Healthcare Data Breach Statistics: Key Findings
The figures below deliberately keep their original populations and denominators. HHS OCR, Verizon and IBM do not measure the same thing.
| Metric | Latest Verified Figure | Period / Scope | Source | Important Caveat |
|---|---|---|---|---|
| Large healthcare breach filings submitted to OCR | 804 | 2025 submission-year snapshot | HHS OCR-derived dashboard | Submission year is not necessarily incident year. |
| Individuals listed as affected | 140,574,754 | 2025 OCR filings, Sep. 4 snapshot | HHS OCR-derived dashboard | Individuals, not records; entries can be amended. |
| 2026 large-breach filings | 506 | Through Sep. 4, 2026 | HHS OCR-derived dashboard | Partial year; totals can change as OCR updates reports. |
| Individuals affected in 2026 snapshot | 74,872,402 | Through Sep. 4, 2026 | HHS OCR-derived dashboard | YTD figure, not a full-year comparator. |
| Hacking/IT filings | 651 / 81% | 2025 OCR register | OCR-derived register | OCR breach classification, not an attack-vector taxonomy. |
| Healthcare provider filings | 604 / 75% | 2025 | OCR-derived register | Reporting-entity type, not necessarily breach origin. |
| Business associate filings | 139 / 17% | 2025 | OCR-derived register | A single business-associate event may affect many covered entities. |
| Health plan filings | 59 / 7% | 2025 | OCR-derived register | Reporting classification. |
| Verizon healthcare incidents | 1,492 | 2026 DBIR dataset | Verizon DBIR | Contributed incident corpus, not a HIPAA census. |
| Verizon confirmed healthcare breaches | 1,438 | 2026 DBIR dataset | Verizon DBIR | Different population from OCR. |
| Vulnerability exploitation as initial access | 20% | Verizon healthcare breaches | Verizon DBIR | DBIR healthcare corpus only. |
| Phishing as initial access | 14% | Verizon healthcare breaches | Verizon DBIR | DBIR healthcare corpus only. |
| Credential abuse as initial access | 11% | Verizon healthcare breaches | Verizon DBIR | DBIR healthcare corpus only. |
| Third-party involvement | 32% | Verizon healthcare breaches | Verizon DBIR | Not equivalent to OCR’s business-associate classification. |
| Financial motive | 99% | Verizon healthcare breaches | Verizon DBIR | Verizon dataset only. |
| Average healthcare breach cost | $6.64M | IBM 2026 study | IBM | Study average, not the cost of every breach. |
| Change Healthcare affected population | ~192.7M | Updated Jul. 31, 2025 | HHS OCR | Approximately affected individuals. |
| OCR ransomware enforcement actions | 21 | Through Jul. 29, 2026 | HHS OCR | Enforcement actions are not ransomware attack counts. |
How to read these statisticsA breach, security incident, affected individual, record, OCR filing and victim notice are not interchangeable units. The denominator and reporting period matter as much as the headline figure.
What Counts as a Healthcare Data Breach?
Under the HIPAA Breach Notification Rule, covered entities must provide notification following breaches of unsecured protected health information. Business associates also have notification obligations when a breach occurs at or by the business associate. HHS explains the notification framework for affected individuals, the media and the Secretary.
For public statistical analysis, the most visible HHS dataset is the OCR list of breaches affecting 500 or more individuals. The portal includes fields such as the covered entity, state, entity type, individuals affected, breach submission date, breach type, location of breached information and whether a business associate was present.
What the OCR Breach Portal Measures
The OCR portal is one of the strongest datasets for studying U.S. healthcare breach reporting, but it is not a census of every healthcare cybersecurity incident. It records regulatory breach reports submitted under HIPAA requirements, and the values can change as investigations progress.
For breaches affecting at least 500 individuals, HHS requires notification without unreasonable delay and no later than 60 calendar days after discovery. If an organization does not yet know the final affected population, HHS permits an estimate and requires the report to be supplemented when additional information becomes available.
Affected Individuals Are Not the Same as Records Exposed
OCR frames its reporting threshold around the number of individuals affected. An OCR aggregate of 140.5 million should therefore be described as approximately 140.5 million affected individuals listed across the relevant breach filings.
