The computers held names and security numbers of patients treated at HCA hospitals in Kansas, Colorado, Louisiana, Mississippi, Oklahoma, Oregon, Texas and Washington between 1996 and 2006. The records did not contain addresses or dates of birth.

HCA did not disclose the date or location of the attack, but said that those affected had been notified by letter. Ads have also been placed in the newspapers of affected states.

Authorities said the computers were stolen for hardware purposes, not for personal data. There is speculation that the theft was an inside job, due to the elaborate computer security which included a keypad lock and password protection.