NASHVILLE, Tenn., August 14, 2023 – HCA Healthcare, Inc. (NYSE: HCA), one of the nation’s leading healthcare providers which, through its affiliates, operates 182 hospitals and 2,300+ sites across 20 states, announced today that notification letters have been mailed to certain patients affected by a previously reported data security incident. HCA Healthcare issued a press release to report the incident publicly on July 10, 2023 and sent emails to the patients impacted by the incident the following week. HCA Healthcare is now mailing notification letters on a rolling basis, according to states of residence. This press release is intended to provide the same information included in the notification letters to individuals for whom HCA Healthcare has insufficient or out-of-date contact information.
As previously reported, on or around July 5, 2023, HCA Healthcare discovered that a list of certain information with respect to some of its patients was made available on an online platform by an unauthorized party. The information was obtained by the unauthorized party in late June in what appears to be a theft from an external storage location exclusively used to automate the formatting of email messages, such as reminders that patients may wish to schedule an appointment and education on healthcare programs and services. This incident caused no disruption to the care and services HCA Healthcare affiliates provide to patients and communities.
The exposed files contained patient name, city, state, zip code, email, telephone number, date of birth, gender, service date, location and, in some instances, the date of next appointment. The exposed personal information does not include clinical information, such as treatment, diagnosis, or condition; or payment information, such as credit card or account numbers; or other sensitive information, such as passwords, government-issued ID numbers, or social security numbers.
HCA Healthcare disabled user access to the aforementioned storage location as an immediate containment measure. HCA Healthcare also reported this event to law enforcement, retained third-party forensic and threat intelligence advisors to investigate the incident, and secured complimentary credit and identity protection services for affected individuals.
HCA Healthcare cares deeply about the patients it serves and takes this incident very seriously. Patients are encouraged to be vigilant against identity theft and fraud by reviewing account statements, monitoring any available credit reports for unauthorized or suspicious activity, and taking care in response to any email, telephone or other contacts that ask for personal or sensitive information (e.g., phishing). HCA Healthcare will never request sensitive information by phone or email and encourages patients to remain vigilant in identifying calls, emails or SMS texts which appear to be spam or fraudulent. Additionally, HCA Healthcare is providing complimentary credit monitoring and identity protection services to affected individuals for 2 years via IDX. Information regarding these services and enrollment instructions are included in the notification letters which are being mailed to impacted individuals, in addition to this press release.
HCA Healthcare has also established a dedicated toll-free call center to support individuals with questions about the incident. The call center can be reached at 1 (888) 993-0010, Monday to Friday from 8 am – 8 pm Central Time, excluding major U.S. holidays. Additional information can also be found on a dedicated webpage: hcahealthcare.com/privacyupdate to keep its patients informed.
Nashville-based HCA Healthcare is one of the nation’s leading providers of healthcare services comprising 180 hospitals and approximately 2,300 ambulatory sites of care, including surgery centers, freestanding ERs, urgent care centers, and physician clinics, in 20 states and the United Kingdom. With its founding in 1968, HCA Healthcare created a new model for hospital care in the United States, using combined resources to strengthen hospitals, deliver patient-focused care and improve the practice of medicine. HCA Healthcare has conducted a number of clinical studies, including one that demonstrated that full-term delivery is healthier than early elective delivery of babies and another that identified a clinical protocol that can reduce bloodstream infections in ICU patients by 44%. HCA Healthcare is a learning health system that uses its more than 37 million annual patient encounters to advance science, improve patient care and save lives.
To read the original July 10, 2023 news release, click here.
All references to “Company,” “HCA” and “HCA Healthcare” as used throughout this document refer to HCA Healthcare, Inc. and its affiliates.
HCA Healthcare recently discovered that a list of certain information with respect to some of its patients was made available by an unknown and unauthorized party on an online forum. The list includes:
Clinical information (such as treatment, diagnosis, or condition), payment information (such as credit card or account numbers), or other sensitive information (such as passwords, driver’s license or social security number) is not involved.
The external storage location was exclusively used to automate the formatting of email messages.
Upon discovery of the incident, we have worked as quickly as possible to identify and contact the patients whose data was impacted by this data security incident. We sent an email to impacted patients starting on July 14, and are in the process of mailing out notification letters on a rolling basis, according to states of residence. If you received an email or notice letter, your information appeared on a list of individuals who received care at a doctor’s office, clinic, hospital, or emergency room affiliated with HCA Healthcare, and the list was involved in the data security incident. Because the list did not include street address, we have been working with outside vendors to append the correct street address to the list of impacted persons. We are also following media and substitute notice procedures defined under applicable law to ensure that everyone on the list is notified.
