Skip to content

NextGen Healthcare

Disclosed Apr 27, 20233 years ago1,050,000 affectedConfirmed

Official notice

Stolen credentials used to access NextGen Office data of 1.05 million patients

Electronic health record vendor NextGen Healthcare said attackers used client credentials that appeared to have been stolen elsewhere to access its NextGen Office system between March 29 and April 14, 2023. Names, dates of birth, addresses and Social Security numbers of about 1.05 million patients were taken.

What is known

People affected1,050,000 (as reported by the organization)
DisclosedApr 27, 2023
DiscoveredMar 30, 2023
HappenedMar 29, 2023
AttackHacking
Data exposedNames, Dates of birth, Addresses, Social Security numbers
SectorHealthcare · US
StatusConfirmed

Sources

Source
California Attorney General breach notice: NextGen Healthcareoag.ca.gov · Official notice
Washington Attorney General breach notice: NextGen Healthcareatg.wa.gov · Official notice
Notice letter filed with the Delaware DOJ: NextGen Healthcareattorneygeneral.delaware.gov · Official notice
Oregon DOJ breach notice: NextGen Healthcarejustice.oregon.gov · Official notice
California AG data breach notice: NextGen Healthcare, Inc.oag.ca.gov · Regulator
NextGen Healthcare says hackers accessed personal data of more than 1 million patientstechcrunch.com · News
Vermont Attorney General: 2023-04-27 NextGen Healthcare Data Breach Notice to Consumersago.vermont.gov · Official notice
Indiana Attorney General 2023 data breach report: NextGen Healthcarein.gov · Official notice

Notices filed

WhereFiledPeople
Vermont AGresidents of VTApr 27, 2023
Delaware DOJresidents of DEApr 28, 20235,142
Indiana AGresidents of INApr 28, 202317,001
Washington AGresidents of WAMay 3, 202321,981
Oregon DOJresidents of ORMay 4, 20231,049,375
California AGresidents of CAMay 5, 2023
ResearchtotalMay 5, 20231,050,000
History of this record
  • 2026-09-25 · source: empty to https://www.in.gov/attorneygeneral/consumer-protection-division/id-theft-prevention/files/D-BYear-to-Date-Report-2023.pdf · backfill source
  • 2026-09-25 · disclosed: 2023-04-28 to 2023-04-27 · backfill source
  • 2026-09-25 · data_types: ["names"] to ["names","dob","addresses","ssn"] · seed source
  • 2026-09-25 · records_basis: empty to organization · seed source
  • 2026-09-25 · records: empty to 1050000 · seed source
  • 2026-09-25 · summary: empty to Electronic health record vendor NextGen Healthcare said attackers used client credentials that appeared to have been stolen elsewhere to access its NextGen Office system between March 29 and April 14, 2023. Names, dates of birth, addresses · seed source
  • 2026-09-25 · title: empty to Stolen credentials used to access NextGen Office data of 1.05 million patients · seed source
  • 2026-09-25 · data_types: [] to ["names"] · backfill source
  • 2026-09-25 · disclosed: 2023-05-03 to 2023-04-28 · backfill source
  • 2026-09-25 · attack: unknown to hacking · backfill source
  • 2026-09-25 · disclosed: 2023-05-05 to 2023-05-03 · backfill source
  • 2026-09-25 · discovered: empty to 2023-03-30 · backfill source
  • 2026-09-25 · added · backfill source

First seen 2026-09-25 (California AG), confirmed by California AG. Record counts are as reported. Not legal advice.

Everything about NextGen Healthcare

New breaches by email

Wednesdays, only in weeks with newly disclosed breaches, the largest first.

Double opt-in. Unsubscribe any time.