Insights · Healthcare
Healthcare Data Breaches: What 15+ Years of HHS Reports Tell Leaders
An executive read of 8,007 breach reports filed with the U.S. Department of Health and Human Services since 2009: how often large breaches happen, what causes them, and where the impact concentrates.
- 8,007breach reports since Oct 2009
- 1.09Bindividuals affected, as reported*
- 81%of 2025 breaches were hacking/IT incidents
- 763reports a year on average, 2023–2025
* Totals add up individuals affected as reported for each breach; the same person can be counted in more than one breach.
Four takeaways
-
Large breaches are now routine.
Reports of breaches affecting 500 or more people averaged 763 a year in 2023–2025, about 3.7 times the 2010–2012 average of 205.
Board questionIs our incident readiness planned for an event we are likely to face, rather than a rare one?
-
Hacking has replaced lost and stolen devices as the main cause.
Hacking/IT incidents were 4% of reported breaches in 2010 and 81% in 2025. They account for 91% of all individuals affected in the record.
Board questionDo our cyber priorities and investment reflect that shift?
-
A few incidents drive most of the impact.
The 10 largest breaches account for 39% of the 1.09 billion individuals affected reported since 2009. The median breach affected 4,000 people.
Board questionHave we rehearsed a large, prolonged incident, including clinical and financial continuity?
-
Vendors carry a large share of the exposure.
Business associates were involved in 30% of breaches but 56% of individuals affected (47% excluding the 2024 Change Healthcare breach).
Board questionDo we know which vendors hold our patients’ data, and how quickly they must tell us about an incident?
Chart 1Reported breaches per year
Reported breaches rose from 199 in 2010 to 802 in 2025, the highest full year; 2026 is partial (563 reports posted through Sep 21, versus 606 in the same period of 2025).
* Partial year: 2009 starts with the breach notification rule (first posted submission Oct 21, 2009); 2026 runs through the latest posted submission (Sep 21, 2026). Line shows the 3-year average of full years.
View data table
| Year | Breaches | 3-year average | Individuals affected |
|---|---|---|---|
| 2009* | 18 | 134,773 | |
| 2010 | 199 | 5,932,276 | |
| 2011 | 200 | 13,162,158 | |
| 2012 | 217 | 205.3 | 2,853,985 |
| 2013 | 277 | 231.3 | 7,018,839 |
| 2014 | 314 | 269.3 | 19,073,551 |
| 2015 | 270 | 287.0 | 112,466,720 |
| 2016 | 328 | 304.0 | 16,711,004 |
| 2017 | 357 | 318.3 | 5,313,246 |
| 2018 | 369 | 351.3 | 15,256,235 |
| 2019 | 511 | 412.3 | 44,969,724 |
| 2020 | 663 | 514.3 | 35,321,223 |
| 2021 | 715 | 629.7 | 61,206,238 |
| 2022 | 718 | 698.7 | 64,570,326 |
| 2023 | 745 | 726.0 | 183,256,225 |
| 2024 | 741 | 734.7 | 290,054,222 |
| 2025 | 802 | 762.7 | 140,574,793 |
| 2026* | 563 | 76,637,981 |
Chart 2What kind of breach: share by type each year
Theft was the most common breach type every year through 2014; hacking/IT incidents have been the largest category every year since 2017, reaching 81% of breaches in 2025.
* 2026 is a partial year. Reports listing more than one type are grouped under “Other, unknown or multiple.”
View data table
| Year | Hacking/IT incident | Unauthorized access/disclosure | Theft | Loss | Improper disposal | Other, unknown or multiple |
|---|---|---|---|---|---|---|
| 2010 | 4.0 | 5.0 | 65.3 | 7.0 | 4.0 | 14.6 |
| 2011 | 7.5 | 14.5 | 57.0 | 7.5 | 3.0 | 10.5 |
| 2012 | 4.6 | 12.9 | 55.8 | 7.8 | 3.2 | 15.7 |
| 2013 | 9.7 | 23.1 | 43.0 | 7.2 | 4.3 | 12.6 |
| 2014 | 11.1 | 28.0 | 35.7 | 6.4 | 2.5 | 16.2 |
| 2015 | 20.7 | 38.1 | 30.0 | 8.9 | 2.2 | 0.0 |
| 2016 | 34.8 | 39.6 | 18.6 | 4.9 | 2.1 | 0.0 |
| 2017 | 41.7 | 35.3 | 15.4 | 4.5 | 3.1 | 0.0 |
| 2018 | 44.7 | 37.9 | 11.1 | 3.5 | 2.7 | 0.0 |
| 2019 | 61.4 | 27.0 | 7.4 | 2.9 | 1.2 | 0.0 |
| 2020 | 68.9 | 21.0 | 5.9 | 2.0 | 2.3 | 0.0 |
| 2021 | 76.4 | 18.2 | 3.4 | 1.4 | 0.7 | 0.0 |
| 2022 | 79.1 | 16.2 | 2.6 | 1.5 | 0.6 | 0.0 |
| 2023 | 81.5 | 15.7 | 1.6 | 0.5 | 0.7 | 0.0 |
| 2024 | 82.6 | 14.7 | 1.6 | 0.5 | 0.5 | 0.0 |
| 2025 | 80.9 | 17.6 | 1.1 | 0.2 | 0.1 | 0.0 |
| 2026* | 85.3 | 14.0 | 0.2 | 0.2 | 0.4 | 0.0 |
Chart 3Typical size by where the information was held
Breaches involving network servers had the largest typical size, a median of 9,962 individuals, compared with 1,500 for paper and films.
