Data Breaches in Healthcare: What the Numbers Tell Us

In our consulting services to clients in the areas of HIPAA Privacy Rule, the HIPAA Breach Notification Rule, and the HIPAA Security Rule, we have always emphasized…

Read More

Jim Hook, MPH

By Jim Hook, MPH | July 18, 2026

The words DATA BREACH with a backdrop of ones and zeros and the shadow of a caduceus, all representing Data Breaches in Healthcare.

In our consulting services to clients in the areas of HIPAA Privacy Rule, the HIPAA Breach Notification Rule, and the HIPAA Security Rule, we have always emphasized how important it is for healthcare organizations to avoid making an appearance on the “Wall of Shame”. However, analyzing the data breaches on the HIPAA Breach Portal provides an opportunity to learn from this compilation of healthcare data breaches. Many other sectors have a tradition of learning from the mistakes or misfortunes of others, and the healthcare industry is a leader among them.

Executive Summary – Key Takeaways

  • Healthcare breaches are increasingly driven by large-scale hacking incidents.
  • Cyberattacks dominate, but preventable human errors persist.
  • Business associate failures amplify exposure and operational disruption.
  • Risk assessment and incident readiness are now executive priorities. 

What is the HIPAA Breach Portal?

The HIPAA Breach Portal (also known as the HIPAA Wall of Shame) is a website managed by the Department of Health and Human Services (HHS), Office for Civil Rights (OCR), which lists companies and individuals that have experienced data breaches affecting 500 or more individuals. Specifically, these breaches are a violation of the Health Insurance Portability and Accountability Act (HIPAA), the federal law that covers the privacy of protected health information (PHI).

The Breach Portal lists all data breaches reported within the last 24 months that are currently under investigation by the Office for Civil Rights (OCR), and archived data breaches dating back to 2015. It also provides an analytic tool to review the reported healthcare data breaches by several categories:

  • By a date range;
  • By type of breach, e.g., hacking/IT incident, theft, etc..
  • By location of breach, e.g., network server or electronic health records;
  • By type of Covered Entity, e.g., healthcare provider, health plan, or healthcare clearing house;
  • By State or Territory;
  • By association with a Business associate;
  • By a description of the breach, and
  • By the name of the Covered Entity or Business Associate.

The results can be exported as Excel or CSV files, or PDF or XML files.

There are some definite trends we can identify by doing some comparisons over time. Keep in mind that these data breach cases represent only the healthcare data breaches involving healthcare providers where 500 or more records were breached. Some highlights (or lowlights, if you prefer):

  1. The number of reported incidents in the Hacking/IT incident category went from 30 in 2015 to 374 in 2023 to 444 (!) in 2024.
  2. The majority of Hacking/IT Incidents involved email or network servers. Both of these categories increased by about 50% between 2023 and 2024.
  3. Hacking/IT incidents at healthcare providers affected 55 million and 48 million people in 2023 and 2024, respectively. Hacking/IT incidents accounted for the overwhelming majority (99% and 95%) of reported healthcare data breaches in both years.
  4. Healthcare data breaches were reported by 468 healthcare providers in 2023 and by 538 healthcare providers in 2024, respectively.
  5. Theft and Loss (mainly of laptops and devices) went from 84 reported incidents in 2015 to 12 in 2024. The number of individuals affected declined from 790 thousand in 2015 to only 86 thousand in 2024.
  6. The total number of affected individuals grew from 172.8 million in 2023 to 282.2 million in 2024.
  7. Paper records are also still a source of unauthorized disclosures of PHI. Paper records are still lost in the mail. Large numbers (large enough to meet the 500 record reporting threshold) are sent to the wrong individuals at one time. Records are stolen during robberies or burglaries. Improper disposal incidents, e.g., throwing healthcare records in a dumpster, are also still happening.

The following graphs look at various trends over the last 5 years of reported breaches based on data retrieved from the HIPAA Breach Portal. All figures, unless otherwise noted in the graph title, are based on the total breaches for all entities, and not just the subset of healthcare providers. Also, it may be worth mentioning that it’s common to see fluctuations in the figures displayed on the portal. Some reasons for this include ongoing investigations, late reporting, and updates and revisions as new information becomes available.

Column Graph - Number of Reported Breaches by Year
Column Graph - Total Individuals Affected by Year
Column Graph - Avg Individuals Affected Per Breach by Year
Column Graph - Number of Breaches Due to Hacking vs Non-Hacking by Year
Column Graph - Individuals Affected by Hacking Related Breaches by Year
Column Graph - Number of Breaches by Year Due to Theft or Loss
Column Graph - Number of Individuals Affected Due to Theft or Loss by Year
Column Graph - Number of Breaches by Providers vs Business Associates by Year
Column Graph - Individuals Affected by Year Providers vs Business Associates

What is the Experience with Business Associates?

