← Standing Watch Advisory home

Insights · Healthcare

Healthcare Data Breaches: What 15+ Years of HHS Reports Tell Leaders

An executive read of 8,007 breach reports filed with the U.S. Department of Health and Human Services since 2009: how often large breaches happen, what causes them, and where the impact concentrates.

  • 8,007breach reports since Oct 2009
  • 1.09Bindividuals affected, as reported*
  • 81%of 2025 breaches were hacking/IT incidents
  • 763reports a year on average, 2023–2025

* Totals add up individuals affected as reported for each breach; the same person can be counted in more than one breach.

For boards and executives

Four takeaways

  • Large breaches are now routine.

    Reports of breaches affecting 500 or more people averaged 763 a year in 2023–2025, about 3.7 times the 2010–2012 average of 205.

    Board questionIs our incident readiness planned for an event we are likely to face, rather than a rare one?

  • Hacking has replaced lost and stolen devices as the main cause.

    Hacking/IT incidents were 4% of reported breaches in 2010 and 81% in 2025. They account for 91% of all individuals affected in the record.

    Board questionDo our cyber priorities and investment reflect that shift?

  • A few incidents drive most of the impact.

    The 10 largest breaches account for 39% of the 1.09 billion individuals affected reported since 2009. The median breach affected 4,000 people.

    Board questionHave we rehearsed a large, prolonged incident, including clinical and financial continuity?

  • Vendors carry a large share of the exposure.

    Business associates were involved in 30% of breaches but 56% of individuals affected (47% excluding the 2024 Change Healthcare breach).

    Board questionDo we know which vendors hold our patients’ data, and how quickly they must tell us about an incident?

Chart 1Reported breaches per year

Reported breaches rose from 199 in 2010 to 802 in 2025, the highest full year; 2026 is partial (563 reports posted through Sep 21, versus 606 in the same period of 2025).

* Partial year: 2009 starts with the breach notification rule (first posted submission Oct 21, 2009); 2026 runs through the latest posted submission (Sep 21, 2026). Line shows the 3-year average of full years.

View data table
Reported breaches and individuals affected by year of submission (* partial year)
YearBreaches3-year averageIndividuals affected
2009*18134,773
20101995,932,276
201120013,162,158
2012217205.32,853,985
2013277231.37,018,839
2014314269.319,073,551
2015270287.0112,466,720
2016328304.016,711,004
2017357318.35,313,246
2018369351.315,256,235
2019511412.344,969,724
2020663514.335,321,223
2021715629.761,206,238
2022718698.764,570,326
2023745726.0183,256,225
2024741734.7290,054,222
2025802762.7140,574,793
2026*56376,637,981
Source: HHS Office for Civil Rights breach portal, data as of Oct 7, 2026. Analysis: Standing Watch Advisory.

Chart 2What kind of breach: share by type each year

Theft was the most common breach type every year through 2014; hacking/IT incidents have been the largest category every year since 2017, reaching 81% of breaches in 2025.

* 2026 is a partial year. Reports listing more than one type are grouped under “Other, unknown or multiple.”

View data table
Share of reported breaches by type, by year of submission (%; * partial year)
YearHacking/IT incidentUnauthorized access/disclosureTheftLossImproper disposalOther, unknown or multiple
20104.05.065.37.04.014.6
20117.514.557.07.53.010.5
20124.612.955.87.83.215.7
20139.723.143.07.24.312.6
201411.128.035.76.42.516.2
201520.738.130.08.92.20.0
201634.839.618.64.92.10.0
201741.735.315.44.53.10.0
201844.737.911.13.52.70.0
201961.427.07.42.91.20.0
202068.921.05.92.02.30.0
202176.418.23.41.40.70.0
202279.116.22.61.50.60.0
202381.515.71.60.50.70.0
202482.614.71.60.50.50.0
202580.917.61.10.20.10.0
2026*85.314.00.20.20.40.0
Source: HHS Office for Civil Rights breach portal, data as of Oct 7, 2026. Analysis: Standing Watch Advisory.