It should not automatically become “140.5 million medical records stolen.” A patient may have multiple medical, billing or insurance records. Annual aggregates also do not necessarily represent the same number of unique Americans because an individual could theoretically appear in more than one unrelated breach.
Measurement ruleFor OCR statistics, this report uses affected individuals rather than substituting the word “records.” Where another source genuinely measures records, that unit should be retained separately.
Healthcare Data Breaches by Year

OCR began publishing summaries of large healthcare breaches in October 2009. The current OCR-derived historical series shows how reported large breaches have expanded from fewer than 20 filings in the partial first year to hundreds of filings annually.
| Submission Year | Large-Breach Filings | Individuals Listed as Affected |
|---|---|---|
| 2009 | 18 | 134,773 |
| 2010 | 199 | 5,932,276 |
| 2011 | 200 | 13,162,158 |
| 2012 | 218 | 2,854,525 |
| 2013 | 277 | 7,018,839 |
| 2014 | 314 | 19,073,551 |
| 2015 | 270 | 112,466,720 |
| 2016 | 328 | 16,711,004 |
| 2017 | 358 | 5,314,987 |
| 2018 | 369 | 15,256,235 |
| 2019 | 511 | 44,969,724 |
| 2020 | 663 | 35,321,223 |
| 2021 | 715 | 61,206,238 |
| 2022 | 718 | 64,053,662 |
| 2023 | 746 | 183,266,304 |
| 2024 | 741 | 290,054,222 |
| 2025 | 804 | 140,574,754 |
Source: HHS OCR Breach Portal data compiled by HealthcareBreaches.com, current through September 4, 2026. These figures are organized by submission year, not necessarily by the year in which each incident occurred.

Why OCR-derived totals can differ between datasetsTwo OCR-derived September 2026 snapshots both contain 804 filings for 2025 but differ slightly in the summed affected population: HealthcareBreaches.com reports 140,574,754, while another OCR-derived register reports 140,514,189. The difference is 60,565 affected individuals. This illustrates why breach research should preserve the retrieval date and source rather than treating a portal aggregate as permanently fixed.
Submission Year and Occurrence Year Are Different Measurements
HHS’s 2024 Annual Report to Congress recorded 663 large breaches that occurred or ended during 2024, affecting approximately 242.9 million individuals. OCR nevertheless received 742 large-breach reports through the web portal during calendar 2024 because some submitted reports related to incidents from other periods.
- Reports received during a calendar year measure regulatory submissions.
- Breaches occurring or ending during a calendar year measure incident timing.
- The live register can change when entries are added or amended.
For that reason, this research uses explicit descriptions such as “filings submitted in 2025” rather than presenting every portal-derived total as breaches that occurred in 2025.
Breaches Affecting Fewer Than 500 Individuals Are Mostly Missing From the Public Wall
The public OCR breach portal focuses on incidents affecting 500 or more individuals, but HIPAA reporting does not stop at that threshold. HHS’s 2024 Report to Congress says OCR received 74,299 reports of breaches affecting fewer than 500 individuals that occurred or ended in 2024. Together, those smaller incidents affected 340,618 individuals.
HHS says unauthorized access or disclosure was the most frequently reported category among those smaller breaches. The scale difference is important: the public 500+ dataset is useful for analyzing large incidents, but it does not represent the full number of HIPAA breach reports received by OCR.
The Median 2025 Large Breach Affected 4,824 Individuals
The 2025 OCR-derived register has a median filing size of 4,824 affected individuals. That median is far below the year’s overall average because a small number of mega-breaches — especially Conduent’s 62.2 million-person filing — pull the aggregate sharply upward.
This is why annual totals alone can give a misleading impression of a “typical” healthcare breach. The distribution contains hundreds of incidents affecting thousands of people alongside a small number affecting millions.
Why 2024 Was Such an Extreme Year
The Change Healthcare incident dominated the 2024 affected-person total. HHS says Change Healthcare eventually informed OCR that approximately 192.7 million individuals had been impacted.
