As of this week, a data breach forum is selling personal data for possibly tens of millions of HCA Healthcare patients.
HCA, one of the top U.S. firms, announced the breach today. It informed patients that their full names, cities, and last physician visits had been compromised in a release.
Healthcare major shares rose 1.4% on Monday and were steady after hours. The provider denied disclosing clinical data.
DataBreaches.net stated Monday that the unknown hacking organization sent them a sample set of data about a patient's "low-risk" lung cancer assessment.
Which contradicts HCA's claim that no substantial or protected health information was accessed.
Patients in over two dozen states, including dozens of Florida and Texas clinics, were hacked.
New Zealand-based Emsisoft analyst Brett Callow tweeted about the data transaction.
“This may be one of the biggest healthcare breaches of the year and all time. "That said, despite affecting millions of people.
It may not be as harmful as other breaches as, based on HCA's statement, it doesn't seem to have impacted diagnoses or other medical information," Callow said.
“The hacker has claimed to have ‘emails with health diagnosis that correspond to a clientID,’” Callow said.
Patient data breaches are prevalent but vary in severity. HCA stated the hacked data came from an “external storage location exclusively used to automate the formatting of email messages” and did not include essential medical records.