Novocure said Tuesday that a cybersecurity incident in mid-August involving unauthorized access to certain information systems exposed internal records belonging to more than 1,400 U.S. patients. The oncology company said it activated its response plan, put containment measures in place, and opened an internal investigation.
The number is small compared with the health care breaches that made headlines this year. What makes it worth a patient's attention is the company it keeps. Over roughly the past three months, cyberattacks have hit device makers including Abbott, Stryker, Medtronic, and Boston Scientific, drugmaker Novo Nordisk, and drug delivery equipment supplier West Pharmaceutical Services.
One point is worth making early, because it shapes what people should actually do. In this incident, the exposed material was not a stack of medical charts.
The Records That Were Actually Exposed
According to the company's account, the information involved included internal Novocure patient identification numbers, general contact information for health care providers the company works with, and details about Novocure employees such as job titles and phone numbers.
There is an exception, and it matters. Novocure said data for fewer than 50 other patients in the western United States was also exposed, and that this data included additional identifying information. The company did not specify what that additional information consisted of.
For the larger group, this is a meaningfully different exposure from a breach that spills diagnoses, treatment histories, Social Security numbers, or insurance details. An internal patient ID number is a company's own reference code. On its own it is not the kind of identifier that opens a bank account. For the smaller western group, the picture is less clear, and those patients in particular should read their notification letters closely.
Novocure said access to its medical treatment devices was not obtained and that all its systems are fully functional. The company does not expect the incident to have a material impact on its financial results. It has not said who was responsible, how the intruders got in, or whether any data was copied rather than merely accessed.
A Summer of Breaches Across Medical Device Makers
The pattern behind this disclosure is the actual story. Health care organizations hold data that is both sensitive and, unlike a credit card number, impossible to reissue.
The scale elsewhere this year dwarfs the Novocure figure. Electronic health record vendor CareCloud confirmed to federal regulators that an intrusion into one of its cloud environments in March affected more than 3.75 million people, a figure revised up sharply from earlier estimates. Notification letters describe exposed data that varies by individual and can include names, dates of birth, Social Security numbers, government identification numbers, financial account and card numbers, and medical and health insurance information. That is the profile of a breach where a credit freeze is a reasonable response.
Drug distribution giant McKesson has confirmed an intrusion in which attackers broke into several of its cloud-hosted accounts and took data, with the company's chief technology officer saying the stolen data relates to its oncology and multispecialty and medical-surgical units. A hacking group has claimed it took millions of patient records. The intrusion is confirmed; the scale claimed by the attackers is not, and extortion groups have an incentive to inflate. Federal breach notification filings, which are legally required, are the more reliable record.
Pacemaker Monitoring Is the Sharper Patient Consequence
The incident from this run with the most direct effect on a person's body rather than their paperwork is not a data exposure at all.
Boston Scientific identified a cybersecurity incident on August 25 that disrupted its global operations. In a company update on the incident, it said there are no known impacts to implantable device function, and no impact on remote monitoring for devices that were already enrolled before the disruption.
The gap is for new implants. For cardiac rhythm management devices implanted since the outage began, new remote monitoring communicators cannot be activated, so device data will not transmit to remote patient management systems until activation is possible. New insertable cardiac monitors cannot pair with the patient's remote monitoring phone. Those devices still record heart rhythm episodes, and the data can be retrieved through an in-person check with the clinic app. In-office programmer interrogations are not affected.
Remote monitoring is how a cardiology team catches an arrhythmia or a lead problem between office visits. Losing it does not stop a pacemaker from pacing. It does mean a gap in surveillance for people who just received a device.
Anyone who received a new cardiac device since late August, or is scheduled for one, has a specific question for their cardiology team: whether remote monitoring is transmitting, and what in-person follow-up schedule applies until it is.
Steps That Matter and Steps That Do Not
For the Novocure patients specifically, the reasonable response is proportionate. Read the notification letter when it arrives, because it will state what was involved for your record. Be alert to unsolicited calls or emails referencing your treatment, since exposed contact information is what enables targeted phishing. Do not give information to anyone who calls claiming to be from the company.
A credit freeze is aimed at breaches involving Social Security numbers or financial data. Based on what Novocure has described for the larger group, that does not appear to be this one, though the notification letter is the authority for any individual record.
Medical identity theft, where someone uses another person's information to obtain care, shows up in explanation of benefits statements and billing records rather than credit reports. Reviewing those statements for services you did not receive is the health-specific version of checking your credit.
Nobody should delay or stop cancer treatment over a data breach. The company has said no device, therapy, or clinical service was affected.
What remains unknown is substantial. Novocure has not identified the attacker or the entry point, has not said whether data was taken rather than viewed, and has not published a notification timeline. Formal breach reporting to federal health regulators typically follows disclosure by weeks, and that filing will carry the authoritative affected-person count.
Key Questions Answered
What happened at Novocure? The company disclosed on September 1 that a mid-August cybersecurity incident involved unauthorized access to certain systems and exposed internal records for more than 1,400 U.S. patients.
Were medical records exposed? Not for the main group. The company said the information involved internal patient ID numbers, general provider contact information, and employee details. It also said fewer than 50 additional patients in the western United States had data exposed that included further identifying information.
Should I freeze my credit? That step is aimed at breaches involving Social Security numbers or financial data. The notification letter for your specific record is the authority on what was involved.
How would I know if my medical information were misused? Medical identity theft appears in explanation of benefits statements and billing records, not credit reports. Review those for services you did not receive.
Is my cancer treatment affected? Novocure said access to its medical treatment devices was not obtained and its systems are fully functional. Do not delay or stop treatment over a data breach.
Why are health care companies being targeted so often? Health data is sensitive and cannot be reissued the way a credit card can, which makes it valuable for extortion and fraud.
What about the Boston Scientific incident? That is a separate attack. Devices enrolled in remote monitoring before the outage are unaffected, but patients who received a new cardiac device since late August may have monitoring setup delayed and should ask their cardiology team about follow-up.