That one breach represented most of the roughly 242.9 million affected individuals in HHS’s occurrence-year 2024 report. This illustrates why event frequency and human impact can move differently.
A year with fewer breach events can produce a much larger affected population when one or two highly concentrated service providers are compromised.
Why 2025 Had More Filings but Fewer Affected Individuals
The September 4, 2026 snapshot contains 804 filings submitted in 2025, above the 741 filings listed for 2024, yet the affected-person total fell to approximately 140.6 million.
That does not demonstrate that healthcare became safe in 2025. It mainly shows that the year’s filings did not contain another incident on the scale of Change Healthcare. Conduent alone accounts for more than 62 million affected individuals in the 2025 register, while Aflac, Episource and several large healthcare systems added millions more.
2026 Healthcare Data Breaches So Far
An HHS OCR-derived dashboard current through September 4, 2026 contained 506 large-breach filings affecting 74,872,402 individuals. The most recently listed reports in that snapshot were submitted on September 4.
Because OCR reports can be added or amended after the initial submission, this figure should be treated as a dated YTD snapshot rather than a final 2026 total.
Partial-year cautionThe 2026 YTD total should not be compared directly with full-year 2025 as evidence of an increase or decrease. Equivalent-period comparisons are required before drawing a directional conclusion.
What Causes Healthcare Data Breaches?

The answer depends on which dataset is being used. OCR classifies regulatory breach reports into broad categories such as Hacking/IT Incident and Unauthorized Access/Disclosure. Verizon analyzes a cybersecurity corpus using the VERIS framework and can describe initial access vectors, actors, motives and incident patterns in more detail.
Patient portals and third-party web applications appear repeatedly in this data, which makes a recurring website security scan a straightforward HIPAA security-rule control.
Those classifications should complement one another rather than be merged.
Hacking and IT Incidents Dominate OCR Filings
In the current 2025 register:
- 651 filings, or 81%, were classified as Hacking/IT Incident;
- 141, or 18%, as Unauthorized Access/Disclosure;
- nine as Theft;
- two as Loss; and
- one as Improper Disposal.
“Hacking/IT Incident,” however, is a broad regulatory category. It should not be translated into “ransomware” without incident-level evidence.
Verizon Shows How Attackers Get In
Verizon’s 2026 healthcare analysis covers 1,492 incidents and 1,438 breaches with confirmed data disclosure. The top three healthcare patterns — System Intrusion, Miscellaneous Errors and Social Engineering — collectively represented 81% of breaches in its dataset.
For initial access, Verizon reported:
- 20% vulnerability exploitation;
- 14% phishing; and
- 11% credential abuse.
These values come from Verizon’s healthcare corpus, not the OCR breach portal. For broader exploitation trends, see ScanTitan’s vulnerability statistics, while broader social-engineering trends are covered in our phishing statistics research.
Human Error Has Not Disappeared
Verizon found a 54% human element in healthcare breaches and described Miscellaneous Errors as a persistent healthcare pattern. Its leading error types included misdelivery, loss and misconfiguration.
Healthcare breach analysis therefore needs to account for both malicious intrusion and non-malicious exposure, including:
- misdelivery;
- incorrect access;
- unsafe data flows;
- exposed storage;
- tracking or analytics misconfiguration; and
- loss of unencrypted devices or media.
Where Breached Healthcare Information Was Located in 2025
The OCR-derived 2025 register also records the location of breached information. Because a filing can list more than one location, these categories are multi-valued and the shares can sum to more than 100%.
| Location of Breached Information | 2025 Filings | Share of 804 Filings |
|---|---|---|
| Network Server | 512 | 64% |
| 194 | 24% | |
| Paper/Films | 42 | 5% |
| Electronic Medical Record | 36 | 4% |
| Other | 18 | 2% |
| Laptop | 11 | 1% |
| Desktop Computer | 10 | 1% |
| Other Portable Electronic Device | 6 | 1% |
Network servers were therefore recorded far more often than any other location in the 2025 submission-year dataset. That does not mean 64% of all healthcare cyberattacks globally involve network servers; it describes the location field on these OCR filings.
