Novocure, a company that works in cancer treatment, has confirmed that a cybersecurity incident exposed information connected to more than 1,400 U.S. patient records. The unauthorized access was discovered in mid-August 2026 after someone gained access to some of the company’s information systems. Novocure said it immediately activated its cybersecurity response plan, took steps to contain the incident and started an internal investigation. The company also brought in independent cybersecurity experts to examine what happened and determine exactly what information was accessed during the incident.

According to Novocure’s investigation so far, the information exposed from more than 1,400 U.S. patient records consisted of internal company patient identification numbers. These identification numbers are used internally by Novocure and, importantly, the company said patient names and other identifying information were not exposed for those records. However, the investigation found that information belonging to fewer than 50 additional patients in the western United States was also accessed. Those records contained additional identifying information, making this smaller group different from the larger set of patient records.

The cybersecurity incident did not only involve patient-related information. Novocure said general contact information belonging to healthcare providers it works with was also exposed during the unauthorized access. General contact information relating to Novocure employees was affected as well, including details such as their job titles and phone numbers. The company has not disclosed the exact number of employees whose information was involved. Novocure continues to review the affected information as part of its investigation and is assessing the legal and regulatory requirements connected with the incident.

One important point from the company’s disclosure is that the attackers did not gain access to Novocure’s medical treatment devices. The company also said that its ability to operate has not been compromised and that all of its systems are currently fully functional. This means the cybersecurity incident has not affected the operation of its medical treatment devices or stopped the company from continuing its activities. Novocure said it is taking the privacy and security of its patients’ information seriously and continues to investigate the incident with the help of cybersecurity specialists.

Novocure is still reviewing the incident to determine all of its notification obligations under applicable laws and regulations. The company said it will make the required notifications based on the results of its investigation, including notifying affected patients when required. At this stage, Novocure has not publicly provided details about how the unauthorized party entered its systems or identified who was responsible for the incident. The investigation is therefore still ongoing, and additional information could become available as the company completes its review of the affected systems and data.

The incident comes as cyberattacks against healthcare and medical technology organizations continue to raise concerns because these companies handle sensitive information and support important medical services. Novocure said it does not currently expect the cybersecurity incident to have a material impact on its financial condition or results of operations. However, the company is continuing to gather information and evaluate the situation. For now, Novocure says its systems remain fully operational, its medical treatment devices were not accessed, and the company will continue taking the required steps to protect affected patients and address the breach.

Stay alert, and keep your security measures updated!

Source: Follow cybersecurity88 on X and LinkedIn for the latest cybersecurity news