LivaNova USA, Inc. Data Breach Notice (Oregon Attorney General): What Was Exposed & What To Do
LivaNova USA, Inc. disclosed a data breach on June 21, 2024 that occurred on October 26, 2023 and exposed the personal information of 129,219 individuals. Anyone who received notice from the company or who provided personal information to LivaNova should verify their status and consider protective steps such as monitoring accounts and placing a credit freeze.
In late 2023, personal information tied to more than 129,000 people associated with LivaNova USA, Inc. was exposed in a cybersecurity incident. For anyone who has received care involving LivaNova devices or services, or whose details appear in the company’s records, the practical question is straightforward: what was taken, how it might be misused, and what to do next. Public filings give a clear outline of timing and scale, even while many operational details remain limited.
LivaNova USA notified Oregon residents through a filing reported to the Oregon Department of Justice on June 21, 2024. That notice places the incident itself on October 26, 2023, and states that personal information was involved. The number of people affected is reported as 129,219. Beyond those points, public detail on method and exact data fields is limited, so affected individuals must weigh the known exposure carefully rather than assume every possible record type was confirmed.
What happened
According to the Oregon Attorney General breach notice, LivaNova USA, Inc. experienced a data incident dated October 26, 2023. The company later notified Oregon residents, with the filing recorded on June 21, 2024. The notice reports 129,219 people affected and describes the exposed material as personal information per the breach notification.
The public record does not describe how the intrusion occurred, whether systems were encrypted or exfiltrated, how long unauthorized access lasted, or which specific technical controls failed. No threat actor is named in the available facts. What is established is the incident date, the later regulatory reporting date in Oregon, the affected-person count, and the characterization of the data as personal information.
How a breach like this happens
Incidents that lead to notices like this typically begin with unauthorized access to corporate networks or cloud environments that store customer, patient-related, or employee records. Common entry paths in the wider industry include compromised credentials, phishing that yields remote access, unpatched remote services, or misuse of legitimate accounts. Once inside, an attacker may move laterally, locate databases or file shares, and copy data for later use or sale.
Organizations then investigate, determine what was accessed or taken, and issue notices when personal information meets legal thresholds. The gap between an incident date and a public filing—here, from late October 2023 to a June 2024 Oregon report—often reflects forensic work, legal review, and coordination with regulators. None of that general pattern assigns a specific method or group to this LivaNova matter; those details are simply not provided in the disclosure summarized here.
LivaNova USA, Inc. and its sector
LivaNova USA, Inc. is the U.S. arm of a medical technology company known for devices and therapies used in cardiac surgery, neuromodulation, and related clinical settings. Firms in this sector routinely hold identity data, contact details, and information linked to patients, clinicians, sales channels, or employees because devices, support, and regulatory follow-up require accurate records.
A breach at a medical-device company is consequential because the same identifiers used for care coordination or device tracking can also support identity fraud or targeted scams. Even when clinical treatment notes are not confirmed as exposed, the combination of name-level personal information and a healthcare-adjacent context raises the stakes for people who may already be dealing with medical bills, insurance, or device follow-up.
What data was at risk
The breach notification names the exposed material as personal information. It does not, in the facts available here, list individual fields such as Social Security numbers, dates of birth, medical record numbers, financial account data, or clinical details. Those specifics are unconfirmed in the public summary provided.
Organizations of this kind typically maintain names, addresses, phone numbers, email addresses, dates of birth, insurance or billing identifiers, and sometimes government ID numbers or employee data. Because the notice only confirms “personal information” at a high level, readers should treat any more granular inventory as unknown unless LivaNova or a regulator later publishes a fuller breakdown. The What's Publicly Reported stop at personal information affecting 129,219 people.
Why it matters
For affected individuals, personal information in the wrong hands can enable account takeover attempts, phishing that references a real medical-device relationship, tax or benefits fraud, and long-lived identity misuse. Even limited data can be combined with other leaked sets to build fuller profiles. The large reported count—129,219—means the exposure is not a narrow internal event; it reaches a substantial population that may include patients, caregivers, or others tied to LivaNova’s U.S. operations.
For the organization, the incident carries regulatory notification duties, potential follow-on inquiries, remediation costs, and reputational pressure in a sector where trust and data handling are closely watched. The multi-month span between the October 26, 2023 incident date and the June 21, 2024 Oregon filing also illustrates how long people may remain unaware before official notice arrives, which can delay protective steps.
Were you affected?
If you have a past or current relationship with LivaNova USA—through a device, clinic, support program, or employment—watch for an official notice by mail or other channel the company uses. Treat unexpected calls or emails that cite the breach and ask for passwords, payment, or remote access as suspicious. Consider placing a fraud alert or credit freeze with the major credit bureaus, monitoring financial and insurance statements, and documenting any suspicious activity. Change passwords on related accounts and enable multi-factor authentication where available.
You can also run a free exposure scan of your email address to check whether that address has already appeared in known breach datasets, which can help you prioritize further monitoring even when a company’s full data inventory remains only partly disclosed.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
Stiiizy Inc. Data Breach Notice (Oregon Attorney General)American Addiction Centers, Inc. Data Breach Notice (Oregon Attorney General)Norwex USA, Inc. Data Breach Notice (Oregon Attorney General)Oregon Reproductive Medicine, LLC Data Breach Notice (Oregon Attorney General)Latest breaches
Verified breach
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.