HHS OCR vs Verizon DBIR vs IBM: Why the Numbers Differ
Three of the strongest healthcare breach sources answer three different questions.
| Dataset | What It Measures | Population | Best Use | Do Not Treat It As |
|---|---|---|---|---|
| HHS OCR Breach Portal | HIPAA breach reports | U.S. HIPAA-regulated entities and reportable breaches | Regulatory volume, affected individuals and breach classification | Every healthcare cyberattack |
| Verizon DBIR | Security incidents and confirmed breaches contributed to Verizon’s research corpus | Multisource cybersecurity incident dataset | Attack patterns, actors, access vectors and third parties | A U.S. healthcare breach census |
| IBM Cost of a Data Breach | Economic consequences of breached organizations in IBM/Ponemon’s study | Sample of organizations that experienced breaches | Cost benchmarking | Number of healthcare breach events |
Verizon’s 2026 report says its broader dataset covers tens of thousands of security incidents and more than 22,000 confirmed breaches from organizations in 145 countries, contributed by sources including forensic firms, law enforcement, cyber insurers and other organizations.
HHS, by contrast, is operating a statutory U.S. health-information reporting system. IBM is measuring breach economics.
Do not combine these denominatorsAdding OCR, Verizon and other incident counts together would not produce a meaningful healthcare breach total because the datasets measure different populations using different collection methods.
Which Healthcare Organizations Report the Most Breaches?

Healthcare providers represent most OCR filings by count.
| Reporting Entity Type | 2025 Filings | Share |
|---|---|---|
| Healthcare providers | 604 | 75% |
| Business associates | 139 | 17% |
| Health plans | 59 | 7% |
| Healthcare clearinghouses | 2 | <1% |
The reporting-entity distribution is only one way to measure third-party exposure. In the same 2025 register, 282 of 804 filings recorded a business associate as present. That is approximately 35.1% of filings, compared with only 139 filings — 17% — where the reporting entity itself was classified as a Business Associate.
| Business-Associate Metric | 2025 Filings | Share | What It Means |
|---|---|---|---|
| Reporting entity classified as Business Associate | 139 | 17% | The filer itself is categorized as a business associate. |
| Business associate present | 282 | 35.1% | A business associate is recorded as involved, regardless of who submitted the filing. |
The 35.1% value is a ScanTitan calculation from 282 business-associate-present filings divided by 804 total 2025 filings. The two metrics should not be substituted for one another.
Reporting Entity Does Not Always Equal Breach Origin
HIPAA allows notification responsibilities to be delegated in some business-associate situations. HHS explains that notification responsibilities can be performed on behalf of affected covered entities when delegation is appropriate.
Consequently, the statement “75% of 2025 filings were classified as healthcare providers” is supportable from the OCR dataset.
The broader statement “75% of healthcare breaches originated inside provider systems” is not necessarily supportable from those filing categories alone.
Third-Party Healthcare Data Breaches
Third parties matter disproportionately because a single service provider can sit between many healthcare organizations and millions of patients.
Verizon found third-party involvement in 32% of healthcare breaches in its 2026 dataset. OCR’s business-associate classification measures something different, but the largest incidents show the same concentration problem operationally.
Change Healthcare processes healthcare transactions across a large network of payers and providers. Conduent provides business-processing services. Episource works with health plans and providers.
Compromise of one such organization can therefore propagate exposure across many customers.
Concentration riskThe security problem is not simply that “vendors get breached.” Organizations that aggregate claims, eligibility, billing, analytics or other healthcare information can create exceptionally large breach populations when compromised.
Healthcare Ransomware and System Intrusion Statistics
Ransomware remains important, but OCR’s Hacking/IT totals should not be renamed “ransomware statistics.” A ransomware attack may be reported under the broader Hacking/IT Incident category, but not every Hacking/IT filing is ransomware.
Verizon describes ransomware-driven System Intrusions as a major healthcare pattern in its 2026 analysis, alongside social engineering and recurring error-related breaches.
