Novocure, a healthtech company focused on oncology, disclosed that a mid-August cyberattack exposed data tied to more than 1,400 U.S. cancer patients and an undisclosed number of employees, according to BleepingComputer. BleepingComputer reports that Novocure described the incident in a filing with the U.S. Securities and Exchange Commission. The company said it discovered unauthorized access to some of its information systems in mid-August and later determined that attackers had viewed patient and employee information. The largest affected group was more than 1,400 U.S. patient records containing ID numbers. According to BleepingComputer, Novocure said those records did not include patient names or other identifying data. A smaller set of patients was more directly exposed. For fewer than 50 patients in the western U.S., attackers accessed identifying information as well as general contact information for healthcare providers, BleepingComputer reports. Employee data was also involved. The breach exposed contact information for an undisclosed number of Novocure employees, including job titles and phone numbers, according to the report. Novocure said the incident did not extend to its medical treatment devices. BleepingComputer quotes the company as saying no access to those devices was obtained, its ability to operate was not compromised, and its systems are fully functional. The company said it is still evaluating regulatory and legal notification requirements and will make required notifications based on its findings, including to impacted patients. BleepingComputer said a Novocure spokesperson was not immediately available to answer questions about how attackers breached the network or whether the company had contact with them about a ransom. Novocure has more than 1,300 employees and operates across North America, Europe, the Middle East, and Asia, according to BleepingComputer. The company is known for commercializing Tumor Treating Fields, a non-invasive electromagnetic field therapy for cancer tumors. Who benefits: Patients and providers benefit if Novocure's statement holds that medical treatment devices were not accessed and systems remain functional. Security teams also get a clearer boundary between data exposure and operational compromise in this incident. Who's exposed: The exposed groups are more than 1,400 U.S. cancer patients whose records included ID numbers, fewer than 50 western U.S. patients whose identifying information was accessed, and an undisclosed number of Novocure employees whose contact details were exposed.