HCA Healthcare Inc.
bd_ed9268ebe6d9585b · schema v1 · pii pii-v1
Full breach record for HCA Healthcare Inc. →6 incidents on fileHCA Healthcare, Inc. notified the NH Attorney General that an unauthorized third party accessed its Global Human Resources website on February 23, 2026. The attacker used fake authentication portals (phishing) and a man-in-the-middle attack to intercept employee credentials. The actor changed direct deposit information for certain employees, exposing names, SSNs, and bank account details. Five New Hampshire residents were affected. HCA reset accounts, removed external access to the site, and engaged an incident response partner. Affected individuals were notified on July 17, 2026, and offered one year of credit monitoring.
J jump to incidentP pin to compareR raw source
Incident timeline
Feb 23, 2026
Begins
Jul 27, 2026
Filed
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.