OCR Ransomware Enforcement
On July 29, 2026, OCR announced a settlement with OSF Healthcare System and identified it as the agency’s 21st ransomware enforcement action. OCR’s announcement emphasized the requirement for an accurate and thorough HIPAA risk analysis.
This enforcement count should not be interpreted as the number of healthcare ransomware attacks. It measures OCR enforcement actions in its ransomware series.
Healthcare Data Breach Costs

Healthcare remains the most expensive industry in IBM’s current breach-cost research.
IBM’s 2026 report puts the average healthcare breach cost at $6.64 million and says healthcare held the highest industry average for the 15th consecutive year.
Healthcare Breach Costs Have Declined for Two Consecutive IBM Studies
Because the figures below come from the same IBM report family, they can be compared more safely than unrelated vendor cost estimates.
| IBM Study Year | Average Healthcare Breach Cost |
|---|---|
| 2024 | $9.77M |
| 2025 | $7.42M |
| 2026 | $6.64M |
IBM reported $9.77 million in 2024. Its 2025 study then reported $7.42 million before the current 2026 benchmark fell to $6.64 million.
The decline should not be interpreted as evidence that healthcare breaches are inexpensive. Healthcare still has the highest sector average in IBM’s current study.
IBM groups breach costs into categories including detection and escalation, lost business, post-breach response and notification. In its 2026 analysis, detection/escalation and lost business together accounted for a majority of total costs.
For broader cross-industry context, see ScanTitan’s Data Breach Statistics research.
10 Largest Healthcare Data Breaches Reported to HHS OCR
The table below is an all-time ranking by the number of affected individuals currently listed in the HHS OCR-derived dataset. It uses the reporting date rather than assuming that the report year is the same as the incident year.
| Rank | Organization | Individuals Affected | Date Reported | Breach Type |
|---|---|---|---|---|
| 1 | Change Healthcare, Inc. | 192,700,000 | Jul. 19, 2024 | Hacking/IT Incident |
| 2 | Anthem Inc. | 78,800,000 | Feb. 13, 2015 | Hacking/IT Incident |
| 3 | Conduent Business Services LLC | 62,224,658 | Oct. 8, 2025 | Hacking/IT Incident |
| 4 | DentaQuest, LLC | 15,000,000 | Jul. 16, 2026 | Hacking/IT Incident |
| 5 | Welltok, Inc. | 14,782,887 | Nov. 6, 2023 | Hacking/IT Incident |
| 6 | Aflac Incorporated | 13,924,906 | Aug. 8, 2025 | Hacking/IT Incident |
| 7 | Kaiser Foundation Health Plan, Inc. | 13,400,000 | Apr. 12, 2024 | Unauthorized Access/Disclosure |
| 8 | Optum360, LLC | 11,500,000 | Jul. 1, 2019 | Hacking/IT Incident |
| 9 | HCA Healthcare | 11,270,000 | Jul. 31, 2023 | Hacking/IT Incident |
| 10 | Premera Blue Cross | 11,000,000 | Mar. 17, 2015 | Hacking/IT Incident |
Source: HealthcareBreaches.com, based on HHS OCR breach data current through September 4, 2026. The affected-person counts remain subject to revision when organizations or regulators update an incident.
The ranking also demonstrates why a “largest breach” table should not be used as a proxy for the most common healthcare breach. The median 2025 large-breach filing affected only 4,824 individuals, while the largest incidents affected tens or hundreds of millions.

Why Healthcare Breach Counts Change After Publication
The healthcare breach ecosystem contains several kinds of revision.
Initial Counts May Be Estimates
HHS explicitly instructs covered entities to provide an estimate when the number affected is uncertain and to submit updated information later. That means early breach rankings can change materially.
Change Healthcare’s Count Was Revised as the Investigation Progressed
HHS says Change Healthcare notified OCR on October 22, 2024 that about 100 million individual notices had been sent.
On January 24, 2025, it reported approximately 190 million individuals impacted.
On July 31, 2025, the affected population was updated again to approximately 192.7 million.
A research page that retained the earlier number after these later updates would now be stale.
Aflac Has Two Different but Valid Populations
Aflac identified unauthorized access to its U.S. network on June 12, 2025. Its SEC filing said the potentially affected material included claims information, health information, Social Security numbers and other personal information associated with its U.S. business.