Business Associates have contributed more than their share of unsecured protected health information data breaches in the healthcare sector. This is somewhat understandable. Large healthcare systems may have several hundred thousand records at risk of a hacking incident. Business Associates providing services to multiple large and small healthcare providers may have tens of millions of records containing sensitive healthcare data exposed in breached healthcare records.

Investigations often involve large-scale record breaches. In 2024, there were 12 investigations with over a million records exposed. This included the largest data breach to date at Change Healthcare, with 190 million records exposed. Note that this breach also caused significant disruption in payments to healthcare providers. This type of cost has not previously been reflected in the costs of recovery from a breach.

First, there has been a steady increase in the number of Covered Entities that report data breaches. Overall, reported healthcare data breaches have grown from 270 in 2015 to 746 in 2023 and to 736 in 2024. It is worth noting that the rate in the first half of 2025 (through June 30) is on pace to exceed all these figures, with 390 reported healthcare breaches to date.

Second, the number of breached records exposed, or potentially exposed, has ballooned, especially because of multiple large data breaches involving Business Associates. The total number of exposed records grew from 112.5 million in 2015 to 172.8 million in 2023 and to 282.2 million in 2024. Breaches reported due to Hacking/IT incidents routinely expose hundreds of thousands of records among healthcare providers, and millions of records at Business Associates.

Third, breaches reported by Healthcare Clearinghouses and health plans are typically much more modest, although Kaiser Foundation Health Plan did report unauthorized access/disclosure of 13.4 million records in 2024.

What Are Some Real-World Examples of Healthcare Data Breaches?

There are some things not to do, or situations to avoid. Some of the more challenging situations our clients have faced include:

1. Data Breach at a Business Associate

A large data breach occurred at a Business Associate of one of our clients. The BA had implemented email-free Fridays, during which no company employee was allowed to send emails internally. The fact that a hacker had invaded their system was discovered when the CEO got an email on a Friday from an employee whose account had been compromised. Several hundred of our Client hospital’s records were compromised.

The Business Associate took responsibility for notification to affected individuals, but the hospital, a California healthcare provider, had to report the incident to state licensing authorities, who initiated their own investigation. 

2. Faxed Patient Records Sent to an Employer

A hospital business office employee faxed some patient records to an individual’s employer in connection with a workers’ compensation claim. The records, which included mental health patient information, were passed around in the employer’s office. The patient ultimately lost his job.

3. Patient Mix-Up Due to Similar Names

Patient #1 (first name Candy) came to the Hospital Emergency Department via ambulance. She shared an almost identical first and last name with Patient #2. Patient #1 was registered in Patient #2’s record. Patient #2 discovered the issue when she received a bill from the ambulance company that transported Patient #1.

Months later, Patient #1 again came to the Emergency Department and was again registered in Patient #2’s record. Patient #2 found out about it when she received a call from her primary care physician wondering what had caused her to go to the hospital and be admitted the previous night.

Patient #2 contacted the Office for Civil Rights at HHS and lodged a complaint. The OCR wrote to the hospital asking for a corrective action plan, e.g., two-factor identification, to avoid this type of occurrence in the future. We assisted in drafting the response while reminding our client that multiple complaints about the same issue are the types of things that trigger an onsite investigation by the OCR. And onsite investigations involve every aspect of a Covered Entity’s compliance with the HIPAA Privacy Rule and the HIPAA Security Rule.

4. Patient Lists Sent to Non-internal email addresses

A hospital was changing electronic health record systems and needed to close out all entries in its legacy system. Management for the physician clinics set out to remind physicians about incomplete records in the legacy system that needed to be completed before the implementation of the new system. A list of each patient and the type of record that was incomplete was developed and sent to the physicians.

Management was reminded that some of the physicians were not employees and did not have internal hospital email addresses. The lists contained all the patient data and were sent to all physicians, including those with external email addresses. After the breach was reported to state licensing authorities, they came on-site to do an investigation. The results of that incident are still pending.

What’s a Healthcare Provider to Do?

Well, with the widespread implementation of electronic health record systems, it is clear that healthcare entities must implement safeguards to prevent data breaches, especially against Hacking Incidents involving Network Servers and email. 

One thing to do immediately is to conduct a HIPAA self-audit to gauge your readiness for the real thing. These periodic audits can go a long way in shoring up your HIPAA compliance efforts. Here are some key questions to ask.

