Scantitan Researches

Healthcare Data Breach Statistics 2026: 506 Breaches, 74.9M Affected & 804 in 2025

PUBLISHED
September 22, 2026
Researcher
Obaida Al-Sulaiman
Reviewed by
Security Research Team
Healthcare Data Breach Statistics
Table of Contents
Healthcare data breach statistics are unusually easy to misread. The U.S. Department of Health and Human Services Office for Civil Rights (HHS OCR) operates a public breach portal for incidents involving unsecured protected health information, but entries can be added or amended after the original report. A breach submitted in one calendar year may also have occurred in an earlier year, and OCR measures individuals affected, not a universal count of medical records.A September 2026 OCR-derived dashboard identified 804 large-breach filings submitted during 2025, collectively listing approximately 140.6 million affected individuals. The same dataset contained 506 filings affecting 74,872,402 individuals through September 4, 2026. Those figures should be read as dated regulatory-reporting snapshots rather than immutable final annual totals.The operational threat data tell a complementary story. Verizon’s 2026 Data Breach Investigations Report analyzed 1,492 healthcare security incidents, including 1,438 breaches with confirmed data disclosure. Vulnerability exploitation, phishing and credential abuse were important initial-access paths, while IBM’s 2026 breach-cost research put the average healthcare breach at $6.64 million, still the highest industry average in IBM’s study for the fifteenth consecutive year.

Healthcare Data Breach Statistics: Key Findings

The figures below deliberately keep their original populations and denominators. HHS OCR, Verizon and IBM do not measure the same thing.

Metric Latest Verified Figure Period / Scope Source Important Caveat
Large healthcare breach filings submitted to OCR 804 2025 submission-year snapshot HHS OCR-derived dashboard Submission year is not necessarily incident year.
Individuals listed as affected 140,574,754 2025 OCR filings, Sep. 4 snapshot HHS OCR-derived dashboard Individuals, not records; entries can be amended.
2026 large-breach filings 506 Through Sep. 4, 2026 HHS OCR-derived dashboard Partial year; totals can change as OCR updates reports.
Individuals affected in 2026 snapshot 74,872,402 Through Sep. 4, 2026 HHS OCR-derived dashboard YTD figure, not a full-year comparator.
Hacking/IT filings 651 / 81% 2025 OCR register OCR-derived register OCR breach classification, not an attack-vector taxonomy.
Healthcare provider filings 604 / 75% 2025 OCR-derived register Reporting-entity type, not necessarily breach origin.
Business associate filings 139 / 17% 2025 OCR-derived register A single business-associate event may affect many covered entities.
Health plan filings 59 / 7% 2025 OCR-derived register Reporting classification.
Verizon healthcare incidents 1,492 2026 DBIR dataset Verizon DBIR Contributed incident corpus, not a HIPAA census.
Verizon confirmed healthcare breaches 1,438 2026 DBIR dataset Verizon DBIR Different population from OCR.
Vulnerability exploitation as initial access 20% Verizon healthcare breaches Verizon DBIR DBIR healthcare corpus only.
Phishing as initial access 14% Verizon healthcare breaches Verizon DBIR DBIR healthcare corpus only.
Credential abuse as initial access 11% Verizon healthcare breaches Verizon DBIR DBIR healthcare corpus only.
Third-party involvement 32% Verizon healthcare breaches Verizon DBIR Not equivalent to OCR’s business-associate classification.
Financial motive 99% Verizon healthcare breaches Verizon DBIR Verizon dataset only.
Average healthcare breach cost $6.64M IBM 2026 study IBM Study average, not the cost of every breach.
Change Healthcare affected population ~192.7M Updated Jul. 31, 2025 HHS OCR Approximately affected individuals.
OCR ransomware enforcement actions 21 Through Jul. 29, 2026 HHS OCR Enforcement actions are not ransomware attack counts.

How to read these statisticsA breach, security incident, affected individual, record, OCR filing and victim notice are not interchangeable units. The denominator and reporting period matter as much as the headline figure.

What Counts as a Healthcare Data Breach?

Under the HIPAA Breach Notification Rule, covered entities must provide notification following breaches of unsecured protected health information. Business associates also have notification obligations when a breach occurs at or by the business associate. HHS explains the notification framework for affected individuals, the media and the Secretary.

