DataBreaches.Net

Menu
  • About
  • Breach Notification Laws
  • Privacy Policy
  • Transparency Report
Menu

HCA Healthcare settled two lawsuits this week; one was over its 2023 data breach

Posted on August 2, 2025August 2, 2025 by Dissent

Steve Alder reports:

HCA Healthcare Inc. has agreed to settle class action litigation stemming from a July 2023 data breach that was reported to the HHS’ Office for Civil Rights as affecting 11,270,000 patients. The affected individuals had received healthcare services at HCA hospitals and doctors’ offices in 20 U.S. states.

HCA Healthcare was targeted by hackers who accessed and stole data from an external storage location, which was used to automate the formatting of email messages. A database was stolen that contained 27.7 million records. The hackers listed the database for sale when the ransom was not paid. Data compromised in the incident included names, contact information, dates of birth, and appointment information.

Read more at HIPAA Journal.

DataBreaches broke the story of the HCA Healthcare breach in July 2023, and tfollowed up with additional coverage  which was referenced in the class action complaint (In re HCA Healthcare, Inc. Data Security Litigation, Case 3:23-cv-00684).

As is often the case in such litigation, HCA Healthcare has not admitted any wrongdoing but has settled the consolidated class action lawsuit. The official settlement website is HCAHealthcareSettlement.com, where consumers can find out if they are eligible to be reimbursed and what documentation may be required. Eligible class members may be entitled to either of the following:

  • Credit Monitoring and Insurance Services – One (1) year of the Credit Monitoring and Insurance Services (“CMIS”). CMIS will include credit monitoring, fraud consultation, and identity theft restoration services; AND
  • Documented Loss Payment – Settlement Class Members may submit a claim for a Documented Loss payment of up to $5,000 with Reasonable Documentation supporting the loss as a result of the Data Incident.

DataBreaches notes that the settlement agreement also contains a section on HCA’s commitment to improving security, but details are filed under seal.

The total amount of the settlement has not been revealed, but has been estimated at $9M+ by extrapolating from the $3.1 million allocated for attorneys’ fees, which are often one-third of a total settlement amount.

This was not the only settlement involving HCA Healthcare announced this week, however. Courthouse News reported that HCA Healthcare settled a suit by several state attorneys general and the CFPB stemming from HCA Healthcare requiring nurses hired at HCA hospitals to sign a training repayment agreement provision as part of their employment contract. In total, HCA will pay $2.9 million in penalties between settlements in California, Colorado and Nevada.

Category: Breach IncidentsHackHealth DataU.S.

Post navigation

← Highlands Oncology Group notifies 113,575 people after ransomware attack by Medusa
Qilin Ransomware Affiliate Panel Login Credentials Exposed Online →

Now more than ever

"Stand with Ukraine:" above raised hands. The illustration is in blue and yellow, the colors of Ukraine's flag.

Search

Browse by Categories

Recent Posts

  • District of Massachusetts Allows Higher-Ed Student Data Breach Claims to Survive
  • End of the game for cybercrime infrastructure: 1025 servers taken down
  • Doctor Alliance Data Breach: 353GB of Patient Files Allegedly Compromised, Ransom Demanded
  • St. Thomas Brushed Off Red Flags Before Dark-Web Data Dump Rocks Houston
  • A Wiltshire police breach posed possible safety concerns for violent crime victims as well as prison officers
  • Amendment 13 is gamechanger on data security enforcement in Israel
  • Almost two years later, Alpha Omega Winery notifies those affected by a data breach.
  • Court of Appeal reaffirms MFSA liability in data leak case, orders regulator to shoulder costs
  • A jailed hacking kingpin reveals all about the gang that left a trail of destruction
  • Army gynecologist took secret videos of patients during intimate exams, lawsuit says

No, You Can’t Buy a Post or an Interview

This site does not accept sponsored posts or link-back arrangements. Inquiries about either are ignored.

And despite what some trolls may try to claim: DataBreaches has never accepted even one dime to interview or report on anyone. Nor will DataBreaches ever pay anyone for data or to interview them.

Want to Get Our RSS Feed?

Grab it here:

https://databreaches.net/feed/

RSS Recent Posts on PogoWasRight.org

  • Lawmakers Warn Governors About Sharing Drivers’ Data with Federal Government
  • As shoplifting surges, British retailers roll out ‘invasive’ facial recognition tools
  • Data broker Kochava agrees to change business practices to settle lawsuit
  • Amendment 13 is gamechanger on data security enforcement in Israel
  • Changes in the Rules for Disclosure for Substance Use Disorder Treatment Records: 42 CFR Part 2: What Changed, Why It Matters, and How It Aligns with HIPAAs

Have a News Tip?

Email: Tips[at]DataBreaches.net

Signal: +1 516-776-7756

Contact Me

Email: info[at]databreaches.net
Security Issue: security[at]databreaches.net
Mastodon: Infosec.Exchange/@PogoWasRight
Signal: +1 516-776-7756
DMCA Concern: dmca[at]databreaches.net
© 2009 – 2025 DataBreaches.net and DataBreaches LLC. All rights reserved.