Median individuals affected per report. A report listing several locations counts under each. Locations with fewer than 50 reports are not shown.
View data table
| Location | Reports | Median individuals affected |
|---|---|---|
| Network Server | 3,690 | 9,961.5 |
| 1,851 | 3,259 | |
| Electronic Medical Record | 477 | 2,864 |
| Other | 460 | 2,560.5 |
| Desktop Computer | 380 | 2,367 |
| Laptop | 513 | 2,300 |
| Other Portable Electronic Device | 331 | 2,287 |
| Paper/Films | 1,012 | 1,500 |
Chart 4Business associates: share of breaches vs. share of people affected
Business associates were involved in 30% of reported breaches but 56% of individuals affected (47% excluding the 2024 Change Healthcare breach).
“Involved” means the reporting entity is a business associate, or the report says a business associate was present.
View data table
| Measure | Business associate involved | Not involved |
|---|---|---|
| Share of breaches | 30.0% | 70.0% |
| Share of individuals affected | 56.3% | 43.7% |
| Share of individuals affected, excluding the 2024 Change Healthcare breach | 46.9% | 53.1% |
| Median individuals affected per breach | 4,424 | 3,840 |
| Number of breaches | 2,403 | 5,604 |
Chart 5Where breaches are reported
California has the most reported breaches (786); by individuals affected, Minnesota leads (212.1 million), mostly from Change Healthcare’s 2024 breach (192.7 million individuals), which was reported there.
State of the reporting entity, not where affected individuals live. Indiana ranks 2nd by individuals affected (93.1 million, including 78.8 million from Anthem’s 2015 breach) and 12th by number of breaches (202).
View data table
| Rank | By breaches | Breaches | By individuals affected | Individuals affected |
|---|---|---|---|---|
| 1 | California | 786 | Minnesota | 212,076,397 |
| 2 | Texas | 654 | Indiana | 93,114,333 |
| 3 | New York | 516 | New Jersey | 79,985,058 |
| 4 | Florida | 471 | California | 79,958,213 |
| 5 | Illinois | 364 | Florida | 54,072,220 |
| 6 | Pennsylvania | 345 | Texas | 49,862,944 |
| 7 | Ohio | 278 | New York | 42,564,803 |
| 8 | Massachusetts | 245 | Tennessee | 39,597,433 |
| 9 | Michigan | 239 | Georgia | 38,859,277 |
| 10 | Georgia | 229 | Colorado | 29,369,166 |
About the data
- Source: the HHS Office for Civil Rights breach portal, combining the “Under Investigation” list (763 reports from the last 24 months) and the Archive (7,248 reports). Exported October 7, 2026 at 1:38 PM Arizona time; 4 exact duplicate rows removed, leaving 8,007 reports.
- The portal lists breaches of unsecured protected health information affecting 500 or more individuals, as reported by HIPAA covered entities and business associates.
- Years are based on the date a breach was submitted to HHS, not when it occurred or was discovered.
- Recent periods are incomplete. 2009 starts with the breach notification rule (effective September 2009). 2026 runs through the latest posted submission (Sep 21, 2026), and reports can take weeks to appear, so the most recent months undercount.
- Individuals affected are the counts reported by each organization and can be revised later. Adding them up counts a person once for each breach that affected them.
- State is the reporting organization’s state, not where affected individuals live.
- Reports listing more than one breach type are grouped as “Other, unknown or multiple.” A report listing several locations counts under each location.
Want a clear read on what this means for your organization?
Standing Watch Advisory helps boards and executives in healthcare and financial services turn cyber and vendor risk into decisions they can oversee with confidence.
Start a conversation