For public statistical analysis, the most visible HHS dataset is the OCR list of breaches affecting 500 or more individuals. The portal includes fields such as the covered entity, state, entity type, individuals affected, breach submission date, breach type, location of breached information and whether a business associate was present.

What the OCR Breach Portal Measures

The OCR portal is one of the strongest datasets for studying U.S. healthcare breach reporting, but it is not a census of every healthcare cybersecurity incident. It records regulatory breach reports submitted under HIPAA requirements, and the values can change as investigations progress.

For breaches affecting at least 500 individuals, HHS requires notification without unreasonable delay and no later than 60 calendar days after discovery. If an organization does not yet know the final affected population, HHS permits an estimate and requires the report to be supplemented when additional information becomes available.

Affected Individuals Are Not the Same as Records Exposed

OCR frames its reporting threshold around the number of individuals affected. An OCR aggregate of 140.5 million should therefore be described as approximately 140.5 million affected individuals listed across the relevant breach filings.

It should not automatically become “140.5 million medical records stolen.” A patient may have multiple medical, billing or insurance records. Annual aggregates also do not necessarily represent the same number of unique Americans because an individual could theoretically appear in more than one unrelated breach.

Measurement ruleFor OCR statistics, this report uses affected individuals rather than substituting the word “records.” Where another source genuinely measures records, that unit should be retained separately.

Healthcare Data Breaches by Year

Healthcare Data Breaches by Year

OCR began publishing summaries of large healthcare breaches in October 2009. The current OCR-derived historical series shows how reported large breaches have expanded from fewer than 20 filings in the partial first year to hundreds of filings annually.

Submission Year Large-Breach Filings Individuals Listed as Affected
2009 18 134,773
2010 199 5,932,276
2011 200 13,162,158
2012 218 2,854,525
2013 277 7,018,839
2014 314 19,073,551
2015 270 112,466,720
2016 328 16,711,004
2017 358 5,314,987
2018 369 15,256,235
2019 511 44,969,724
2020 663 35,321,223
2021 715 61,206,238
2022 718 64,053,662
2023 746 183,266,304
2024 741 290,054,222
2025 804 140,574,754

Source: HHS OCR Breach Portal data compiled by HealthcareBreaches.com, current through September 4, 2026. These figures are organized by submission year, not necessarily by the year in which each incident occurred.

Individuals Listed as Affected

Why OCR-derived totals can differ between datasetsTwo OCR-derived September 2026 snapshots both contain 804 filings for 2025 but differ slightly in the summed affected population: HealthcareBreaches.com reports 140,574,754, while another OCR-derived register reports 140,514,189. The difference is 60,565 affected individuals. This illustrates why breach research should preserve the retrieval date and source rather than treating a portal aggregate as permanently fixed.

Submission Year and Occurrence Year Are Different Measurements

HHS’s 2024 Annual Report to Congress recorded 663 large breaches that occurred or ended during 2024, affecting approximately 242.9 million individuals. OCR nevertheless received 742 large-breach reports through the web portal during calendar 2024 because some submitted reports related to incidents from other periods.

  • Reports received during a calendar year measure regulatory submissions.
  • Breaches occurring or ending during a calendar year measure incident timing.
  • The live register can change when entries are added or amended.

For that reason, this research uses explicit descriptions such as “filings submitted in 2025” rather than presenting every portal-derived total as breaches that occurred in 2025.

Breaches Affecting Fewer Than 500 Individuals Are Mostly Missing From the Public Wall

The public OCR breach portal focuses on incidents affecting 500 or more individuals, but HIPAA reporting does not stop at that threshold. HHS’s 2024 Report to Congress says OCR received 74,299 reports of breaches affecting fewer than 500 individuals that occurred or ended in 2024. Together, those smaller incidents affected 340,618 individuals.

HHS says unauthorized access or disclosure was the most frequently reported category among those smaller breaches. The scale difference is important: the public 500+ dataset is useful for analyzing large incidents, but it does not represent the full number of HIPAA breach reports received by OCR.

