Novocure Cyberattack Exposes Data of 1,400+ Cancer Patients and Employees
Global oncology company **Novocure** has disclosed a mid-August cyberattack that led to the exposure of data belonging to over 1,400 U.S. cancer patients and an undisclosed number of employees. While patient names were largely spared, the incident highlights persistent vulnerabilities within the healthcare sector.
A recent cyberattack on **Novocure**, a global oncology company renowned for its **Tumor Treating Fields (TTFields)** therapy, has resulted in a significant data breach. The incident, which occurred in mid-August, saw unauthorized access to some of the company's information systems.
### Patient and Employee Data Compromised
According to an investigation, the attackers accessed records for over 1,400 U.S. patients, including ID numbers. Crucially, **Novocure** states that these records did not contain patient names or other directly identifying information for this larger group. However, for a smaller subset of fewer than 50 patients in the western U.S., identifying information and general contact details for their healthcare providers were accessed.
The breach also impacted **Novocure** employees, exposing contact information such as job titles and phone numbers for an undisclosed number of individuals.
### Operational Integrity Maintained
**Novocure** has assured that its medical treatment devices were not compromised, and its operational capabilities remain unaffected. "Our ability to operate has not been compromised and all of our systems are fully functional," the company stated.
In a filing with the **U.S. Securities and Exchange Commission (SEC)**, **Novocure** emphasized its commitment to safeguarding patient data and is currently evaluating regulatory and legal notification requirements. The company will issue all necessary notifications to affected parties.
### Growing Trend in Healthcare Breaches
This incident is the latest in a troubling series of cyberattacks targeting healthcare organizations. In the past month alone:
* Healthcare software company **Unlimited Technology Systems** disclosed a breach impacting over 3.8 million individuals.
* Healthcare IT firm **CareCloud** reported a March data breach affecting more than 3.7 million patients.
* Hospital operator **Nutex Health** initiated an investigation into information theft from its servers.
* Pharmaceutical distribution giant **McKesson** revealed a cybersecurity incident after the **ShinyHunters** extortion group claimed to have stolen 284 million patient records.
The increasing frequency and scale of these attacks underscore the critical need for robust cybersecurity measures within the healthcare industry to protect sensitive patient and employee data.