By December 2025, Aflac had determined that personal information associated with approximately 22.65 million individuals was involved.
The HIPAA/OCR healthcare filing, however, lists approximately 13.9 million affected individuals.
Those figures should not be forced into one number because they describe different reporting populations.
Different Regulators Can Publish Different Counts
The current OCR-derived register lists 62,224,658 affected individuals for Conduent Business Services, while a later state-regulator submission has reported a slightly different aggregate.
The defensible research approach is not to average the values. For an OCR-based comparison table, the OCR figure should remain the comparable value while the existence of a later regulator figure is disclosed separately.
Major Healthcare Data Breach Case Studies
Change Healthcare: Concentration Risk at National Scale
UnitedHealth disclosed unauthorized access to Change Healthcare systems in February 2024. The incident disrupted healthcare transactions nationally and ultimately produced an HHS estimate of approximately 192.7 million affected individuals.
The important statistical lesson is not only that the breach was large. Change Healthcare demonstrates how dependence on highly connected healthcare intermediaries can make one incident dominate an entire year’s affected-person statistics.
Without understanding that concentration, 2024’s healthcare breach total can look like a uniform sector-wide increase rather than a distribution heavily influenced by one exceptional event.
Conduent: One Event, Different Regulator Totals
The current OCR-derived register lists 62,224,658 affected individuals for Conduent Business Services, making it one of the largest healthcare-related breach filings in the current dataset.
Other regulator reporting has produced a slightly different total. The correct research response is not to average the counts or silently select the larger number. For an OCR-based healthcare table, the OCR figure should remain the comparable value while any later regulator count is explained separately.
Aflac: Scope Matters More Than Headline Size
Aflac’s SEC disclosure eventually identified about 22.65 million people whose personal information was involved in its U.S. incident. Its HIPAA/OCR population is narrower.
This is a useful example of why people affected by the broader cyber incident and individuals included in the HIPAA breach report can be different populations.
It also corrects another common error: Aflac specifically stated that its systems were not affected by ransomware.
Blue Shield of California: A Major Breach Without Ransomware
Blue Shield disclosed that Google Analytics had been configured in a way that allowed certain member information to be shared with Google Ads between April 2021 and January 2024. Blue Shield said it discovered the issue on February 11, 2025 and that no bad actor was involved.
The potentially affected information included insurance-plan information, location data, member account identifiers and certain medical-claim-related details.
This case demonstrates that a large healthcare breach can result from data-flow and tracking configuration, not malware, ransomware or network intrusion.
HIPAA Breach Reporting and Enforcement
For breaches affecting 500 or more individuals, covered entities must notify HHS without unreasonable delay and no later than 60 calendar days after discovery. Breaches involving fewer than 500 individuals are subject to annual reporting requirements.
A business associate can report on behalf of a covered entity in appropriate circumstances, and HHS allows certain notification responsibilities to be delegated.
A Breach Does Not Automatically Mean a HIPAA Penalty
OCR enforcement focuses on compliance with the HIPAA Privacy, Security and Breach Notification Rules, not simply on whether a cyberattack occurred.
For example, in announcing its 21st ransomware enforcement action in July 2026, OCR specifically emphasized the importance and legal requirement of conducting an accurate and thorough risk analysis.
A breach may prompt an investigation, but the existence of a breach by itself should not be presented as proof of a HIPAA violation or an inevitable financial penalty.
Five Healthcare Data Breach Statistics Myths
Myth 1: “Healthcare Breaches Increase Every Year”
Not necessarily. Different metrics can move in different directions.
The number of OCR filings may rise while the total number of affected individuals falls because one year contains a mega-breach and another does not. The current 2025 register contains more filings than the current 2024 register, yet substantially fewer affected individuals.
Myth 2: “140 Million Affected Individuals Means 140 Million Medical Records”
No. OCR reports the approximate number of individuals affected. That is not a medical-record count.
One person can have many records, and annual aggregates can potentially include the same individual in multiple unrelated incidents.
