The listings featured on this site are from companies from which this site receives compensation. This influences: Appearance, order, and manner in which these listings are presented.
Disclosure:
Professional Reviews

vpnMentor contains reviews that are written by our community reviewers. These take into consideration the reviewers’ independent and professional examination of the products/services.

Ownership

vpnMentor was established in 2014 as an independent site reviewing VPN services and covering privacy-related stories. Today, our team of hundreds of cybersecurity researchers, writers, and editors continues to help readers fight for their online freedom in partnership with Kape Technologies PLC, which also owns the following products: ExpressVPN, CyberGhost, ZenMate, Private Internet Access, and Intego, which may be reviewed on this website.

Affiliate Commissions Advertising

vpnMentor contains reviews that follow the strict reviewing standards, including ethical standards, that we have adopted. Such standards require that each review will take into consideration the independent, honest and professional examination of the reviewer. That being said, we may earn a commission when a user completes an action using our links, at no additional cost to them. On listicle pages, we rank vendors based on a system that prioritizes the reviewer’s examination of each service, but also considers feedback received from our readers and our commercial agreements with providers.

Reviews Guidelines

The reviews published on vpnMentor are written by community reviewers that examine the products according to our strict reviewing standards. Such standards ensure that each review prioritizes the independent, professional and honest examination of the reviewer, and takes into account the technical capabilities and qualities of the product together with its commercial value for users. The rankings we publish may also take into consideration the affiliate commissions we earn for purchases through links on our website.

11 Million Patients' Data Stolen in HCA Healthcare Breach

11 Million Patients' Data Stolen in HCA Healthcare Breach
Keira Waddell Published on 14th July 2023 Senior Writer

HCA, a prominent US healthcare company, has recently announced an alarming data breach that may have affected approximately 11 million patients. The disclosure followed an incident where a cybercriminal posted a message on a well-known cybercrime forum asserting possession of the pilfered data and its availability for sale.

HCA has officially confirmed that the compromised information includes a range of personal details, such as full names, cities, states, ZIP codes, email addresses, telephone numbers, dates of birth, genders, service dates, locations, and next appointment dates. This data could potentially be exploited by malicious individuals to launch phishing attacks and social engineering scams.

Fortunately, HCA Healthcare states that the compromised data does not include detailed clinical information, payment details, passwords, social security numbers, or driver's license numbers. The organization emphasizes that patient care and services remain uninterrupted despite the breach.

HCA operates an extensive network of 180 hospitals and 2,300 sites spread across more than 20 states in the US. It also serves as a private healthcare provider for UK residents. HCA has diligently listed over 1,000 impacted hospitals and facilities on its website in response to the data breach.

The exact method of the data breach and how it emerged on the cybercrime forum remains undisclosed. On July 5th, DataBreaches.net was the first to report the post, where the seller claimed possession of 17 files and 27 million rows of database records. The compromised data also includes patient records created between 2021 and 2023.

In an attempt to extort HCA Healthcare, the threat actor made demands that required compliance from the organization before July 10th. However, the specifics of these demands were not disclosed in the forum post. As HCA did not comply with the demands, the hacker took the next step of offering the complete database for sale, subsequently attracting the attention of other malicious actors who expressed interest in acquiring the stolen information.

Following the incident, HCA Healthcare has notified law enforcement agencies and is actively investigating to ensure the absence of any lingering malicious activity within its networks and systems. Urgent measures have been taken to disable access to the breached storage location, and additional security and data protection measures are being implemented to prevent future breaches.

About the Author

Keira is an experienced cybersecurity and tech writer dedicated to providing comprehensive insights on VPNs, online privacy, and internet censorship.