iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more
Norton Healthcare disclosed a ransomware incident discovered on May 9, 2023, involving unauthorized access to certain network storage devices. SecurityWeek reported that about 2.5 million people were affected, based on Norton’s filing with Maine; that is an approximate reported figure, not a verified count of stolen records. Norton said it had no evidence that its medical record system or Norton MyChart was accessed.
Was Norton Healthcare hacked?
Yes. Norton Healthcare said it discovered a cybersecurity incident on May 9, 2023, and later determined it was a ransomware attack. Its investigation found unauthorized access to certain network storage devices between May 7 and May 9, 2023. Norton said it notified federal law enforcement and brought in outside cybersecurity specialists to investigate. Norton Healthcare’s December 8, 2023 statement
In its Maine notice, Norton said it analyzed the incident and reviewed potentially exfiltrated files from May into mid-November 2023 to identify people and the types of information involved. Norton also said it did not pay the ransom. Norton Healthcare’s Maine notice
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
SecurityWeek reported that the BlackCat/ALPHV ransomware group claimed responsibility and threatened to leak roughly 4.7 terabytes of data. That was the group’s claim as reported by SecurityWeek; it is not a verified count of personal records stolen or proof of what was ultimately published. SecurityWeek’s report
#1 Best Overall
How many people were affected?
SecurityWeek reported approximately 2.5 million affected individuals, attributing the figure to Norton’s filing with Maine. Treat it as an approximate reported total, not an independently established count of records stolen. Norton’s notice says the affected population included current and former patients, employees, and employee dependents or beneficiaries; the information potentially involved differed from person to person. SecurityWeek Norton’s Maine notice
Was MyChart or the medical record system accessed?
Norton said: “We have no evidence that the unauthorized individual(s) gained access to Norton Healthcare’s medical record system or Norton MyChart.” This is Norton’s finding, stated in its December 8, 2023 incident statement; it is not a claim that no personal or health information was exposed. Files on network storage devices were involved, and Norton’s notice lists health-related information among the data that may have been affected. Norton Healthcare’s statement Norton Healthcare’s Maine notice
What information may have been exposed?
Norton said potentially impacted files could include different information depending on the individual. Categories listed in its notice include:
- Names and contact details
- Social Security numbers and dates of birth
- Health and insurance information
- Medical identification numbers
- For some individuals, government identification numbers, financial account numbers, or digital signatures
The notice does not mean every listed category applied to every affected person. Use the breach letter you received to determine which information Norton said may have been involved in your case. Norton Healthcare’s Maine notice
What should you do if you received a Norton Healthcare breach letter?
- Read the letter for your specific data categories. Do not assume that every item in Norton’s general list applies to you.
- Use the contact details printed in the letter. Norton’s 2023 statement described a breach-specific call center, but its phone number and hours are historical details and are not confirmed as currently active.
- Check the enrollment deadline and eligibility for the offered protection. Norton said affected people would be offered 24 months of credit monitoring and identity protection through Kroll. This was a historical offer announced in 2023; do not assume enrollment is still available.
- Pay attention to accounts and information relevant to your notice. If it lists Social Security or financial information, watch for unfamiliar account activity and follow the relevant bank or credit provider’s guidance. If it lists health or insurance information, review related statements and communications for activity you do not recognize.
HHS says breach notices should, to the extent possible, explain what happened and what information was involved, recommend protective steps, describe mitigation, and give contact details. Its general rule summary says covered entities must notify affected individuals without unreasonable delay and no later than 60 days after discovery. That general requirement is not a finding about Norton’s compliance. HHS Breach Notification Rule
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.What Norton said it did
Norton said it notified law enforcement, investigated with outside cybersecurity support, and reviewed potentially affected files to identify individuals and the data involved. It also said it would mail letters to potentially affected people for whom it had an address. The company stated in December 2023 that it did not pay the ransom and that it would offer two years of free credit protection services to affected people; the Maine notice identifies Kroll and a 24-month term. Norton’s statement Norton’s Maine notice
Quick Recap
Best Value
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