The Median 2025 Large Breach Affected 4,824 Individuals

The 2025 OCR-derived register has a median filing size of 4,824 affected individuals. That median is far below the year’s overall average because a small number of mega-breaches — especially Conduent’s 62.2 million-person filing — pull the aggregate sharply upward.

This is why annual totals alone can give a misleading impression of a “typical” healthcare breach. The distribution contains hundreds of incidents affecting thousands of people alongside a small number affecting millions.

Why 2024 Was Such an Extreme Year

The Change Healthcare incident dominated the 2024 affected-person total. HHS says Change Healthcare eventually informed OCR that approximately 192.7 million individuals had been impacted.

That one breach represented most of the roughly 242.9 million affected individuals in HHS’s occurrence-year 2024 report. This illustrates why event frequency and human impact can move differently.

A year with fewer breach events can produce a much larger affected population when one or two highly concentrated service providers are compromised.

Why 2025 Had More Filings but Fewer Affected Individuals

The September 4, 2026 snapshot contains 804 filings submitted in 2025, above the 741 filings listed for 2024, yet the affected-person total fell to approximately 140.6 million.

That does not demonstrate that healthcare became safe in 2025. It mainly shows that the year’s filings did not contain another incident on the scale of Change Healthcare. Conduent alone accounts for more than 62 million affected individuals in the 2025 register, while Aflac, Episource and several large healthcare systems added millions more.

2026 Healthcare Data Breaches So Far

An HHS OCR-derived dashboard current through September 4, 2026 contained 506 large-breach filings affecting 74,872,402 individuals. The most recently listed reports in that snapshot were submitted on September 4.

Because OCR reports can be added or amended after the initial submission, this figure should be treated as a dated YTD snapshot rather than a final 2026 total.

Partial-year cautionThe 2026 YTD total should not be compared directly with full-year 2025 as evidence of an increase or decrease. Equivalent-period comparisons are required before drawing a directional conclusion.

What Causes Healthcare Data Breaches?

What Causes Healthcare Data Breaches

The answer depends on which dataset is being used. OCR classifies regulatory breach reports into broad categories such as Hacking/IT Incident and Unauthorized Access/Disclosure. Verizon analyzes a cybersecurity corpus using the VERIS framework and can describe initial access vectors, actors, motives and incident patterns in more detail.

Patient portals and third-party web applications appear repeatedly in this data, which makes a recurring website security scan a straightforward HIPAA security-rule control.

Those classifications should complement one another rather than be merged.

Hacking and IT Incidents Dominate OCR Filings

In the current 2025 register:

  • 651 filings, or 81%, were classified as Hacking/IT Incident;
  • 141, or 18%, as Unauthorized Access/Disclosure;
  • nine as Theft;
  • two as Loss; and
  • one as Improper Disposal.

“Hacking/IT Incident,” however, is a broad regulatory category. It should not be translated into “ransomware” without incident-level evidence.

Verizon Shows How Attackers Get In

Verizon’s 2026 healthcare analysis covers 1,492 incidents and 1,438 breaches with confirmed data disclosure. The top three healthcare patterns — System Intrusion, Miscellaneous Errors and Social Engineering — collectively represented 81% of breaches in its dataset.

For initial access, Verizon reported:

  • 20% vulnerability exploitation;
  • 14% phishing; and
  • 11% credential abuse.

These values come from Verizon’s healthcare corpus, not the OCR breach portal. For broader exploitation trends, see ScanTitan’s vulnerability statistics, while broader social-engineering trends are covered in our phishing statistics research.

Human Error Has Not Disappeared

Verizon found a 54% human element in healthcare breaches and described Miscellaneous Errors as a persistent healthcare pattern. Its leading error types included misdelivery, loss and misconfiguration.

Healthcare breach analysis therefore needs to account for both malicious intrusion and non-malicious exposure, including:

  • misdelivery;
  • incorrect access;
  • unsafe data flows;
  • exposed storage;
  • tracking or analytics misconfiguration; and
  • loss of unencrypted devices or media.

Where Breached Healthcare Information Was Located in 2025

The OCR-derived 2025 register also records the location of breached information. Because a filing can list more than one location, these categories are multi-valued and the shares can sum to more than 100%.