Chart 3Typical size by where the information was held

Breaches involving network servers had the largest typical size, a median of 9,962 individuals, compared with 1,500 for paper and films.

Median individuals affected per report. A report listing several locations counts under each. Locations with fewer than 50 reports are not shown.

View data table
Median individuals affected by location of breached information (locations with 50+ reports)
LocationReportsMedian individuals affected
Network Server3,6909,961.5
Email1,8513,259
Electronic Medical Record4772,864
Other4602,560.5
Desktop Computer3802,367
Laptop5132,300
Other Portable Electronic Device3312,287
Paper/Films1,0121,500
Source: HHS Office for Civil Rights breach portal, data as of Oct 7, 2026. Analysis: Standing Watch Advisory.

Chart 4Business associates: share of breaches vs. share of people affected

Business associates were involved in 30% of reported breaches but 56% of individuals affected (47% excluding the 2024 Change Healthcare breach).

“Involved” means the reporting entity is a business associate, or the report says a business associate was present.

View data table
Business associate involvement (filer is a business associate, or a business associate was present)
MeasureBusiness associate involvedNot involved
Share of breaches30.0%70.0%
Share of individuals affected56.3%43.7%
Share of individuals affected, excluding the 2024 Change Healthcare breach46.9%53.1%
Median individuals affected per breach4,4243,840
Number of breaches2,4035,604
Source: HHS Office for Civil Rights breach portal, data as of Oct 7, 2026. Analysis: Standing Watch Advisory.

Chart 5Where breaches are reported

California has the most reported breaches (786); by individuals affected, Minnesota leads (212.1 million), mostly from Change Healthcare’s 2024 breach (192.7 million individuals), which was reported there.

State of the reporting entity, not where affected individuals live. Indiana ranks 2nd by individuals affected (93.1 million, including 78.8 million from Anthem’s 2015 breach) and 12th by number of breaches (202).

View data table
Top 10 states by reported breaches and by individuals affected (state of the reporting entity)
RankBy breachesBreachesBy individuals affectedIndividuals affected
1California786Minnesota212,076,397
2Texas654Indiana93,114,333
3New York516New Jersey79,985,058
4Florida471California79,958,213
5Illinois364Florida54,072,220
6Pennsylvania345Texas49,862,944
7Ohio278New York42,564,803
8Massachusetts245Tennessee39,597,433
9Michigan239Georgia38,859,277
10Georgia229Colorado29,369,166
Source: HHS Office for Civil Rights breach portal, data as of Oct 7, 2026. Analysis: Standing Watch Advisory.

About the data

  • Source: the HHS Office for Civil Rights breach portal, combining the “Under Investigation” list (763 reports from the last 24 months) and the Archive (7,248 reports). Exported October 7, 2026 at 1:38 PM Arizona time; 4 exact duplicate rows removed, leaving 8,007 reports.
  • The portal lists breaches of unsecured protected health information affecting 500 or more individuals, as reported by HIPAA covered entities and business associates.
  • Years are based on the date a breach was submitted to HHS, not when it occurred or was discovered.
  • Recent periods are incomplete. 2009 starts with the breach notification rule (effective September 2009). 2026 runs through the latest posted submission (Sep 21, 2026), and reports can take weeks to appear, so the most recent months undercount.
  • Individuals affected are the counts reported by each organization and can be revised later. Adding them up counts a person once for each breach that affected them.
  • State is the reporting organization’s state, not where affected individuals live.
  • Reports listing more than one breach type are grouped as “Other, unknown or multiple.” A report listing several locations counts under each location.

Want a clear read on what this means for your organization?

Standing Watch Advisory helps boards and executives in healthcare and financial services turn cyber and vendor risk into decisions they can oversee with confidence.

Start a conversation