HCA Healthcare Inc.
ent_019e1014d25a9699b7d5888a7f4da9da
Disclosures
14
State AG · HHS OCR · SEC 8-K · 12 jurisdictions
Multi-filing incidents
1
incidents joining 2+ filings here
Max affected reported
11,270,000
nationwide · HHS OCR TN
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- HCA Healthcare Inc.
- Normalized
- hca healthcare— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- 529900PH4ZGUH2MNEU89
- SEC EDGAR CIK
- 0000860730
- Domain
- hcahealthcare.com
Disclosure history (14)newest first
- New Hampshire State AGas victim2026-07-27
HCA Healthcare, Inc. notified the NH Attorney General that an unauthorized third party accessed its Global Human Resources website on February 23, 2026. The attacker used fake authentication portals (phishing) and a man-in-the-middle attack to intercept employee credentials. The actor changed direct deposit information for certain employees, exposing names, SSNs, and bank account details. Five New Hampshire residents were affected. HCA reset accounts, removed external access to the site, and engaged an incident response partner. Affected individuals were notified on July 17, 2026, and offered one year of credit monitoring.
- South Carolina State AGas victim2023-08-31
HCA Healthcare notified patients of a data breach discovered on July 5, 2023. An unauthorized party accessed an external storage location used for email formatting automation in late June 2023. Exposed data included names, contact info, DOB, and gender, but no PHI, SSNs, or financial data. HCA disabled access, notified law enforcement, and engaged forensic advisors. Affected individuals were offered 2 years of credit monitoring.
- Oregon State AGas victim2023-08-30
HCA Healthcare reported a data breach to the Oregon Attorney General. The breach was reported on 2023-08-30. The breach occurred during 6/30/2023. The breach was discovered on 7/5/2023. Notice was sent on 7/10/2023.
- Montana State AGas victim2023-08-29
HCA Healthcare notified Montana residents that patient contact information (names, emails, DOBs, etc.) was stolen from an external storage location in late June 2023 and posted online. The breach was discovered on July 5, 2023. No clinical or payment data was compromised. HCA engaged forensic advisors, notified law enforcement, and is offering 2 years of credit monitoring.
- Massachusetts State AGas victim2023-08-29
HCA Healthcare reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2023-08-29. 17,000 Massachusetts residents were affected. The report records the breach type as electronic.
- New Hampshire State AGas victim2023-08-28
HCA Healthcare notified the NH Attorney General of a data incident where an unauthorized party accessed patient information from an external storage location in late June 2023. Data exposed included names, DOB, and contact info. HCA disabled access, notified law enforcement, and offered credit monitoring. This is a supplemental notice regarding HIPAA mailings to NH residents.
- Idaho State AGas victim2023-08-28
HCA Healthcare notified the Idaho AG of a data incident where patient contact info (name, email, DOB, etc.) was stolen from an external storage location in late June 2023. Discovered July 5, 2023. No PHI or financial data exposed. HCA engaged forensic advisors and notified law enforcement.
- California State AGas victim2023-08-01
HCA Healthcare discovered on July 5, 2023, that patient information was made available on an online platform by an unauthorized party. The data was stolen from an external storage location in late June 2023. Affected data includes names, contact info, dates of birth, and service dates, but excludes clinical or payment data. HCA disabled access to the storage location, engaged forensic advisors, and offered 2 years of credit monitoring.
- Washington State AGas victim2023-08-01
HCA Healthcare reported a data breach affecting 7,500 Washington residents. Unauthorized access to an external storage location used for email automation occurred between June 29 and July 5, 2023. Exposed data included names, contact info, and dates of birth. No PHI or financial data was compromised. HCA disabled access, notified law enforcement, and engaged forensic investigators.
- TENNESSEEHHS OCRas victim2023-07-31
HCA Healthcare reported to HHS on 2023-07-31 a Hacking/IT Incident affecting 11,270,000 individuals. Breached information located on Network Server. Business associate present.
- Delaware State AGas victim2023-07-14
HCA Healthcare disclosed that in late June 2023, an unauthorized party accessed an external storage location used for email formatting automation. The incident, discovered on July 5, 2023, exposed patient PII including names, contact info, and DOB. No clinical or financial data was compromised. HCA disabled access, notified law enforcement, and engaged forensic advisors. Credit monitoring was offered.
- FEDERALSEC 8-Kas victim2023-07-10
On July 10, 2023, HCA Healthcare, Inc. filed an Item 8.01 Form 8-K attaching a same-day press release (Exhibit 99.1) reporting a data security incident. HCA said it recently discovered that a list of certain information about some of its patients had been made available by an unknown and unauthorized party on an online forum. The list included patient name, city, state and zip code; email, telephone number, date of birth and gender; and service date, location and next appointment date, and did not include clinical information, payment information, or passwords, driver's license or social security numbers. HCA said this appears to be a theft from an external storage location used to automate the formatting of email messages, that it has not identified evidence of malicious activity on its networks or systems, and that patient care and day-to-day operations were not disrupted. The company reported the event to law enforcement, retained third-party forensic and threat intelligence advisors, disabled user access to the storage location as an immediate containment measure, and plans to contact impacted patients and offer credit monitoring and identity protection services where appropriate; it does not believe the incident will materially impact its business, operations or financial results.
- Illinois State AGas victim2023-01-01
HCA HEALTHCARE filed a data-breach notice with the Illinois Attorney General during 2023 (case 23-521). The register records the breach as discovered on June 1, 2023. Illinois does not publish the number of people affected — 815 ILCS 530/10 permits the Attorney General to publish only the entity name, the types of personal information and the date range.
- Washington State AGas victim2021-12-01
HealthCare, Inc. reported a third-party cyberattack affecting 625 Washington residents. Attackers accessed vendor systems from Sept 19-22, 2021; HealthCare was notified Nov 3, 2021. Data involved: names and dates of birth. Vendor secured data; no misuse known.