Healthcare Data Breach Statistics – Updated for 2026
The HIPAA Journal has compiled healthcare data breach statistics from October 2009, when the Department of Health and Human Services (HHS) Office for Civil Rights (OCR) started publishing summaries of healthcare data breaches on its website. This page is regularly updated to reflect the latest healthcare data breach statistics. These statistics and graphs were last updated on September 8, 2026, and are based on breach data obtained from OCR on September 4, 2026. The data covers the period from October 21, 2009 through June 30, 2026. Check back regularly to get the latest healthcare data breach statistics and healthcare data breach trends. You can view our 2025 healthcare data breach report here. You can also receive a free copy of our HIPAA Compliance Checklist to understand your organization’s responsibilities under HIPAA. Trends In Healthcare Data Breach Statistics Our healthcare data breach statistics clearly show an upward trend in data breaches since 2009, when OCR first started publishing data breach summaries on its website, peaking in 2026, when 772 healthcare data...
Five Healthcare Providers Report Ransomware-Related Data Breaches
Data breaches have been confirmed by Alta Orthopaedics in California, Cornerstone Behavioral Healthcare in Maine, Cameron Regional Medical Center in Missouri, Suntree Internal Medicine in Florida, and Associated Endocrinologists in Michigan. Ransomware groups have claimed responsibility for the attacks. Alta Orthopaedics Medical Group, California Alta Orthopaedics, a specialty medical practice with locations in Santa Barbara, Solvang, Santa Maria, and Oxnard, California, has recently confirmed that the protected health information of 24,496 individuals was exposed and potentially stolen in a cybersecurity incident earlier this year. Unusual network activity was identified on March 10, 2026, and the investigation determined that an unauthorized third party had accessed information on its network between February 3, 2026, and February 6, 2026. The review of the affected data was completed on June 24, 2026. Personally identifiable information potentially compromised in the incident included names, contact information, Social Security numbers, driver’s licence numbers/state ID numbers,...
Multi-Million Settlement Resolves Managed Care of North America Data Breach Litigation
Managed Care of North America, Inc. (MCNA) has agreed to settle class action litigation stemming from a 2023 cybersecurity incident that affected around 8.9 million individuals. MCNA is a provider of dental insurance in Florida, and a third-party administrator of dental benefits in other states and Puerto Rico. MCNA’s subsidiaries include MCNA Dental, MCNA Insurance Company, and Healthplex. The cybersecurity incident was identified on March 6, 2023, and the forensic investigation determined that an unauthorized third party accessed its network between February 22, 2023, and March 7, 2023, and potentially viewed or obtained private information. The investigation confirmed that sensitive data was exfiltrated from its network. The compromised data included names, addresses, telephone numbers, email addresses, birth dates, Social Security numbers, driver’s license numbers, government-issued ID numbers, health insurance information, Medicare/Medicaid ID numbers, group plan names and numbers, and information related to the dental and orthodontic care provided. Notification letters...
Baylor Genetics: ePHI of 2.8M Patients Exposed in Cybersecurity Incident
On August 19, 2026, we reported on a cybersecurity incident at the clinical genomics company Baylor Genetics. At the time, it was clear that this was a significant breach, based on reports submitted to state attorneys general; however, the scale of the breach was unknown. The Baylor Genetics data breach has recently been added to the HHS’ Office for Civil Rights website, which shows that the electronic protected health information (ePHI) of 2,810,878 individuals was exposed or stolen in the incident. August 19, 2026: Patient & Employee Data Exposed in Baylor Genetics Cybersecurity Incident Baylor Genetics, a clinical diagnostic genomics company, has recently disclosed a cybersecurity incident that has exposed patient and employee data. The incident was first announced in June; however, the extent of the data breach was unclear at the time. Baylor Genetics provides genetic testing services to hospitals and is headquartered at the Texas Medical Center in Houston. The company identified suspicious activity within its computer network on or around June 15, 2026. Immediate...
Nutex Health Confirms Sensitive Data Stolen in August Cyberattack
Nutex Health, a Houston, Texas-based healthcare management and operations company that delivers care through 27 micro-hospitals, specialty hospitals, and outpatient departments in 12 U.S. states, has disclosed a cyberattack involving the exfiltration of data from some of its servers. Nutex is currently investigating the incident to determine the extent of data theft, including whether provider, employee, or patient data were exposed or stolen. The incident was disclosed in an August 24, 2026, Item 8.01 Form 8-K filing with the U.S. Securities and Exchange Commission (SEC). Nutex explained that it recently learned of unauthorized activity related to data stored on its computer network. The company activated its incident response plan, implemented containment measures, and engaged an independent third-party cybersecurity response team and forensics experts to assist with the investigation and determine the extent to which data was exposed or stolen. Per that filing, Nutex said the incident is still being assessed, and it has yet to determine whether private and confidential data was...



