NEW: A Better Approach to HIPAA Training
View HIPAA Courses
NEW: A Better Approach to HIPAA Training
View HIPAA Courses

The HIPAA Journal is the leading provider of HIPAA training, news, regulatory updates, and independent compliance advice.

H1 2026 Healthcare Data Breach Report

There has been a 5.9% decline in healthcare breaches compared to H1 2025. Between January 1 and June 30, 2026, 397 data breaches affecting 500 or more individuals were reported to the U.S. Department of Health and Human Services (HHS) Office for Civil Rights – the lowest H1 total since 2023. While the year-over-year reduction in healthcare data breaches is a step in the right direction, healthcare data breaches continue to be reported in high numbers. In the first six months of the year, large healthcare data breaches were reported at a rate of more than 2.2 per day.

H1, 2026 Healthcare data breaches

Across the 397 reported data breaches, the protected health information of 33.77 million individuals was exposed or impermissibly disclosed. That represents a 22.6% reduction in affected individuals compared to H1 2025, and it is the lowest number of affected individuals in H1 since 2023.

H1 2026 healthcare data breaches: individuals affected

If data breaches continue to be reported at a similar rate in the second half of the year, the end-of-year healthcare data breach total is likely to be lower than 2025, which was a record-breaking year with 804 data breaches currently listed on the OCR breach portal for 2025. The current total also suggests that this year could see a major reduction in affected individuals, as more than 140 million individuals were affected in 2025. That said, several very large data breaches have yet to be added to the OCR breach portal for this year.

The Biggest Healthcare Data Breaches in H1 2026

In the first half of the year, nine healthcare data breaches were reported that affected more than 1 million individuals, the largest breach of which affected more than 5.8 million individuals. All but two of the top twenty data breaches were due to hacking incidents or ransomware attacks. The two non-hacking breaches were unauthorized access/disclosure incidents, and both occurred at state departments of human services.

Rank Regulated Entity State Covered Entity Type Individuals Affected Type of Breach
1 Lumexa Imaging NC Healthcare Provider 5,830,949 Hacking Incident
2 TriZetto Provider Solutions MO Business Associate 3,433,965 Hacking Incident
3 QualDerm Partners, LLC TN Healthcare Provider 2,951,318 Hacking Incident
4 Nacogdoches Memorial Hospital TX Healthcare Provider 2,507,073 Hacking Incident
5 Navia Benefit Solutions, Inc. WA Business Associate 2,151,330 Hacking Incident
6 Insightin Health, Inc. MD Business Associate 1,949,534 Hacking Incident
7 New York City Health and Hospitals Corporation NY Healthcare Provider 1,800,000 Hacking Incident
8 Xsolis, Inc. TN Business Associate 1,396,519 Hacking Incident
9 MCBS, LLC GA Business Associate 1,261,464 Hacking Incident
10 OpenLoop Health, Inc. IA Business Associate 716,000 Hacking Incident
11 Illinois Department of Human Services IL Health Plan 705,017 Unauthorized Disclosure Incident
12 ApolloMD Business Services, LLC GA Business Associate 626,540 Hacking Incident (Ransomware)
13 Erie Family Health Centers IL Healthcare Provider 570,000 Hacking Incident
14 Centers Lab NJ LLC NJ Healthcare Provider 542,377 Hacking Incident
15 Networking Technology, Inc. (RXNT) NC Business Associate 353,844 Hacking Incident
16 Minnesota Department of Human Services MN Health Plan 303,965 Unauthorized Access Incident
17 North Texas Behavioral Health Authority TX Healthcare Provider 285,086 Hacking Incident
18 Florida Physician Specialists FL Healthcare Provider 276,498 Hacking Incident
19 Radiology Associates of Richmond VA Healthcare Provider 266,183 Hacking Incident
20 Anatomic and Clinical Laboratory Associates, P.C. TN Healthcare Provider 169,626 Hacking Incident

The majority of the data breaches reported in H1 2026 were relatively small, affecting fewer than 10,000 individuals. Currently, 37 healthcare data breaches are listed as affecting 500 or 501 individuals. These are commonly used placeholder figures when data reviews are incomplete by the breach reporting deadline. The majority of those 37 data breaches are likely to see the totals increased, potentially significantly. The Change Healthcare data breach in 2024 was initially reported to OCR as affecting at least 500 individuals but was subsequently increased to 192.7 million individuals!

