Crashes, No Sound, or Screen Glitches?
Random freezes, missing sound and display glitches usually trace back to one bad driver. Find and replace yours safely.Free scan · under a minuteWindows Errors? Fix Them Before They Spread
Repair common Windows errors and clear accumulated junk for a smoother, more stable PC - no reinstall needed.Free scan · no reinstalliTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more
HCA Healthcare said information for approximately 11 million patients may have been included in a list that an unauthorized party made available online in 2023. The company described the information as contact and appointment-related details—not clinical records, payment information, or Social Security numbers. The estimate and exclusions are HCA’s statements, not an independent forensic finding.
What happened in the HCA Healthcare breach?
On July 10, 2023, HCA Healthcare announced that patient information had been made available by an unauthorized party on an online forum. HCA described the source as an external storage location used exclusively to automate the formatting of email messages, including appointment reminders and information about programs and services. In its second-quarter 2023 filing, HCA said the list may have included information for approximately 11 million patients.
HCA’s announcement characterized the incident this way: “This appears to be a theft from an external storage location exclusively used to automate the formatting of email messages.” HCA Healthcare’s July 10, 2023 announcement and its second-quarter filing are the company’s public descriptions.
Free tools Windows power users keep installed
One-click scans. No signup required.
What information was exposed?
HCA said the list contained identifying, contact, and appointment-related details. The patient notice says a next appointment date appeared only in some cases.
#1 Best Overall
- Patient name, city, state, and ZIP code
- Email address and telephone number
- Date of birth and gender
- Service date and service location
- Next appointment date in some cases
HCA said the list did not include clinical information such as treatment, diagnosis, or condition; payment information such as credit-card or account numbers; or passwords, driver’s-license numbers, or Social Security numbers. These are exclusions HCA reported. The Delaware Department of Justice-hosted patient notice provides the patient-facing description.
How did HCA discover and respond to the incident?
HCA’s patient notice says its preliminary investigation suggested the information was obtained from the external storage location in late June 2023. The notice says HCA discovered around July 5 that the list had been made available online; HCA announced the incident publicly on July 10.
HCA said it disabled user access to the storage location, reported the event to law enforcement, retained outside forensic and threat-intelligence advisers, and planned or began notifying affected patients. HCA also reported no disruption to care or day-to-day operations and said that, while its investigation was ongoing, it had not identified evidence of related malicious activity on its networks or systems. Those statements describe the company’s reported findings at the time; they do not establish whether information was misused elsewhere.
How can you tell if you were affected?
The incident-wide estimate does not identify any particular patient. HCA said it planned or began notifying impacted patients; check any notice you received directly from HCA and use the contact details in that notice to verify its authenticity. The public materials cited here do not provide a way to determine an individual’s status from the estimate alone.
Is the HCA data breach settlement still open?
The settlement administrator’s FAQ describes In re HCA Healthcare, Inc. Data Security Litigation, Case No. 3:23-cv-00684, in the U.S. District Court for the Middle District of Tennessee. It says 27 putative class actions were filed alleging inadequate data-security practices. HCA denied wrongdoing, and the FAQ says no court or judicial body had made a finding of wrongdoing in the account it provides.
The FAQ lists one year of credit monitoring, fraud consultation, and identity-theft restoration services for claimants with approved claims. It also describes payment for documented losses up to $5,000 with reasonable supporting documentation. The FAQ’s claim deadline was September 25, 2025, and its final approval hearing was scheduled for October 27, 2025. Both dates had passed by October 4, 2026. The FAQ alone does not establish what the court later decided or whether claims are still being processed. For current status, consult an updated court docket or administrator notice; the settlement administrator’s FAQ is the source for the stated terms and dates.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.What should patients do with this information?
Because HCA said Social Security numbers, payment details, and clinical information were not in the list, the disclosed categories point chiefly to contact and appointment-related details. Be alert for unexpected messages or calls that use those details to appear credible, and avoid sharing passwords or financial information in response to an unsolicited contact. The cited materials do not establish that anyone’s information was used for fraud, nor do they require patients to buy a monitoring product. If you are considering settlement services, verify current eligibility and availability with the administrator rather than relying on expired dates in the FAQ.
Quick Recap
Best Value
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