Myth 3: “Most Healthcare Breaches Happen at Hospitals”
OCR’s largest reporting category is healthcare providers, but “healthcare provider” includes more than hospitals.
More importantly, reporting entity does not necessarily identify the technical origin of every breach. Large business-associate compromises can affect enormous populations across multiple downstream organizations.
Myth 4: “Large Healthcare Breaches Are Basically Ransomware Attacks”
Ransomware is important, but not every large breach involves ransomware.
Aflac said its 2025 systems were not affected by ransomware, while Blue Shield’s disclosure resulted from website analytics and tracking configuration rather than a malicious network intrusion.
Myth 5: “Once OCR Publishes a Number, It Is Final”
HHS permits estimated initial affected-person counts and subsequent updates when new information becomes available.
Change Healthcare is the clearest example: its known affected population was revised as investigation and notification progressed.
What the Data Means for Healthcare Security Teams
The strongest lesson from the current evidence is not that healthcare organizations need one specific security tool. The threat surface is broader.
Third-Party Concentration Needs Its Own Risk Model
A vendor handling information for dozens or hundreds of healthcare organizations can create much greater systemic exposure than its own organization size suggests.
The 32% third-party figure in Verizon’s healthcare corpus and the scale of Change Healthcare and Conduent make vendor dependencies a core security issue, not merely a procurement concern.
Vulnerability Management Remains Operationally Important
Verizon identified vulnerability exploitation as the leading listed initial-access vector in 20% of its healthcare breaches, ahead of phishing and credential abuse in that dataset.
Healthcare organizations therefore need to understand externally exposed applications, network services and software dependencies rather than focusing exclusively on employee phishing training.
The ScanTitan website vulnerability scanner can support this layer by helping identify certain known and externally observable weaknesses. Automated scanning, however, does not detect every attack path and does not replace penetration testing, identity controls, endpoint security, monitoring or incident response.
Error Prevention Still Deserves Investment
Healthcare’s persistent Miscellaneous Errors pattern means security programs also need controls against misdelivery, incorrect access, unsafe data flows, exposed storage, tracking misconfiguration and loss of unencrypted devices or media.
Not every meaningful healthcare breach begins with an attacker.
Methodology
This research prioritizes primary regulators, official company disclosures and original industry research. Secondary datasets are used where they provide a reproducible view of OCR data or help explain current portal snapshots.
HHS OCR Breach Data
The HHS OCR Breach Portal is the central U.S. regulatory source for HIPAA breaches of unsecured PHI affecting 500 or more individuals.
Because the public register is mutable, annual portal totals in this article are treated as dated snapshots rather than permanent historical facts.
The main annual series and 2026 YTD benchmark use an OCR-derived dataset current through September 4, 2026. It lists 804 filings and 140,574,754 affected individuals for 2025, and 506 filings affecting 74,872,402 individuals in 2026 through September 4.
A separate OCR-derived analytical register reports the same 804 filings for 2025 but a slightly different affected-person sum of 140,514,189. This report preserves the discrepancy rather than averaging the two values.
Occurrence-Year Data
Where occurrence-year reporting is required, HHS’s annual Report to Congress takes precedence.
The latest available report covers 2024 and identifies 663 large breaches occurring during that calendar year, affecting approximately 242.9 million individuals.
No equivalent finalized HHS occurrence-year report for 2025 was available at the time of this research.
Verizon DBIR
Verizon’s 2026 DBIR uses contributed incident data normalized through the VERIS framework. Its healthcare section covers 1,492 incidents and 1,438 confirmed breaches.
These observations are used for attack patterns, actor characteristics and vectors — not for calculating a national HIPAA breach total.
IBM Cost of a Data Breach
IBM’s Cost of a Data Breach research is used for financial benchmarking. The $6.64 million healthcare value is a study average, not a forecast or a universal cost assigned to every healthcare breach.
Research Limitations
- OCR’s public 500+ list does not represent every small HIPAA breach.
- Portal entries can be revised after initial submission.
- Submission date and incident date are different concepts.
- “Individuals affected” is not necessarily a unique-person or record count across an annual aggregate.
- Healthcare security datasets use different populations and definitions.