Location of Breached Information 2025 Filings Share of 804 Filings
Network Server 512 64%
Email 194 24%
Paper/Films 42 5%
Electronic Medical Record 36 4%
Other 18 2%
Laptop 11 1%
Desktop Computer 10 1%
Other Portable Electronic Device 6 1%

Network servers were therefore recorded far more often than any other location in the 2025 submission-year dataset. That does not mean 64% of all healthcare cyberattacks globally involve network servers; it describes the location field on these OCR filings.

HHS OCR vs Verizon DBIR vs IBM: Why the Numbers Differ

Three of the strongest healthcare breach sources answer three different questions.

Dataset What It Measures Population Best Use Do Not Treat It As
HHS OCR Breach Portal HIPAA breach reports U.S. HIPAA-regulated entities and reportable breaches Regulatory volume, affected individuals and breach classification Every healthcare cyberattack
Verizon DBIR Security incidents and confirmed breaches contributed to Verizon’s research corpus Multisource cybersecurity incident dataset Attack patterns, actors, access vectors and third parties A U.S. healthcare breach census
IBM Cost of a Data Breach Economic consequences of breached organizations in IBM/Ponemon’s study Sample of organizations that experienced breaches Cost benchmarking Number of healthcare breach events

Verizon’s 2026 report says its broader dataset covers tens of thousands of security incidents and more than 22,000 confirmed breaches from organizations in 145 countries, contributed by sources including forensic firms, law enforcement, cyber insurers and other organizations.

HHS, by contrast, is operating a statutory U.S. health-information reporting system. IBM is measuring breach economics.

Do not combine these denominatorsAdding OCR, Verizon and other incident counts together would not produce a meaningful healthcare breach total because the datasets measure different populations using different collection methods.

Which Healthcare Organizations Report the Most Breaches?

Third-Party Healthcare Data Breaches

Healthcare providers represent most OCR filings by count.

Reporting Entity Type 2025 Filings Share
Healthcare providers 604 75%
Business associates 139 17%
Health plans 59 7%
Healthcare clearinghouses 2 <1%

The reporting-entity distribution is only one way to measure third-party exposure. In the same 2025 register, 282 of 804 filings recorded a business associate as present. That is approximately 35.1% of filings, compared with only 139 filings — 17% — where the reporting entity itself was classified as a Business Associate.

Business-Associate Metric 2025 Filings Share What It Means
Reporting entity classified as Business Associate 139 17% The filer itself is categorized as a business associate.
Business associate present 282 35.1% A business associate is recorded as involved, regardless of who submitted the filing.

The 35.1% value is a ScanTitan calculation from 282 business-associate-present filings divided by 804 total 2025 filings. The two metrics should not be substituted for one another.

Reporting Entity Does Not Always Equal Breach Origin

HIPAA allows notification responsibilities to be delegated in some business-associate situations. HHS explains that notification responsibilities can be performed on behalf of affected covered entities when delegation is appropriate.

Consequently, the statement “75% of 2025 filings were classified as healthcare providers” is supportable from the OCR dataset.

The broader statement “75% of healthcare breaches originated inside provider systems” is not necessarily supportable from those filing categories alone.

Third-Party Healthcare Data Breaches

Third parties matter disproportionately because a single service provider can sit between many healthcare organizations and millions of patients.

Verizon found third-party involvement in 32% of healthcare breaches in its 2026 dataset. OCR’s business-associate classification measures something different, but the largest incidents show the same concentration problem operationally.

Change Healthcare processes healthcare transactions across a large network of payers and providers. Conduent provides business-processing services. Episource works with health plans and providers.

Compromise of one such organization can therefore propagate exposure across many customers.

Concentration riskThe security problem is not simply that “vendors get breached.” Organizations that aggregate claims, eligibility, billing, analytics or other healthcare information can create exceptionally large breach populations when compromised.

Healthcare Ransomware and System Intrusion Statistics

Ransomware remains important, but OCR’s Hacking/IT totals should not be renamed “ransomware statistics.” A ransomware attack may be reported under the broader Hacking/IT Incident category, but not every Hacking/IT filing is ransomware.

Verizon describes ransomware-driven System Intrusions as a major healthcare pattern in its 2026 analysis, alongside social engineering and recurring error-related breaches.

