HCA Healthcare: 11 Million Patient Records, One Exposed Storage Location
One of the largest hospital operators in the country lost patient data not through a sophisticated hack, but through a misconfigured external storage location. Here's what that means.
In July 2023, HCA Healthcare — one of the largest hospital systems in the United States, operating facilities across 20 states — disclosed that data belonging to roughly 11 million patients had been stolen from an external storage location used to format email messages.
What actually happened
The exposed data wasn’t pulled from HCA’s core medical record systems. It came from a storage location used for automating patient communications — things like appointment reminders. That distinction matters: the stolen data was largely contact and demographic information (names, contact details, appointment dates) rather than full clinical records or Social Security numbers, according to HCA’s own disclosure.
Why “less sensitive” data still matters
Even without medical records or financial details, this kind of data is exactly what’s used to make phishing attempts look legitimate — a scam email referencing your real name, the hospital you actually visit, and a plausible appointment date is far more convincing than a generic one.
The uncomfortable pattern in healthcare breaches
This wasn’t a novel, unstoppable attack — it was data sitting in a storage location, formatted for an automated messaging system, that ended up accessible to someone who shouldn’t have had it. A large share of healthcare breaches trace back to exactly this kind of gap: not the core clinical systems, but the supporting infrastructure around them that handles data in bulk.
What to actually do about it
- Be skeptical of appointment-related messages that ask you to click a link or confirm personal details, especially in the months after a healthcare breach notification.
- Confirm what data was actually exposed in your specific notification — healthcare breach letters usually specify categories (contact info vs. clinical vs. financial), and the response you need depends heavily on which one applies to you.
- Report suspicious contact claiming to be from the hospital system to the hospital directly through a number you look up independently, not one provided in a suspicious message.
Worried this affects you?
Check whether your email address has shown up in this breach — or any other — in seconds.
Run a free breach check →Related coverage
The Change Healthcare Breach: The Largest Healthcare Hack in US History
A ransomware attack on a single billing company froze prescriptions and payments across the entire US healthcare system for weeks. Here's what happened and who was affected.
The MOVEit Breach Explained: What Actually Happened
A 2023 flaw in a file-transfer tool used by thousands of companies led to one of the largest data breaches in recent memory. Here's what it means if you got a notification letter.