HCA Healthcare, Inc. has notified state regulators and affected employees of a data security incident involving unauthorized access to its Global Human Resources website that resulted in fraudulent changes to employee direct deposit information. The exposed information included Social Security numbers and banking details. Companies that manage employee payroll and personal data have a responsibility to protect that information from unauthorized access.
HCA Healthcare’s Data Breach Investigation
According to a notice filed with the New Hampshire Attorney General’s Office, HCA Healthcare determined that on February 23, 2026, an unauthorized third party accessed the company’s Global Human Resources website and changed the direct deposit information for certain employees. The third party obtained login credentials by creating fake HCA authentication portals that appeared to employees searching for the real Website online, then used a man-in-the-middle attack to intercept those credentials as employees attempted to log in.
Upon discovering the incident, HCA Healthcare contacted the employees whose direct deposit information had been altered, reset all employee account credentials, took down the fraudulent authentication portals, and engaged a third-party incident response firm to determine the scope of the third party’s access. On February 26, 2026, the company removed external access to the affected Website entirely and later removed employee Social Security numbers from the system. This kind of payroll-diversion scheme, sometimes called a business email compromise or credential-phishing attack targeting HR systems, has become an increasingly common tactic against large employers, since a single successful login can allow an attacker to redirect wages before the fraud is detected.
Because the attackers specifically targeted login credentials rather than exploiting a technical vulnerability in the Website itself, this incident illustrates how convincingly-designed fake login pages can compromise even well-defended corporate systems. Exposure of Social Security numbers alongside banking and routing information creates a heightened risk profile, since that combination of data can enable both direct financial fraud, through unauthorized account access, and longer-term identity theft, through new account or credit fraud using the stolen SSN.
When Did This Breach Occur?
The unauthorized access and fraudulent direct deposit changes occurred on or about February 23, 2026. HCA Healthcare removed external access to the affected Website on February 26, 2026. Affected individuals were notified on July 15, 2026, and the company notified the New Hampshire Attorney General’s Office on July 27, 2026.
What Information Was Breached?
HCA Healthcare’s investigation determined that the exposed information included employees’ first and last names, employee identification numbers, internal identification numbers, phone numbers, addresses, email addresses, Social Security numbers, and checking account and routing numbers. HCA Healthcare’s New Hampshire filing identified five New Hampshire residents affected by this incident; the total number of employees affected company-wide has not been publicly disclosed.
What You Can Do
HCA Healthcare is offering affected employees one year of complimentary identity theft prevention and credit monitoring services through IDX. If you received a notification letter from HCA Healthcare regarding this incident, consider taking the following steps:
- Enroll in the complimentary IDX credit monitoring services by the deadline listed in your notification letter
- Place a fraud alert or credit freeze with Equifax, Experian, and TransUnion
- Monitor your bank accounts closely for unauthorized transactions
- Request and review a free copy of your credit report from annualcreditreport.com
- Report any suspected identity theft to the FTC and your state Attorney General
File a Data Breach Lawsuit Against HCA Healthcare
If your personal information was exposed in the HCA Healthcare data breach, you may have legal options available to you. Companies entrusted with sensitive employee and financial information are expected to maintain reasonable safeguards to protect that data, and victims of a breach may be entitled to compensation.
Contact us at Class Action U, where we’ll connect you with a lawyer skilled in class action lawsuits. If you’ve been contacted about this breach, received notice, or discovered you were impacted, fill out our quick, easy, and secure form to sign up. There is no cost to reach out to our legal partner and no obligation after speaking with someone from our team.