HCA Healthcare is offering credit monitoring and identity protection services to all impacted patients, and the detailed instructions to enroll are included in the notification letters mailed to impacted patients, and also available here. We also encourage patients to remain vigilant in identifying calls, emails or SMS texts which appear to be spam or fraudulent. Additionally, patients should never open links or attachments sent from untrusted sources.
Yes. On July 14, 2023 we began emailing patients to provide them with information about the data security incident and to encourage them to be vigilant about any suspicious or unexpected communications from an unfamiliar source or from anyone claiming to be affiliated with HCA Healthcare. Notification letters to impacted patients are being sent by first class mail on a rolling basis, according to states of residence and applicable laws.
Patients can call us at (888) 993-0010 to ask any general questions and to confirm the legitimacy of any communication from anyone claiming to be affiliated with HCA Healthcare. Representatives will be available to provide assistance Monday through Friday 8:00am - 8:00pm Central Time. If you receive any communication regarding an invoice, outstanding balance, or payment reminder that was not expected or that you believe may be fraudulent, please contact us so that we can confirm the legitimacy of the communication.
HCA Healthcare is one of the country’s leading providers of healthcare services with 182 hospitals and 2,300+ sites across 20 states and the United Kingdom. Though you may not recognize the HCA Healthcare name, if you received care at a hospital or physician office that HCA Healthcare owns or operates, your information might be on the list. We are working as quickly as possible to specifically identify and contact patients whose data is impacted by this incident.
HCA Healthcare believes that the list contains approximately 27 million rows of data that includes information for approximately 11 million HCA Healthcare patients.
No. The patient IT systems of HCA UK are separate to those of HCA Healthcare. These have not been affected and data of patients that have been cared for at HCA UK facilities has not been impacted as a result of the incident.
We learned about the unauthorized persons claims on the online forum on July 5, shortly after the posting was made, and immediately activated incident response protocols to understand and assess the situation.
We are very familiar with this data, which was used to automate the formatting of email messages to our patients, such as reminders that a patient may want to schedule an appointment. Our forensic investigation into the data security incident is robust and ongoing.
No. That information identifies the hospital or physician office on whose behalf certain email messages were sent. It is not information that is specific to any patient.
The emails were intended to communicate general information to patients, including reminders that patients may wish to schedule an appointment and education on healthcare programs and services. For example, the relevant email activities are conducted on behalf of a facility or physician office, and never involve an individual doctor communicating individually to a patient about his or her treatment.
Yes, we have reported to the US Department of Health and Human Services, and state governments, including on a voluntary basis. Our focus is on our patients and ensuring they have information about the data security incident and the actions already underway to take care of them. We also are taking the appropriate steps to inform law enforcement agencies and government officials about the incident and to comply with applicable legal and regulatory requirements.
HCA Healthcare disabled user access to the storage location as an immediate containment measure. HCA Healthcare also has several robust security strategies, systems, and protocols in place to help protect data. The company’s efforts to protect data include ongoing education for our colleagues, physicians, vendors, and others to maintain awareness of safe practices that can help ensure compliance and the security of our information.
Not necessarily. The incident only affected certain, but not all, HCA Healthcare-affiliated facilities. As part of our effort to inform as many patients as possible whose personal information was affected by this incident, we have posted substitute notice on the websites of all HCA Healthcare-affiliated facilities, including those that were not affected by the incident. For a list of facilities that are or were previously affiliated with HCA Healthcare and may have been affected by this incident, please refer to the section below on “Affected Facilities'.
If you received an email or notice letter, your information appeared on a list of individuals who received care at a doctor’s office, clinic, hospital, or emergency room affiliated with HCA Healthcare, and the list was involved in the data security incident.
The name of a doctor’s office, clinic, hospital or emergency room on the list is not always known by an “HCA” name, and it’s also possible that a doctor’s office, clinic, hospital, or emergency room changed names since your last visit.
The following list of facilities is provided as a courtesy to supplement information about the various facilities represented on the list in question:
Hospitals
Physician Clinics
Hospitals
Physician Clinics
Hospitals
Physician Clinics
Hospitals
Physician Clinics
Hospitals
Physician Clinics
Hospitals
Physician Clinics
Hospitals
Physician Clinics
Hospitals
Physician Clinics
Hospitals
Physician Clinics
Hospitals
Physician Clinics
Hospitals
Physician Clinics
Physician Clinics
Hospitals
Physician Clinics
Hospitals
Physician Clinics
Hospitals
Physician Clinics
Hospitals
Physician Clinics
Hospitals
Physician Clinics
Hospitals
Physician Clinics
Hospitals
Physician Clinics
Hospitals
Physician Clinics