OCR Ransomware Enforcement

On July 29, 2026, OCR announced a settlement with OSF Healthcare System and identified it as the agency’s 21st ransomware enforcement action. OCR’s announcement emphasized the requirement for an accurate and thorough HIPAA risk analysis.

This enforcement count should not be interpreted as the number of healthcare ransomware attacks. It measures OCR enforcement actions in its ransomware series.

Healthcare Data Breach Costs

Healthcare Data Breach Costs

Healthcare remains the most expensive industry in IBM’s current breach-cost research.

IBM’s 2026 report puts the average healthcare breach cost at $6.64 million and says healthcare held the highest industry average for the 15th consecutive year.

Healthcare Breach Costs Have Declined for Two Consecutive IBM Studies

Because the figures below come from the same IBM report family, they can be compared more safely than unrelated vendor cost estimates.

IBM Study Year Average Healthcare Breach Cost
2024 $9.77M
2025 $7.42M
2026 $6.64M

IBM reported $9.77 million in 2024. Its 2025 study then reported $7.42 million before the current 2026 benchmark fell to $6.64 million.

The decline should not be interpreted as evidence that healthcare breaches are inexpensive. Healthcare still has the highest sector average in IBM’s current study.

IBM groups breach costs into categories including detection and escalation, lost business, post-breach response and notification. In its 2026 analysis, detection/escalation and lost business together accounted for a majority of total costs.

For broader cross-industry context, see ScanTitan’s Data Breach Statistics research.

10 Largest Healthcare Data Breaches Reported to HHS OCR

The table below is an all-time ranking by the number of affected individuals currently listed in the HHS OCR-derived dataset. It uses the reporting date rather than assuming that the report year is the same as the incident year.

Rank Organization Individuals Affected Date Reported Breach Type
1 Change Healthcare, Inc. 192,700,000 Jul. 19, 2024 Hacking/IT Incident
2 Anthem Inc. 78,800,000 Feb. 13, 2015 Hacking/IT Incident
3 Conduent Business Services LLC 62,224,658 Oct. 8, 2025 Hacking/IT Incident
4 DentaQuest, LLC 15,000,000 Jul. 16, 2026 Hacking/IT Incident
5 Welltok, Inc. 14,782,887 Nov. 6, 2023 Hacking/IT Incident
6 Aflac Incorporated 13,924,906 Aug. 8, 2025 Hacking/IT Incident
7 Kaiser Foundation Health Plan, Inc. 13,400,000 Apr. 12, 2024 Unauthorized Access/Disclosure
8 Optum360, LLC 11,500,000 Jul. 1, 2019 Hacking/IT Incident
9 HCA Healthcare 11,270,000 Jul. 31, 2023 Hacking/IT Incident
10 Premera Blue Cross 11,000,000 Mar. 17, 2015 Hacking/IT Incident

Source: HealthcareBreaches.com, based on HHS OCR breach data current through September 4, 2026. The affected-person counts remain subject to revision when organizations or regulators update an incident.

The ranking also demonstrates why a “largest breach” table should not be used as a proxy for the most common healthcare breach. The median 2025 large-breach filing affected only 4,824 individuals, while the largest incidents affected tens or hundreds of millions.

10 Largest Healthcare Data Breaches Reported to HHS OCR

Why Healthcare Breach Counts Change After Publication

The healthcare breach ecosystem contains several kinds of revision.

Initial Counts May Be Estimates

HHS explicitly instructs covered entities to provide an estimate when the number affected is uncertain and to submit updated information later. That means early breach rankings can change materially.

Change Healthcare’s Count Was Revised as the Investigation Progressed

HHS says Change Healthcare notified OCR on October 22, 2024 that about 100 million individual notices had been sent.

On January 24, 2025, it reported approximately 190 million individuals impacted.

On July 31, 2025, the affected population was updated again to approximately 192.7 million.

A research page that retained the earlier number after these later updates would now be stale.

Aflac Has Two Different but Valid Populations

Aflac identified unauthorized access to its U.S. network on June 12, 2025. Its SEC filing said the potentially affected material included claims information, health information, Social Security numbers and other personal information associated with its U.S. business.

By December 2025, Aflac had determined that personal information associated with approximately 22.65 million individuals was involved.

