HCA Healthcare Inc.
bd_2da8bd258eae0806 · schema v1 · pii pii-v1
Full breach record for HCA Healthcare Inc. →4 incidents on fileOn July 10, 2023, HCA Healthcare, Inc. filed an Item 8.01 Form 8-K attaching a same-day press release (Exhibit 99.1) reporting a data security incident. HCA said it recently discovered that a list of certain information about some of its patients had been made available by an unknown and unauthorized party on an online forum. The list included patient name, city, state and zip code; email, telephone number, date of birth and gender; and service date, location and next appointment date, and did not include clinical information, payment information, or passwords, driver's license or social security numbers. HCA said this appears to be a theft from an external storage location used to automate the formatting of email messages, that it has not identified evidence of malicious activity on its networks or systems, and that patient care and day-to-day operations were not disrupted. The company reported the event to law enforcement, retained third-party forensic and threat intelligence advisors, disabled user access to the storage location as an immediate containment measure, and plans to contact impacted patients and offer credit monitoring and identity protection services where appropriate; it does not believe the incident will materially impact its business, operations or financial results.
J jump to incidentP pin to compareR raw source
Incident timeline — partial
? — ?
Breach window unknown
Jul 10, 2023
Filed
—
Corroborated · see linked filings
Compliance clocks stay unassessable until a regulatory filing lands. Dashed segments fill in automatically when corroboration arrives.
Linked disclosures
Why this link?Regulatory filings (10) · sorted by filing gap
- Delaware State AGbd_35790d97fa0a28592023-07-14 · +4dVerified
- HHS OCRbd_71092e6fb24830ae2023-07-31 · +21dVerified
- California State AGbd_64b2526179555bbb2023-08-01 · +22dVerified
- Washington State AGbd_9b908244a6dec3212023-08-01 · +22dVerified
Show 6 more filings ↓Show fewer ↑up to 52d gap
- New Hampshire State AGbd_a60290f5c43261202023-08-28 · +49dVerified
- Idaho State AGbd_ba5937f7f4bf868d2023-08-28 · +49dVerified
- Montana State AGbd_e1ece1715cd497062023-08-29 · +50dVerified
- Massachusetts State AGbd_ff2e8ab93fef2eeb2023-08-29 · +50dVerified
- Oregon State AGbd_469b4c05c3cce8b62023-08-30 · +51dVerified
- South Carolina State AGbd_9d3b8351bb1555992023-08-31 · +52dVerified
Filing propagation · 11 filings · 10 states
View merged incident ↗Pattern: first filing Jul 10, last Aug 31 (SC) — a 52-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.