Scale of Breach – Affected Individuals Data Breaches
Over 1,000,000 9
100,000 – 999,999 21
10,000 – 99,999 102
1000 – 9,999 175
Under 1000 90

Causes of H1 2026 Healthcare Data Breaches

While the number of large healthcare data breaches has fallen year-over-year, the lower H1 figures this year are due to fewer unauthorized access/disclosure and loss/theft incidents, rather than hacking/IT incidents, which increased for the third consecutive year.

H1 Healthcare data breach causes 2022-2026

H1 2026 Hacking/IT Incidents

Hacking/IT incidents remain the leading cause of healthcare data breaches and increased again in 2026. Ransomware groups continue to attack the healthcare sector, and there has been an increasing trend of data theft and extortion incidents, where data is stolen and threats are issued to publish the stolen data, but files are not encrypted.

As also observed by the Identity Theft Resource Center, there has been a growing trend of breached entities failing to disclose the nature of data breaches, including the cause, whether ransomware was involved, and, concerningly, if data was stolen in the incident. The lack of a breach cause makes it difficult to assess trends, while the failure to disclose whether data has been stolen makes it difficult for individuals to gauge the level of risk they face.

In H1, 343 hacking/IT incidents were reported, affecting an average of 94,167 individuals (median breach size: 4,800 individuals). Hacking/IT incidents have increased by 2.1% year-over-year increase in hacking/IT incidents, although the number of affected individuals has reduced by 14.7% year-over-year.

H1 2026 individuals affected by healthcare hacking/IT incidents

H1 2026 Unauthorized Access/Disclosure Incidents

Unauthorized access and disclosure incidents were the second leading cause of healthcare data breaches in H1 2026. These incidents include any unauthorized access to and disclosure of patient records that are not hacking- or IT-related. They include snooping incidents by insiders, misdirected emails and mailings, and unauthorized data sharing between HIPAA-regulated entities and third parties.

These incidents tend to affect far fewer individuals than hacking and IT incidents, although not always. Incidents involving website tracking tools such as pixels, for example, can affect millions of individuals. The two largest unauthorized access/disclosure incidents made it into the top 20 largest breaches of the first half of the year and occurred at the Illinois Department of Human Services and Minnesota Department of Human Services. The former involved data uploaded to a website for internal use that was accessible via the public internet, and the latter involved a user associated with an authorized healthcare provider accessing data without authorization.

In H1, 51 unauthorized access/disclosure incidents were reported, affecting an average of 28,710 individuals (median breach size: 2,315 individuals).  That represents a 3.8% year-over-year decline in unauthorized access/disclosure incidents, and a 74.2% decline in affected individuals.

H1 2026 individuals affected by healthcare unauthorized access/disclosure

H1 2026 Loss/Theft Incidents

Loss and theft of electronic devices containing protected health information and paper records used to be a leading cause of data breaches; however, the adoption of digital records, data encryption, and cloud storage of protected health information has helped reduce these incidents. In H1 2026, only two such incidents were reported – one loss and one theft incident, both involving a relatively small number of paper records. That equates to a 75% year-over-year reduction in data breaches, and a 96.7% reduction in affected individuals.

H1 2026 individuals affected by healthcare unauthorized loss/theft incidents

H1, 2026 Improper Disposal Incidents

Improper disposal incidents are rarely reported, and when they are, they almost always involve paper records inadvertently disposed of with regular trash. Only one such incident was reported by a HIPAA-regulated entity in H1 2026 – a relatively small data breach affecting an estimated 1,000 individuals. A single improper disposal incident was also reported in H1 2025, althopugh the number of affected individuals has fallen by 97% year-over-year.