The HIPAA/OCR healthcare filing, however, lists approximately 13.9 million affected individuals.

Those figures should not be forced into one number because they describe different reporting populations.

Different Regulators Can Publish Different Counts

The current OCR-derived register lists 62,224,658 affected individuals for Conduent Business Services, while a later state-regulator submission has reported a slightly different aggregate.

The defensible research approach is not to average the values. For an OCR-based comparison table, the OCR figure should remain the comparable value while the existence of a later regulator figure is disclosed separately.

Major Healthcare Data Breach Case Studies

Change Healthcare: Concentration Risk at National Scale

UnitedHealth disclosed unauthorized access to Change Healthcare systems in February 2024. The incident disrupted healthcare transactions nationally and ultimately produced an HHS estimate of approximately 192.7 million affected individuals.

The important statistical lesson is not only that the breach was large. Change Healthcare demonstrates how dependence on highly connected healthcare intermediaries can make one incident dominate an entire year’s affected-person statistics.

Without understanding that concentration, 2024’s healthcare breach total can look like a uniform sector-wide increase rather than a distribution heavily influenced by one exceptional event.

Conduent: One Event, Different Regulator Totals

The current OCR-derived register lists 62,224,658 affected individuals for Conduent Business Services, making it one of the largest healthcare-related breach filings in the current dataset.

Other regulator reporting has produced a slightly different total. The correct research response is not to average the counts or silently select the larger number. For an OCR-based healthcare table, the OCR figure should remain the comparable value while any later regulator count is explained separately.

Aflac: Scope Matters More Than Headline Size

Aflac’s SEC disclosure eventually identified about 22.65 million people whose personal information was involved in its U.S. incident. Its HIPAA/OCR population is narrower.

This is a useful example of why people affected by the broader cyber incident and individuals included in the HIPAA breach report can be different populations.

It also corrects another common error: Aflac specifically stated that its systems were not affected by ransomware.

Blue Shield of California: A Major Breach Without Ransomware

Blue Shield disclosed that Google Analytics had been configured in a way that allowed certain member information to be shared with Google Ads between April 2021 and January 2024. Blue Shield said it discovered the issue on February 11, 2025 and that no bad actor was involved.

The potentially affected information included insurance-plan information, location data, member account identifiers and certain medical-claim-related details.

This case demonstrates that a large healthcare breach can result from data-flow and tracking configuration, not malware, ransomware or network intrusion.

HIPAA Breach Reporting and Enforcement

For breaches affecting 500 or more individuals, covered entities must notify HHS without unreasonable delay and no later than 60 calendar days after discovery. Breaches involving fewer than 500 individuals are subject to annual reporting requirements.

A business associate can report on behalf of a covered entity in appropriate circumstances, and HHS allows certain notification responsibilities to be delegated.

A Breach Does Not Automatically Mean a HIPAA Penalty

OCR enforcement focuses on compliance with the HIPAA Privacy, Security and Breach Notification Rules, not simply on whether a cyberattack occurred.

For example, in announcing its 21st ransomware enforcement action in July 2026, OCR specifically emphasized the importance and legal requirement of conducting an accurate and thorough risk analysis.

A breach may prompt an investigation, but the existence of a breach by itself should not be presented as proof of a HIPAA violation or an inevitable financial penalty.

Five Healthcare Data Breach Statistics Myths

Myth 1: “Healthcare Breaches Increase Every Year”

Not necessarily. Different metrics can move in different directions.

The number of OCR filings may rise while the total number of affected individuals falls because one year contains a mega-breach and another does not. The current 2025 register contains more filings than the current 2024 register, yet substantially fewer affected individuals.

Myth 2: “140 Million Affected Individuals Means 140 Million Medical Records”

No. OCR reports the approximate number of individuals affected. That is not a medical-record count.

One person can have many records, and annual aggregates can potentially include the same individual in multiple unrelated incidents.

Myth 3: “Most Healthcare Breaches Happen at Hospitals”

OCR’s largest reporting category is healthcare providers, but “healthcare provider” includes more than hospitals.

More importantly, reporting entity does not necessarily identify the technical origin of every breach. Large business-associate compromises can affect enormous populations across multiple downstream organizations.

