Skip to content
Back to Blog
low severity June 21, 2024 · 3 min read

LivaNova USA, Inc. Data Breach Notice (Oregon Attorney General)

If you received a notice from LivaNova USA, Inc., here’s what the filing says was exposed, and what to do about it.

LivaNova USA, Inc. notified Oregon residents of a data breach in a filing reported to the Oregon Department of Justice on June 21, 2024. The filing puts the incident itself on October 26, 2023.

LivaNova USA, Inc. Data Breach Notice (Oregon Attorney General)

The data breach at LivaNova USA, Inc. means that personal information belonging to 129,219 people is now outside the company’s control. The incident occurred on October 26, 2023. The company filed its formal notification with the Oregon Department of Justice on June 21, 2024 — an interval of 239 days, or roughly eight months.

What the Exposed Personal Information Actually Enables

The filing lists only one broad category: personal information. No passwords, no financial account numbers, no Social Security numbers, and no government-issued identifiers were exposed. That absence is meaningful. It removes the most immediate routes to new account fraud and tax-related identity theft that dominate many other breaches.

However, the records still contain details that retain long-term value. Names combined with addresses, dates of birth, or medical-adjacent data can be used to refine existing identity profiles, support phishing campaigns that already have partial information about you, or strengthen social-engineering attempts that sound legitimate because they reference real past interactions with LivaNova or affiliated healthcare providers.

Because this information cannot be changed the way a credit card or password can, the exposure is permanent. What you can still control is how that information is used against you in the months and years ahead.

The Gap Between Incident and Notification

The 239-day period between the October 26, 2023 incident date and the June 21, 2024 filing is the single most striking fact in the record. Notification timelines vary by state law and by when an internal investigation concludes. The filing itself does not disclose when LivaNova discovered the incident or how long any unauthorized access may have lasted. What matters to you is the outcome: your personal information left the company’s systems in late 2023 and the public record of that fact arrived more than seven months later.

How to Determine Whether You Are One of the 129,219 People Affected

LivaNova USA, Inc. is required to notify affected individuals directly, usually by mail to the last known address on file. If you have not received a letter, it is likely that your records were not included. Anyone who has moved since October 26, 2023 should contact the company directly to confirm their status, because a letter sent to an outdated address may never have reached you.

What Remains in Your Control

Even without exposed credentials or financial data, vigilance still matters. The exposed personal information can make targeted fraud attempts more convincing. The following steps address the specific risks created by this incident:

  • Place a fraud alert with the three major credit bureaus. A fraud alert forces lenders to verify your identity before opening new accounts and lasts for one year. It is free and does not affect your credit score.
  • Review your Explanation of Benefits statements from any health insurer linked to LivaNova devices or services. Look for claims you did not incur. Medical identity theft often surfaces slowly through unexpected bills or denied claims.
  • Monitor your credit reports weekly for the next 12 months. Use the free weekly access now available at AnnualCreditReport.com. Look for accounts or inquiries you do not recognize.
  • Treat any unsolicited contact that references LivaNova, cardiac devices, or related medical procedures as suspicious. Call the company or your healthcare provider using a number you look up yourself rather than one provided in the message.
  • Consider freezing your credit if you do not anticipate needing new loans or lines of credit in the near future. A freeze is more restrictive than a fraud alert but offers stronger protection against new-account fraud.

The record contains no evidence that passwords or login credentials were involved. Therefore there is no need to change any password connected to LivaNova or its patient portals as a direct result of this breach. Focus instead on the permanent personal details that were exposed and the protective steps that limit what attackers can build from them.

Report details & sourcing

Severity Low contact details only, none of them permanent
Disclosed June 21, 2024
Last reviewed July 22, 2026
Affected 129219
Data exposed Personal information (per the breach notification)
Editorial & sourcing policy
GalaxyWarden is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data. Breach information is compiled from publicly accessible sources and threat-intelligence platforms, and is reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — see our content & takedown policy or write to support@galaxywarden.com.
Share this Post on X Reddit Email