
City of Hope, a leading cancer treatment and research centre in California, said it experienced a data security incident that compromised the sensitive personal information of more than 800,000 individuals.
Located in Duarte, California, City of Hope is a non-profit clinical research centre, hospital and graduate school. The healthcare institute has been ranked as one of the nation’s best Cancer hospitals by the U.S. News & World Report for over ten years and is a founding member of the National Comprehensive Cancer Network.
In a recent filing with the Office of the Maine Attorney General and in a data security incident notice published on its website, City of Hope said that on October 13, it identified suspicious activities in certain parts of its internal system and launched an internal investigation, with assistance from third party cyber security experts, to understand the nature and scope of the incident.
The institute’s investigation revealed that threat actors “accessed a subset of our systems and obtained copies of some files between September 19, 2023, and October 12, 2023.” It said it implemented mitigation measures to minimise any disruption to its daily operations.
While the investigation is still ongoing, City of Hope has confirmed that the compromised data includes names, email addresses, phone numbers, dates of birth, social security numbers, driver’s license and other government identification numbers, financial details like bank account numbers and credit card details, health insurance information, medical records and information about medical history, associated conditions, and unique identifiers to associate individuals with City of Hope like medical record numbers.
City of Hope said in a filing with the state regulator that at least 827,149 individuals were impacted by the data security incident.
“Upon discovery of this incident, City of Hope immediately instituted mitigation measures. We then promptly implemented additional and enhanced safeguards and enlisted the support of a leading cybersecurity firm to enhance the security of our network, systems, and data.
“We also launched a comprehensive investigation, identified individuals affected, reported the incident to law enforcement, and notified regulatory bodies,” it said.
While the healthcare provider found no evidence of the compromised information being misused, it advised all affected individuals to regularly monitor their credit reports, account and benefit statements and report any suspicious activity to law enforcement authorities, including the police and state attorney general.
It has also offered two years of complimentary identity protection and credit monitoring services through Kroll to all the individuals affected by the breach.
Winston House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF
020 8349 4363
© 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543