Myth 4: “Large Healthcare Breaches Are Basically Ransomware Attacks”

Ransomware is important, but not every large breach involves ransomware.

Aflac said its 2025 systems were not affected by ransomware, while Blue Shield’s disclosure resulted from website analytics and tracking configuration rather than a malicious network intrusion.

Myth 5: “Once OCR Publishes a Number, It Is Final”

HHS permits estimated initial affected-person counts and subsequent updates when new information becomes available.

Change Healthcare is the clearest example: its known affected population was revised as investigation and notification progressed.

What the Data Means for Healthcare Security Teams

The strongest lesson from the current evidence is not that healthcare organizations need one specific security tool. The threat surface is broader.

Third-Party Concentration Needs Its Own Risk Model

A vendor handling information for dozens or hundreds of healthcare organizations can create much greater systemic exposure than its own organization size suggests.

The 32% third-party figure in Verizon’s healthcare corpus and the scale of Change Healthcare and Conduent make vendor dependencies a core security issue, not merely a procurement concern.

Vulnerability Management Remains Operationally Important

Verizon identified vulnerability exploitation as the leading listed initial-access vector in 20% of its healthcare breaches, ahead of phishing and credential abuse in that dataset.

Healthcare organizations therefore need to understand externally exposed applications, network services and software dependencies rather than focusing exclusively on employee phishing training.

The ScanTitan website vulnerability scanner can support this layer by helping identify certain known and externally observable weaknesses. Automated scanning, however, does not detect every attack path and does not replace penetration testing, identity controls, endpoint security, monitoring or incident response.

Identity and Social Engineering Still Matter

Phishing accounted for 14% and credential abuse 11% of the initial-access vectors identified in Verizon’s healthcare analysis.

That supports layered controls around authentication, phishing resistance, credential protection and access monitoring.

Error Prevention Still Deserves Investment

Healthcare’s persistent Miscellaneous Errors pattern means security programs also need controls against misdelivery, incorrect access, unsafe data flows, exposed storage, tracking misconfiguration and loss of unencrypted devices or media.

Not every meaningful healthcare breach begins with an attacker.

Methodology

This research prioritizes primary regulators, official company disclosures and original industry research. Secondary datasets are used where they provide a reproducible view of OCR data or help explain current portal snapshots.

HHS OCR Breach Data

The HHS OCR Breach Portal is the central U.S. regulatory source for HIPAA breaches of unsecured PHI affecting 500 or more individuals.

Because the public register is mutable, annual portal totals in this article are treated as dated snapshots rather than permanent historical facts.

The main annual series and 2026 YTD benchmark use an OCR-derived dataset current through September 4, 2026. It lists 804 filings and 140,574,754 affected individuals for 2025, and 506 filings affecting 74,872,402 individuals in 2026 through September 4.

A separate OCR-derived analytical register reports the same 804 filings for 2025 but a slightly different affected-person sum of 140,514,189. This report preserves the discrepancy rather than averaging the two values.

Occurrence-Year Data

Where occurrence-year reporting is required, HHS’s annual Report to Congress takes precedence.

The latest available report covers 2024 and identifies 663 large breaches occurring during that calendar year, affecting approximately 242.9 million individuals.

No equivalent finalized HHS occurrence-year report for 2025 was available at the time of this research.

Verizon DBIR

Verizon’s 2026 DBIR uses contributed incident data normalized through the VERIS framework. Its healthcare section covers 1,492 incidents and 1,438 confirmed breaches.

These observations are used for attack patterns, actor characteristics and vectors — not for calculating a national HIPAA breach total.

IBM Cost of a Data Breach

IBM’s Cost of a Data Breach research is used for financial benchmarking. The $6.64 million healthcare value is a study average, not a forecast or a universal cost assigned to every healthcare breach.

Research Limitations

  • OCR’s public 500+ list does not represent every small HIPAA breach.
  • Portal entries can be revised after initial submission.
  • Submission date and incident date are different concepts.
  • “Individuals affected” is not necessarily a unique-person or record count across an annual aggregate.
  • Healthcare security datasets use different populations and definitions.
  • OCR, Verizon and IBM should not be merged into one synthetic breach total.

