Were you recently affected by a data breach?

HCA Healthcare Data Breach

HCA Healthcare has disclosed that an unauthorized third party used a phishing scheme to access its Global Human Resources website and redirect employee direct deposit payments. Exposed information included names, Social Security numbers, and bank account details. Affected employees were notified in July 2026.

HCA Healthcare
Date of Breach: February 23, 2026 (removed external access February 26, 2026; individuals notified July 15, 2026)
CAU logo

Who was affected:

Clients of HCA Healthcare

Impacted Data:

Names, employee identification numbers, phone numbers, addresses, email addresses, Social Security numbers, checking account and routing numbers

HCA Healthcare, Inc. has notified state regulators and affected employees of a data security incident involving unauthorized access to its Global Human Resources website that resulted in fraudulent changes to employee direct deposit information. The exposed information included Social Security numbers and banking details. Companies that manage employee payroll and personal data have a responsibility to protect that information from unauthorized access.

HCA Healthcare’s Data Breach Investigation

According to a notice filed with the New Hampshire Attorney General’s Office, HCA Healthcare determined that on February 23, 2026, an unauthorized third party accessed the company’s Global Human Resources website and changed the direct deposit information for certain employees. The third party obtained login credentials by creating fake HCA authentication portals that appeared to employees searching for the real Website online, then used a man-in-the-middle attack to intercept those credentials as employees attempted to log in.

Upon discovering the incident, HCA Healthcare contacted the employees whose direct deposit information had been altered, reset all employee account credentials, took down the fraudulent authentication portals, and engaged a third-party incident response firm to determine the scope of the third party’s access. On February 26, 2026, the company removed external access to the affected Website entirely and later removed employee Social Security numbers from the system. This kind of payroll-diversion scheme, sometimes called a business email compromise or credential-phishing attack targeting HR systems, has become an increasingly common tactic against large employers, since a single successful login can allow an attacker to redirect wages before the fraud is detected.

Because the attackers specifically targeted login credentials rather than exploiting a technical vulnerability in the Website itself, this incident illustrates how convincingly-designed fake login pages can compromise even well-defended corporate systems. Exposure of Social Security numbers alongside banking and routing information creates a heightened risk profile, since that combination of data can enable both direct financial fraud, through unauthorized account access, and longer-term identity theft, through new account or credit fraud using the stolen SSN.

When Did This Breach Occur?

The unauthorized access and fraudulent direct deposit changes occurred on or about February 23, 2026. HCA Healthcare removed external access to the affected Website on February 26, 2026. Affected individuals were notified on July 15, 2026, and the company notified the New Hampshire Attorney General’s Office on July 27, 2026.

What Information Was Breached?

HCA Healthcare’s investigation determined that the exposed information included employees’ first and last names, employee identification numbers, internal identification numbers, phone numbers, addresses, email addresses, Social Security numbers, and checking account and routing numbers. HCA Healthcare’s New Hampshire filing identified five New Hampshire residents affected by this incident; the total number of employees affected company-wide has not been publicly disclosed.

What You Can Do

HCA Healthcare is offering affected employees one year of complimentary identity theft prevention and credit monitoring services through IDX. If you received a notification letter from HCA Healthcare regarding this incident, consider taking the following steps:

  • Enroll in the complimentary IDX credit monitoring services by the deadline listed in your notification letter
  • Place a fraud alert or credit freeze with Equifax, Experian, and TransUnion
  • Monitor your bank accounts closely for unauthorized transactions
  • Request and review a free copy of your credit report from annualcreditreport.com
  • Report any suspected identity theft to the FTC and your state Attorney General

File a Data Breach Lawsuit Against HCA Healthcare

If your personal information was exposed in the HCA Healthcare data breach, you may have legal options available to you. Companies entrusted with sensitive employee and financial information are expected to maintain reasonable safeguards to protect that data, and victims of a breach may be entitled to compensation.

Contact us at Class Action U, where we’ll connect you with a lawyer skilled in class action lawsuits. If you’ve been contacted about this breach, received notice, or discovered you were impacted, fill out our quick, easy, and secure form to sign up. There is no cost to reach out to our legal partner and no obligation after speaking with someone from our team.

Were you recently affected by a data breach?
Other Data Breaches
Date of Breach: Underlying vendor incident occurred May 29 - June 1, 2026; New Era notified employees in 2026
Date of Breach: Incident occurred July 8, 2026; Oregon notification filed August 5, 2026
Date of Breach: Hacker group's claim of responsibility posted on or around August 5, 2026; not yet confirmed by the company
Related News

Frequently Asked Questions

A data breach occurs when sensitive, confidential, or protected information is accessed, stolen, or disclosed without authorization. Data breaches often occur through phishing emails, malware, weak passwords, insider threats, or unsecured databases. Indicators of a data breach can include unexpected password resets, suspicious account activity, unauthorized transactions, or notifications from companies about compromised information.If you suspect your data has been compromised, you must take measures and act quickly. Change passwords, enable two-factor authentication, review your financial accounts for unusual activity and consider freezing your credit.

Once stolen, your personal information may be sold on the dark web or used for identity theft and financial fraud. In some cases, hackers use the data to extort companies or launch further attacks. Victims often face long-term risks, including damage to credit and privacy.

If you receive a data breach notification, don’t ignore it. Immediately change passwords for the affected account and any others that share credentials. Enroll in any free credit monitoring services offered and monitor financial statements closely.

To pursue a data breach claim, you’ll need documentation showing your information was compromised and proof of resulting harm, such as fraudulent charges, credit score damage, or identity theft reports. Notification letters, financial records, and communication with the breached company can help support your claim.

Yes. If a company fails to protect consumer data or delays notifying victims, it may be held liable under state and federal privacy laws. Many victims join class action lawsuits to recover financial losses and hold negligent organizations accountable.

Data breach settlements vary widely depending on the size of the breach, type of data compromised, and damages suffered by victims. Payouts may include cash compensation, identity theft protection, or reimbursement for losses. Many settlements range from a few hundred to several thousand dollars per person. A skilled data breach lawyer can guide victims through the complex legal process, ensuring their rights are protected. If you’ve received a data breach notification or believe your personal data was exposed, you may be eligible for compensation. Contact Class Action U to learn more about how to join a data breach lawsuit and understand the process of filing.