Desk live·
ForensicPost
Breaches/Healthcare/File 23-0710

HCA Healthcare Reported 11.27 Million Patients Affected by Email Storage Breach

The data did not come from a clinical system. It came from an external storage location used to format appointment reminders — and it was posted to a forum. No diagnoses, no card numbers, no social security numbers: just enough to identify eleven million patients.

Constructed geometry · not a chart of case data
JurisdictionUSAthe affected organisation’s jurisdiction, not the actor’s suspected origin
TargetHCA Healthcare
ActorUnattributed
S. Rosler10 min readConfidence: high2 sources reviewed

HCA Healthcare announced on 10 July 2023 that an unauthorised party had accessed an external storage location used to automatically format emails — appointment reminders and messages about programmes and services. The data was subsequently posted to an online forum.

The incident was reported to the US Department of Health and Human Services Office for Civil Rights as affecting 11,270,000 individuals.

The Peripheral System Held The Population

An email formatting store is about as far from a clinical system as a hospital group’s architecture gets. It exists to merge a name into a template. To do that it needs the name, the address, the phone number, the date of birth — for every patient the organisation might ever message.

That is the whole file. The system with the weakest claim to protection held the widest population, because breadth is what a mail-merge store is for.

What Was Not Taken Matters Less Than It Sounds

HCA stated the data did not include clinical detail, payment card data or social security numbers. That is a real and worthwhile distinction, and it is also the distinction that makes this exposure permanent rather than remediable.

A card can be reissued. A name, a date of birth and an address, tied to the fact that you are a patient of a named hospital group, cannot be. The corpus records the same irreversibility at 23-1204 for ancestry data and at 26-0324 for fingerprints.

The Register Is Why We Can Count It

This file carries a firm figure because US healthcare has a mandatory breach register and HCA had to file against it. The corpus argues at 25-1231b and 25-1227b that the only sectors it can measure are the ones somebody forced to publish.

How we reported this

Built on contemporaneous reporting of HCA Healthcare’s disclosure and of the figure reported to the HHS Office for Civil Rights. The 11,270,000 figure is the number HCA reported to the regulator. The description of the affected system and of excluded data categories is HCA’s own. A separate figure of 27.7 million records appears in reporting and is not the same quantity as affected individuals; it is not carried here. No actor attribution is made and no indicators are reproduced. Graded high. Corrections: corrections@forensicpost.com.

Sources
  1. 11.27 Million HCA Healthcare Patients Affected by Recent CyberattackHIPAA Journal
  2. HCA Healthcare breach affects patients’ personal dataTechCrunch
S. Rosler
Covers extortion groups and leak-site economics. Verifies our sample sets.
// the chain of custody — tuesdays

Get the next file first.

One incident a week, taken apart properly. Logs, timelines, and what the filing left out.

PGP-signed edition · no tracking pixels · one-click unsubscribe
© 2026 ForensicPost Media · the desk · newsletter · searchGlossary