HCA said it did not believe clinical information, payment data, passwords or Social Security numbers were included. Patients came from about 20 states, with large concentrations in Florida, Texas, Georgia, Tennessee and California.
Even without medical records, the breach drew heavy legal scrutiny. Dozens of lawsuits were filed and consolidated, arguing that knowing where and when someone receives care is itself sensitive and useful for targeted phishing. In 2025 a federal court approved a settlement offering affected patients credit monitoring or reimbursement of documented losses, with plaintiffs' fee requests indicating a fund of more than $9 million, and HCA committed to maintaining enhanced security measures.
The incident is a reminder that ancillary systems built for convenience, such as marketing and messaging pipelines, often hold large copies of patient data with weaker protection than core medical record systems. For patients, the main risk is convincing scam emails and calls that reference real appointments and providers, a tactic fraudsters regularly use after healthcare breaches.