H1 2026 individuals affected by healthcare unauthorized improper disposal incidents

Data Breaches at HIPAA Regulated Entities

Healthcare providers were the worst affected HIPAA-regulated entities in H1 2026 (290 data breaches), followed by business associates (59 data breaches), and health plans (48 data breaches). Healthcare clearinghouses survived the first 6 months of the year without any data breaches. The same order applies in terms of individuals affected by those breaches, with healthcare providers topping the list (19,701,297 individuals), followed by business associates (12,505,090 individuals), and health plans (1,559,474 individuals).

Those figures do not tell the full story, as when a data breach occurs at a business associate, it is not always the business associate that reports the data breach. When a data breach occurs at a business associate, the business associate must notify each affected covered entity, and the covered entity may delegate the reporting and notification requirements to the business associate or may choose to report the data breach and/or send notification letters themselves. If a breach occurs at a business associate, some affected covered entities may delegate the reporting and notification responsibilities to the business associates while others may not. As such, business associate data breaches are often underrepresented in the raw breach data.

The charts below are based on where the data breach occurred, rather than the reporting entity. While the same order applies to both data breaches and affected individuals, almost 100 more breaches occurred at business associates than the raw data suggests.

H1 2026 healthcare data breaches at HIPAA-regulated entities

H1 2026 healthcare data breaches at HIPAA-regulated entities - individuals affected

Based on the adjusted data, the average size of a data breach at a healthcare provider (87,629 individuals) and a business associate (87,643 individuals) was virtually identical, although the median size of a data breach at a healthcare provider (6,323 individuals) is twice that of a business associate (3,086 individuals). In H1 2026, health plan breaches were less severe. The average breach size was less than half the size at other entities at 41,042 individuals, and the median breach size was 2,871 individuals.

Location of Breached Protected Health Information

Given the high number of hacking incidents, it is unsurprising that the most common location of breached protected health information is network servers, as has been the case for several years. Email remains a common location of breached healthcare data due to a relatively high prevalence of phishing and social engineering incidents. While not infallible, multifactor authentication would have prevented many of these data breaches.

A small but significant number of healthcare data breaches involved paper records, although the number of incidents involving physical records is falling. Breaches of protected health information in “other” locations – including the cloud – are on the rise.  Widespread adoption of encryption and use of the cloud have helped to drastically reduce the number of loss and theft incidents.

H1 2026 healthcare data breaches: location of breached protected health information

Geographic Distribution of Healthcare Data Breaches

In H1 2026, large healthcare data breaches were reported by HIPAA-regulated entities in 44 U.S. states, the District of Columbia, and Puerto Rico. The only states to escape the first half of the year unscathed were Hawaii, Montana, New Mexico, North Dakota, South Dakota, and Wyoming.

As a general rule, the states with the biggest populations experience the most data breaches, and vice versa for the states with the fewest number of breaches. California, Texas, Florida, and New York are the most heavily populated states in that order, and the same order applies in H1 2026 in terms of data breaches.