Key Compliance QuestionWhy it Matters
Are you conducting regular risk assessments?The first step to ensuring compliance is performing a regular risk analysis. By identifying your vulnerabilities, you can stop common HIPAA data breaches before they happen.
What are your HIPAA Privacy and Security policies and procedures, and can you describe how you implement them?Your reasonable and appropriate policies and procedures will be unique and based on your company culture as well as laws and regulations. Auditors will want documentation and records showing that you have properly communicated and implemented policies and procedures to your staff.
Do you have up-to-date HIPAA training programs and manuals for employees?When you update your practices, you must also update your training manuals. For example, the Covid pandemic created an increase in remote work. Your staff should be fully trained to keep ePHI secure when working from home. Implement mock phishing attacks to measure employee responses to subtle and/or obvious phishing attacks.
Do you have Business Associate Agreements for every vendor with whom you share ePHI?Periodically review your vendors and Business Associate agreements to be sure they are up-to-date and relevant. Ensure that your agreements require Business Associates to take responsibility for notifying patients if their information has been compromised. They also need to have cyber insurance to cover the costs of unauthorized access disclosures.
Are you keeping well-organized documentation?Document everything. Your thorough records can offer proof of your strong efforts to maintain HIPAA compliance. This is especially important to show compliance with the HIPAA Breach Notification Rule.
Are you keeping track of ePHI?You most likely are aware of ePHI in your main databases and programs, but are you aware of every spreadsheet, file transfer, or mobile device that may contain patient data? You can use technological tools to scan your entire network to locate any ePHI that may be hidden.
Are you prepared to respond to incidents of noncompliance?It’s best to have your plan in place for disclosing a breach before it happens. Hopefully, you will never need it, but if you do, you will already have the policies and procedures that will enable you to disclose the proper information within the required timeframe to meet HIPAA requirements. An don’t forget to review your own organization’s cyber coverage!
How are you monitoring mobile electronic devices?With new technologies and the need for remote work during the pandemic, more organizations are using mobile devices outside of the healthcare organization. Is your mobile data encrypted? Have you trained your staff on how to keep it secure from unauthorized breaches or security hacks? Is your Information Security Officer constantly reviewing the need for new or enhanced security measures and/or health information technology?
Are you monitoring recent trends in common HIPAA violations?In the past few years, the OCR has received many complaints from patients about unfulfilled requests for medical records. The OCR expects HIPAA-covered entities to respond within the 30-day time frame specified in the HIPAA law for responding to such requests. Fines large and small have been levied on covered entities who fail to release medical records timely.
Review your network server security measures.Institute real-time monitoring of access to network servers to alert you if hacking attempts begin. Make sure to keep you list of users up to date, deleting user privileges for users who no longer need them. Institute multi-factor authentication requirements for accessing network servers and email systems.

Data breaches in healthcare are not quite yet a “when”, not an “if”, but they are trending that way! With the estimated cost of dealing with a data breach averaging almost $10 million in 2024, some due diligence at the current time may save you months or even years of grief in the future. If you are a solo practitioner, even the condensed list above may seem overwhelming. There are no shortcuts or de minimus regulations for small providers, but there is help. Check out this guidance for small medical offices!


Frequently Asked Questions About Healthcare Data Breaches

Does every healthcare data breach appear on the HHS Breach Portal?

No, the HHS Breach Portal does not display every healthcare privacy or security incident.

The portal publicly lists reported breaches of unsecured protected health information affecting 500 or more individuals. Breaches affecting fewer than 500 individuals may still require individual notification and must be reported to HHS annually. Portal totals should therefore not be treated as a complete count of HIPAA incidents.

When does an impermissible use or disclosure become a reportable HIPAA breach?

An impermissible use or disclosure is generally presumed to be a breach unless an exception or documented low-risk determination applies.

The organization’s assessment should consider the PHI involved, the unauthorized recipient, whether the information was acquired or viewed, and the extent of mitigation. Notification requirements apply to breaches of unsecured PHI, while information properly encrypted or destroyed using recognized methods may not trigger notification.

What should a healthcare provider do immediately after discovering a possible data breach?

A healthcare provider should contain the incident, activate its response procedures, and begin a documented breach assessment immediately.

The response team should mitigate harmful effects, determine whether PHI was involved, and coordinate privacy, security, operational, legal, and communications responsibilities. When notification is required, affected individuals must generally be notified without unreasonable delay and no later than 60 days after discovery.

Why does a business associate breach remain a concern for the healthcare provider?

A business associate breach can still create substantial notification, operational, and oversight obligations for the covered entity.

Business associates must notify covered entities, but the covered entity remains ultimately responsible for ensuring affected individuals receive required notice, even when delivery is delegated. Organizations should maintain current business associate agreements, defined incident-notification procedures, vendor-risk oversight, and clear responsibility for investigation, communications, mitigation, and corrective action.

How often should a healthcare organization conduct a HIPAA security risk analysis?

HIPAA does not prescribe a fixed schedule, but risk analysis should be an ongoing, documented process.

HHS states that frequency depends on the organization’s circumstances. An updated analysis may be appropriate after a security incident, ownership or staffing changes, new technology, operational changes, or evolving threats. The objective is to identify risks early enough to update safeguards before vulnerabilities result in greater exposure.

Which security controls should healthcare organizations prioritize based on recent breach trends?

Healthcare organizations should prioritize controls addressing compromised credentials, email threats, exposed systems, third-party risks, and recovery readiness.

High-value measures include email security, multifactor authentication, vulnerability management, timely access revocation, workforce training, encryption, backups, incident planning, and vendor-risk controls. More mature programs should also consider network segmentation, centralized logging, and regularly tested incident-response plans. These measures align with HHS healthcare cybersecurity priorities.