TechNewsReel
Live

Novocure Data Breach Exposes Sensitive Info of 1,400+ Cancer Patients

The oncology medical device firm confirmed a mid-August cyberattack compromising patient and employee data.

TechNewsReel Newsroom · September 2, 2026

Oncology medical device company Novocure has confirmed a cyberattack that resulted in a data breach involving sensitive personal information. The incident has exposed the data of more than 1,400 U.S.-based cancer patients and an undisclosed number of company employees.

The breach occurred in mid-August 2024, according to company reports. While the full scope of the compromised data is still being managed, the company has begun the notification process for those affected. The attack targeted systems containing protected health information (PHI) and personal identifiers, leaving the firm to navigate the regulatory aftermath of the compromise.

The Vulnerability of Specialized MedTech

Novocure operates in a highly specialized niche of oncology, focusing on Tumor Treating Fields (TTFields) to treat various forms of cancer. Because the company handles deeply personal health records and patient diagnostics, it is subject to strict HIPAA regulations. These laws mandate rigorous data security standards and require timely notification to the Department of Health and Human Services (HHS) and affected individuals when a breach occurs.

Industry Implications

This incident underscores a growing trend of cyber threats targeting specialized medical technology firms. Unlike general healthcare providers, MedTech companies often hold a concentrated amount of high-value, specific patient data that is attractive to threat actors. For oncology patients, the exposure of such data is particularly sensitive, as it involves not only identity information but also critical health statuses and treatment histories.

Regulatory and Future Outlook

Novocure now faces the dual challenge of remediating its technical vulnerabilities and ensuring full compliance with federal breach notification laws. The company is currently managing the aftermath of the attack, though the specific method of entry used by the attackers has not been publicly disclosed. Industry observers will be watching for further details on whether the breach was the result of a third-party vendor compromise or a direct attack on Novocure's internal infrastructure.

Sources

Get a notification when a big story breaks. A few a day at most — no spam.