- OCR, Verizon and IBM should not be merged into one synthetic breach total.
Source Register
| Organization | Dataset / Document | Period | Primary Use in This Research | Main Limitation |
|---|---|---|---|---|
| HHS OCR | Breach Portal | Live | Filing counts, affected individuals, entity type and breach category | Mutable register; submission date does not equal occurrence date |
| HHS OCR | Annual Report to Congress on Breaches | 2024 | Occurrence-year regulatory benchmark | Published with lag |
| HHS OCR | Change Healthcare Cybersecurity FAQs | Updated through 2025 | Change Healthcare impact and notification revisions | Incident-specific |
| HHS OCR | Enforcement releases | 2026 | Ransomware enforcement actions | Enforcement does not measure ransomware prevalence |
| Stern Security / HealthcareBreaches.com | OCR-derived Healthcare Breaches Dashboard | Current through Sep. 4, 2026 | Historical annual series, 2026 YTD benchmark and all-time breach ranking | Secondary compilation of HHS OCR data; snapshot can differ from other OCR-derived exports |
| DataBreachCost.com | 2025 OCR-derived register analysis | 2025 snapshot | Median breach size, breach-location categories and business-associate involvement | Secondary analytical compilation; preserve its snapshot date and derived metrics |
| Verizon | 2026 Data Breach Investigations Report | 2026 report cycle | Healthcare attack patterns, vectors, actors and third-party involvement | Contributed corpus, not a national census |
| IBM | Cost of a Data Breach 2026 | 2026 | Healthcare breach-cost benchmark | Sample average |
| SEC / Aflac | Company filings | 2025–2026 | Aflac incident population and ransomware status | Broader company-incident scope differs from OCR HIPAA population |
| Blue Shield of California | Official breach notice | Apr. 2025 | Tracking and analytics incident cause | Company disclosure |
Frequently Asked Questions
How many healthcare data breaches were reported in 2025?
A September 2026 HHS OCR-derived snapshot contains 804 large-breach filings submitted during 2025. Those filings list approximately 140.6 million affected individuals. Because OCR entries can be added or amended, the figure should be accompanied by its snapshot date rather than described as permanently final.
How many healthcare data breaches have happened in 2026?
A frozen snapshot through September 4, 2026 contained 506 large-breach filings affecting 74,872,402 individuals. OCR’s live portal already contains later submissions, so that number is intentionally a reproducible YTD cutoff rather than a live total.
How many people were affected by healthcare data breaches in 2025?
The current research snapshot lists 140,574,754 affected individuals across 2025 OCR filings in the September 4 snapshot. This should not be described as 140.5 million medical records or necessarily 140.5 million unique Americans.
What is the largest healthcare data breach?
The Change Healthcare cyberattack is the largest breach currently represented in HHS healthcare breach reporting. HHS says Change Healthcare ultimately reported approximately 192.7 million individuals impacted.
What causes most healthcare data breaches?
In the current 2025 OCR register, 81% of filings were categorized as Hacking/IT Incidents. Verizon’s separate healthcare cybersecurity dataset identifies vulnerability exploitation at 20%, phishing at 14% and credential abuse at 11% among initial-access vectors. These figures describe different datasets and should not be merged.
How much does a healthcare data breach cost?
IBM’s 2026 Cost of a Data Breach research puts the average healthcare breach at $6.64 million, the highest industry average in its study for the fifteenth consecutive year.
Are most healthcare data breaches caused by ransomware?
Ransomware is a major healthcare threat, but OCR’s broad Hacking/IT category should not be interpreted as a ransomware percentage. Verizon identifies System Intrusion as a major healthcare pattern, but errors, social engineering, phishing, credential abuse and other causes also contribute to healthcare breaches.
Why do different websites report different healthcare breach totals?
Different totals can result from different OCR retrieval dates, revised breach entries, submission year versus occurrence year, affected individuals being mislabeled as records, different company and HIPAA reporting populations, and the use of fundamentally different datasets such as OCR, Verizon or IBM. For healthcare breach research, the denominator and cutoff date are therefore as important as the headline number.