Rank State Data Breaches State Individuals Affected
1 California 38 North Carolina 6,358,110
2 Texas 36 Tennessee 4,635,531
3 Florida 24 Missouri 3,468,743
4 New York 20 Texas 3,188,111
5 Illinois 16 Washington 2,270,117
6 Michigan 15 New York 2,113,172
7 North Carolina 14 Georgia 2,005,142
8 Pennsylvania 13 Maryland 1,968,198
9 Washington 13 Illinois 1,756,341
10 Massachusetts 12 Florida 846,997
11 Colorado 11 Iowa 767,730
12 Tennessee 11 New Jersey 702,065
13 Virginia 11 Minnesota 486,202
14 Minnesota 10 Virginia 458,060
15 Ohio 10 California 430,336
16 Georgia 9 Colorado 324,483
17 Indiana 9 South Carolina 318,963
18 Kentucky 9 Pennsylvania 213,188
19 Maryland 9 Michigan 207,522
20 New Jersey 9 Ohio 139,151
21 Oklahoma 9 Connecticut 133,735
22 South Carolina 8 Puerto Rico 116,236
23 Alabama 7 Alabama 103,406
24 Connecticut 7 Kentucky 89,363
25 Missouri 7 Utah 82,335
26 Iowa 6 Arizona 76,546
27 Oregon 6 Idaho 66,625
28 Utah 6 Massachusetts 66,382
29 Idaho 5 Mississippi 60,133
30 Kansas 5 Indiana 49,271
31 Maine 5 Maine 45,932
32 Louisiana 4 Kansas 40,760
33 Arizona 3 Louisiana 37,963
34 District of Columbia 3 Nevada 37,796
35 Arkansas 2 Nebraska 26,937
36 Mississippi 2 District of Columbia 21,481
37 Puerto Rico 2 Oklahoma 18,392
38 West Virginia 2 Oregon 10,278
39 Wisconsin 2 Vermont 5,892
40 Alaska 1 Arkansas 5,800
41 Delaware 1 Rhode Island 5,630
42 Nebraska 1 Wisconsin 2,654
43 Nevada 1 West Virginia 1,500
44 New Hampshire 1 New Hampshire 1,221
45 Rhode Island 1 Delaware 908
46 Vermont 1 Alaska 523

HIPAA Enforcement Activity in H1 2026

OCR has increased the number of penalties imposed for HIPAA violations in recent years, although financial penalties are still relatively rare. OCR investigates all data breaches affecting 500 or more individuals, and when potential HIPAA violations are identified, they are typically resolved through voluntary compliance or by providing technical assistance.

Financial penalties are typically reserved for egregious or particularly impactful HIPAA violations, when there has been a history of noncompliance, and when OCR has an enforcement initiative targeting a specific aspect of the HIPAA regulations. Currently, OCR has two main enforcement initiatives, one targeting noncompliance with the HIPAA Right of Access of the HIPAA Privacy Rule, and another targeting noncompliance with the risk analysis implementation specification of the HIPAA Security Rule.

The HIPAA Right of Access enforcement initiative has been active since late 2019 and has resulted in more than 55 financial penalties. The risk analysis enforcement initiative is more recent and was formally launched in October 2024 in response to widespread noncompliance with this specific security rule provision and its importance for cybersecurity. To date, OCR has imposed 14 financial penalties under this initiative. The risk analysis enforcement initiative has been expanded this year to include risk management. In addition to demonstrating that a HIPAA-compliant risk analysis has been conducted, OCR requires evidence that the identified risks have been properly managed and reduced to a low and acceptable level in a reasonable time frame.

Between January 1 and June 30, 2026, OCR announced seven settlements to resolve alleged violations of the HIPAA Rules, all seven of which included a financial penalty for a risk analysis violation. While OCR has not announced a specific initiative targeting noncompliance with the HIPAA Breach Notification Rule, two of the seven penalties this year included a fine for breach notification failures. Five of the fourteen penalties imposed in 2025 also included penalties for breach notification failures, which suggests OCR is paying close attention to the time taken to issue breach notifications to OCR, the affected individuals, and the media.

H1 2026 HIPAA Settlements and Civil Monetary Penalties

Covered Entity Type of Entity Amount Settlement / Civil Monetary Penalty Reason
Spencer Gifts LLC Flexible Benefits and Welfare Benefit Plans Health Plan $450,000 Settlement Risk analysis failure; failure to implement Privacy, Security, and Breach Notification Rule policies and procedures.
Regional Women’s Health Group (Axia Women’s Health) Healthcare Provider $320,000 Settlement Risk analysis failure; impermissible disclosure of the ePHI of 10,023 individuals.
Assured Imaging Affiliated Covered Entities Healthcare Provider $375,000 Settlement Risk analysis failure (never conducted); breach notification failure.
Consociate, Inc. (Consociate Health) Business Associate $225,000 Settlement Risk analysis failure.
Star Group, L.P. Health Benefits Plan Health Plan $245,000 Settlement Risk analysis failure.
MMG Fusion Business Associate $10,000 Settlement Risk analysis failure; impermissible use/disclosure of PHI; breach notification rule failure.
Top of the World Ranch Treatment Center Healthcare Provider $103,000 Settlement Risk analysis failure

