Hacking Group Claims Responsibility for Multi-Million-Record DentaQuest Data Breach
Wellesley, MA-based DentaQuest, a dental benefits administrator that manages the benefits for 32 million Americans, has announced it is actively managing a cybersecurity incident involving unauthorized access to a limited part of its network. According to its website notice, immediate action was taken to contain and mitigate the threat, and the company is working with a leading cybersecurity expert, forensic investigators, and law enforcement authorities. If the data breach is confirmed as affecting 2.6 million individuals, it will rank as one of the largest healthcare data breaches of the year to date. DentaQuest, part of Sun Life U.S. Dental, is the largest Medicaid and Children’s Health Insurance Program dental benefits administrator in the country, operating in 50 U.S. states. The company has yet to determine the exact scope of the incident and the extent to which sensitive data has been compromised. The company has promised to update clients and ensure that they receive information as quickly and transparently as possible. The digital extortion group ShinyHunters has claimed...
Onsite Women’s Health $2.5M Data Breach Settlement
A breach of the email account of an employee of Onsite Women’s Health that exposed the protected health information of 357,265 individuals has resulted in a $2,525,000 settlement. Onsite Mammography, LLC, which does business as Onsite Women’s Health, a Westfield, Massachusetts-based provider of medical imaging services to hospitals, identified unauthorized access to an employee’s email account in October 2024. The email account was compromised as a result of a response to a phishing email, and while the account was only accessible for a short period of time, sensitive data was exfiltrated, including names, dates of birth, Social Security numbers, driver’s license numbers, credit card numbers, and information related to patients’ mental or physical conditions, and any care they received. Multiple class action lawsuits were filed in response to the data breach, which were consolidated – Clarkson, et al. v. Onsite Mammography, LLC, d/b/a Onsite Women’s Health – in the United States District Court District of Massachusetts. The consolidated lawsuit alleged that inadequate...
Conduent Business Services Data Breach Affected More Than 62.2 Million Individuals
In January 2025, news first surfaced about a massive data breach at Conduent Business Services, a vendor that provides printing, mailing, document processing, payment integrity, and other back-office services to healthcare providers, health plans, and government agencies. Conduent first identified the security breach on January 13, 2025; however, the forensic investigation determined that hackers had access to its computer network for three months, starting on October 21, 2024. At the time, the true scale of the breach was unknown. Based on breach reports submitted to the state attorneys general in Oregon and Texas, at least 25 million Americans were known to have been affected in those states alone; however, the full scale of the breach has only recently been confirmed. Conduent has provided an updated total to the Department of Health and Human Services Office for Civil Rights (OCR), indicating that the protected health information of at least 62,224,658 individuals was compromised in the incident. When a data breach occurs at a business associate of a HIPAA-covered entity, it is...
Clarinda Regional Health Center Reports Data Breach Affecting 24K Patients
Data breaches have been announced by Clarinda Regional Health Center in Iowa, Community Connections in DC, Waveny Lifecare Network in Connecticut, and NJ Pain Care Specialists in New Jersey. Clarinda Regional Health Center Clarinda Regional Health Center, a Clarinda, IA-based non-profit hospital, has started notifying 24,341 individuals about a recent cybersecurity incident that exposed sensitive data. Suspicious activity was identified within its computer network on December 15, 2026, and the forensic investigation determined that files containing patient data may have been accessed or acquired without authorization in October 2025. The LockBit5 ransomware group claimed responsibility for the incident. The file review confirmed that the exposed data included first and last names, dates of birth, medical information, health insurance information, financial account numbers, Social Security numbers, driver’s license numbers, and taxpayer identification numbers. The types of data varied from individual to individual. The review of the affected files was completed on May 21, 2026, and...
Healthcare Data Breach Statistics – Updated for 2026
The HIPAA Journal has compiled healthcare data breach statistics from October 2009, when the Department of Health and Human Services (HHS) Office for Civil Rights (OCR) started publishing summaries of healthcare data breaches on its website. This page is regularly updated to reflect the latest healthcare data breach statistics. These statistics and graphs were last updated on June 4, 2026, and are based on data obtained from OCR up to and including May 19, 2026. Check back regularly to get the latest healthcare data breach statistics and healthcare data breach trends. You can view our 2025 healthcare data breach report here. You can also receive a free copy of our HIPAA Compliance Checklist to understand your organization’s responsibilities under HIPAA. Trends In Healthcare Data Breach Statistics Our healthcare data breach statistics clearly show an upward trend in data breaches since 2009, when OCR first started publishing data breach summaries on its website, peaking in 2026, when 772 healthcare data breaches affecting 500 or more individuals were reported to OCR. There...