Source Register

Organization Dataset / Document Period Primary Use in This Research Main Limitation
HHS OCR Breach Portal Live Filing counts, affected individuals, entity type and breach category Mutable register; submission date does not equal occurrence date
HHS OCR Annual Report to Congress on Breaches 2024 Occurrence-year regulatory benchmark Published with lag
HHS OCR Change Healthcare Cybersecurity FAQs Updated through 2025 Change Healthcare impact and notification revisions Incident-specific
HHS OCR Enforcement releases 2026 Ransomware enforcement actions Enforcement does not measure ransomware prevalence
Stern Security / HealthcareBreaches.com OCR-derived Healthcare Breaches Dashboard Current through Sep. 4, 2026 Historical annual series, 2026 YTD benchmark and all-time breach ranking Secondary compilation of HHS OCR data; snapshot can differ from other OCR-derived exports
DataBreachCost.com 2025 OCR-derived register analysis 2025 snapshot Median breach size, breach-location categories and business-associate involvement Secondary analytical compilation; preserve its snapshot date and derived metrics
Verizon 2026 Data Breach Investigations Report 2026 report cycle Healthcare attack patterns, vectors, actors and third-party involvement Contributed corpus, not a national census
IBM Cost of a Data Breach 2026 2026 Healthcare breach-cost benchmark Sample average
SEC / Aflac Company filings 2025–2026 Aflac incident population and ransomware status Broader company-incident scope differs from OCR HIPAA population
Blue Shield of California Official breach notice Apr. 2025 Tracking and analytics incident cause Company disclosure

Frequently Asked Questions

How many healthcare data breaches were reported in 2025?

A September 2026 HHS OCR-derived snapshot contains 804 large-breach filings submitted during 2025. Those filings list approximately 140.6 million affected individuals. Because OCR entries can be added or amended, the figure should be accompanied by its snapshot date rather than described as permanently final.

How many healthcare data breaches have happened in 2026?

A frozen snapshot through September 4, 2026 contained 506 large-breach filings affecting 74,872,402 individuals. OCR’s live portal already contains later submissions, so that number is intentionally a reproducible YTD cutoff rather than a live total.

How many people were affected by healthcare data breaches in 2025?

The current research snapshot lists 140,574,754 affected individuals across 2025 OCR filings in the September 4 snapshot. This should not be described as 140.5 million medical records or necessarily 140.5 million unique Americans.

What is the largest healthcare data breach?

The Change Healthcare cyberattack is the largest breach currently represented in HHS healthcare breach reporting. HHS says Change Healthcare ultimately reported approximately 192.7 million individuals impacted.

What causes most healthcare data breaches?

In the current 2025 OCR register, 81% of filings were categorized as Hacking/IT Incidents. Verizon’s separate healthcare cybersecurity dataset identifies vulnerability exploitation at 20%, phishing at 14% and credential abuse at 11% among initial-access vectors. These figures describe different datasets and should not be merged.

How much does a healthcare data breach cost?

IBM’s 2026 Cost of a Data Breach research puts the average healthcare breach at $6.64 million, the highest industry average in its study for the fifteenth consecutive year.

Are most healthcare data breaches caused by ransomware?

Ransomware is a major healthcare threat, but OCR’s broad Hacking/IT category should not be interpreted as a ransomware percentage. Verizon identifies System Intrusion as a major healthcare pattern, but errors, social engineering, phishing, credential abuse and other causes also contribute to healthcare breaches.

Why do different websites report different healthcare breach totals?

Different totals can result from different OCR retrieval dates, revised breach entries, submission year versus occurrence year, affected individuals being mislabeled as records, different company and HIPAA reporting populations, and the use of fundamentally different datasets such as OCR, Verizon or IBM. For healthcare breach research, the denominator and cutoff date are therefore as important as the headline number.

Want vulnerability scanning that prioritizes for you?

ScanTitan continuously matches your site against the CVE/NVD database, then ranks findings by real-world exploitability — so you patch what matters first.

o

Information Security Manager · Dubai, UAE · 12+ years InfoSec experience

Obaida specialises in web application security, vulnerability management, and external attack surface reduction for SMB and mid-market organisations. All ScanTitan content is reviewed against live scan findings before publication.

Share :

Facebook
LinkedIn

Continue reading