If you've ever had an account or relationship with HCA Healthcare, it's worth checking whether your personal data was exposed in this incident. Here's what happened, what data was involved, and what to do about it.

What Happened

HCA Healthcare, one of the largest hospital operators in the United States, disclosed in July 2023 that data had been stolen from an external storage location used to format email messages to patients, rather than from its core clinical or medical record systems directly. The incident affected approximately 11 million patients across HCA's network of facilities.

What Data Was Exposed

The exposed data included patient names, addresses, email addresses, phone numbers, dates of birth, gender, and appointment information (such as service dates and locations). HCA stated that clinical information, treatment details, payment data, and Social Security numbers were not part of the exposed dataset.

Why This Still Matters

Exposed data doesn't expire. It's sold, traded, and reused for years, fueling credential stuffing attacks — automated attempts to reuse your email and password combination across other sites. If you reused a password anywhere, one old exposure can compromise several current accounts.

How to Check If You Were Affected

Use our free breach checker below — enter your email and we'll scan it against known breach databases instantly, no signup required.

What to Do If You Were Affected

👉 Check your own exposure in 30 seconds → scan your email free.

Frequently Asked Questions

When did the HCA Healthcare data breach happen?

HCA Healthcare disclosed the breach on 10 July 2023 after stolen data was posted on an online forum by the attacker, affecting an estimated 11 million patients.

What data was stolen in the HCA Healthcare breach?

Names, addresses, email addresses, phone numbers, dates of birth, gender, and appointment details were exposed. HCA stated that clinical/treatment information, payment data, and Social Security numbers were not included.

Was my medical information exposed in the HCA breach?

HCA stated that the compromised data came from a system used for formatting patient emails and did not include clinical records, diagnoses, or treatment information — though contact and appointment metadata was still exposed.

How do I check if I was affected by the HCA Healthcare breach?

HCA notified affected patients directly. You can also check your email at Scan My Shadow, and be alert for phishing emails referencing your HCA appointments or healthcare provider.

What should I do if my HCA Healthcare data was exposed?

Be cautious of phishing emails or calls referencing your specific appointment details, and verify any communication claiming to be from HCA Healthcare independently before responding or clicking links.

Sources

Related Reading