OCR is the main enforcer of the HIPAA Rules, although state attorneys general are also authorized to enforce HIPAA compliance and can impose financial penalties in their respective states. In H1 2026, only one penalty was announced at the state level. Massachusetts and Connecticut participated in a joint investigation of Comstar LLC over a data breach affecting 585,621 individuals (326,426 Massachusetts residents & 22,829 Connecticut residents). The investigation identified violations of the HIPAA Security Rule and the Massachusetts Data Security Regulations. The case was settled with a $515,000 financial penalty.

HIPAA Regulatory Updates

There were no new updates to the HIPAA Rules in the first half of 2026, although there are two pending final rules. During President Trump’s first term in December 2020, OCR proposed an update to the HIPAA Privacy Rule to support coordinated care and improve individual engagement in healthcare. The proposed rule was formally introduced in the Federal Register in January 2021, but a final rule stalled, as OCR had other priorities under the Biden Administration. The return of President Trump for a second term has seen the proposed rule rekindled. OCR set a target of August 2026 for the release of a final rule, although it has yet to be issued.

The other pending final rule is for proposed changes to the HIPAA Security Rule. A notice of proposed rulemaking was announced by OCR in the final days of the Biden administration in late December 2024 and was published in the Federal Register on January 6, 2025. OCR received several thousand comments from industry stakeholders about the proposed changes, including a significant amount of criticism. OCR set a target release date of May 2026 for a final rule; however, it has now been pushed back until July 2027, although a final decision about whether to issue a final rule has yet to be made by the Trump administration.

While there were no new HIPAA updates in H1 2026, the compliance date for updates to the HIPAA Notice of Privacy Practices requirements was February 16, 2026 – the only surviving part of the now vacated HIPAA update to strengthen reproductive healthcare privacy. The Notice of Privacy Practices compliance deadline aligned with the compliance deadline for changes to the 42 CFR Part 2 regulations concerning substance use disorder (SUD) patient records to align those regulations more closely with HIPAA.

About this Report

This report is based on healthcare data breaches affecting 500 or more individuals that were reported to the HHS’ Office for Civil Rights in H1 2026. The data for this report was obtained from OCR on September 10, 2026, and includes supplemental information from data breach reporting from the HIPAA Journal.

You can view more comprehensive healthcare data breach facts and statistics from 2009 to the present on our data breach statistics page, and more comprehensive and up-to-date information on HIPAA enforcement actions on our HIPAA violation cases page, both of which are regularly updated. Information on the latest regulatory changes can be found on our HIPAA Updates/HIPAA Changes page.

Author: Steve Alder is the editor-in-chief of The HIPAA Journal. Steve is responsible for editorial policy regarding the topics covered in The HIPAA Journal. He is a specialist on healthcare industry legal and regulatory affairs, and has 10 years of experience writing about HIPAA and other related legal topics. Steve has developed a deep understanding of regulatory issues surrounding the use of information technology in the healthcare industry and has written hundreds of articles on HIPAA-related topics. Steve shapes the editorial policy of The HIPAA Journal, ensuring its comprehensive coverage of critical topics. Steve Alder is considered an authority in the healthcare industry on HIPAA. The HIPAA Journal has evolved into the leading independent authority on HIPAA under Steve’s editorial leadership. Steve manages a team of writers and is responsible for the factual and legal accuracy of all content published on The HIPAA Journal. Steve holds a Bachelor’s of Science degree from the University of Liverpool. You can connect with Steve via LinkedIn or email via stevealder(at)hipaajournal.com

x

Is Your Organization HIPAA Compliant?

Find Out With Our Free HIPAA Compliance Checklist

Get Free Checklist