HIPAA Compliance News

June 2026 Healthcare Data Breach Report

In June 2026, 66 large healthcare data breaches – data breaches involving the protected health information of 500 or more individuals – were reported to the U.S. Department of Health and Human Services (HHS) Office for Civil Rights (OCR) – a slight increase from the 64 data breaches reported in May. More than two large data breaches a day is the new normal. Over the past 12 months, an average of 65 large healthcare data breaches have been reported per day; eight years ago in 2018, large healthcare data breaches occurred at a rate of around one per day.

Large Healthcare data breaches in the past 12 months - June 2026

The year-to-date figures (Jan 1-Jun 30) show that healthcare data breaches are down 3.2% from the corresponding period in 2024 and down 6.4% from the corresponding period last year, although they are still occurring in significantly higher numbers than in 2022 and 2023.

Year to date figures for large healthcare data breaches - June 2026

Across June’s 66 large healthcare data breaches, the protected health information of at least 4,499,972 individuals was exposed, stolen, or impermissibly disclosed. As data breach investigations continue, that figure is likely to increase. Based on current data, on average, 68,181 individuals were affected by each breach. The median data breach size was 6,306 individuals. While June’s victim total is substantial, the victim count is down 36.3% month-over-month, and 58.7% lower than the 12-month average of 10,906,096 individuals per month. It should be noted that the 12-month average is skewed by an unusually high total for October 2025.

Individuals affected by large healthcare data breaches in the past 12 months - June 2026

The year-to-date figures for 2026 show a substantial improvement compared to recent years, and while almost 34 million individuals have had their protected health information exposed, stolen, or impermissibly disclosed so far in 2026, the victim count is down 37.7% from a high of 54.4 million individuals in 2024, and down 22.1% from 2025.

Get The FREE
HIPAA Compliance Checklist

Immediate Delivery of Checklist Link To Your Email Address

Please Enter Correct Email Address

Your Privacy Respected

HIPAA Journal Privacy Policy

Year to date figures for individuals affected by healthcare data breaches - June 2026

The Biggest Healthcare Data Breaches Reported in June 2026

In June, 25 healthcare data breaches affecting 10,000 or more individuals were reported to the HHS. The two largest data breaches of the month occurred at business associates of HIPAA-covered entities, the largest of which was reported by Xsolis and affected almost 1.4 million individuals. Xsolis is a technology company that provides healthcare organizations with AI-powered solutions for case and utilization management. The incident occurred in January 2026 and started with a phishing email. The phishing attack provided the threat actor with access to systems and data for four days. Files exposed in the incident contained names, dates of birth, Social Security numbers, health insurance information, and medical treatment information.

The second-largest data breach of the month occurred at MCBS (Medical Computer Business Services) and affected more than 1.25 million individuals. MCBS is a healthcare billing, management, and revenue cycle management company. A data theft and extortion group called PEAR breached its network, exfiltrated files, and demanded a ransom to prevent the publication of the data. The threat group had access to the network for four days in September 2025 and stole files containing names, addresses, dates of birth, Social Security numbers, medical histories, health insurance information, and other sensitive data.

A significant breach was reported by the New Jersey-based Centers Lab NJ, a diagnostic testing laboratory for hospitals and other healthcare providers. This was also a data theft and extortion incident, involving the protected health information of more than 542,000 individuals. A threat group called Worldleaks claimed responsibility for the incident and had access to its network for 5 days in August 2025. Data stolen in the incident included names, dates of birth, Social Security numbers, passport numbers, driver’s license number/state ID numbers, medical information, and health insurance information.

HIPAA-Regulated Entity State Covered Entity Type Individuals Affected Cause of Breach
Xsolis, Inc. TN Business Associate 1,396,519 Network server hacking incident
MCBS, LLC GA Business Associate 1,261,464 Data theft and extortion incident (PEAR)
Centers Lab NJ LLC NJ Healthcare Provider 542,377 Data theft and extortion incident (Worldleaks)
Anatomic and Clinical Laboratory Associates, P.C. TN Healthcare Provider 169,626 Network server hacking incident
Operation PAR, Inc. FL Business Associate 145,714 Data theft and extortion incident (Worldleaks)
Chicago Family Health Center IL Healthcare Provider 90,000 Network server hacking incident
Aitkin County Health and Human Services MN Business Associate 83,114 Phishing incident
Minnesota Epilepsy Group, P.A. MN Healthcare Provider 80,061 Network server hacking incident
Gay & Lesbian Community Services Center of Orange County, Inc. CA Healthcare Provider 75,532 Network server hacking incident
Colorado Health Network Inc. CO Healthcare Provider 68,212 Network server hacking incident – data theft confirmed
Women’s Center for Radiology FL Healthcare Provider 66,422 Network server hacking incident
Blue Fish Pediatrics TX Healthcare Provider 62,150 Network server hacking incident
NYC Health + Hospitals NY Healthcare Provider 58,778 Hacking incident at business associate
UnitedHealth Care Services, Inc. Single Affiliated Covered Entity CT Health Plan 37,384 Phishing incident at business associate
UnitedHealth Care Services, Inc. Single Affiliated Covered Entity CT Health Plan 34,574 Network server hacking incident
Kentucky Mountain Health Alliance KY Healthcare Provider 30,830 Network server hacking incident – data theft confirmed
Center for Hearing and Speech dba Texas Hearing Institute TX Healthcare Provider 29,774 Ransomware attack (Interlock) – data theft confirmed
Waveny LifeCare Network, Inc. CT Healthcare Provider 27,113 Network server hacking incident
Elara Caring TX Healthcare Provider 22,172 Hacking incident at third party vendor – data theft confirmed
Minidoka Memorial Hospital ID Healthcare Provider 22,000 Data theft and extortion incident (Blackwater)
Meridian Health Plan of Illinois IL Health Plan 21,027 Employee errors – Impermissible granting certain providers access to its network
City of Middletown OH Healthcare Provider 20,608 Ransomware attack – data theft confirmed
McLeod Physician Associates II SC Healthcare Provider 19,553 Malware identified on network server awaiting decommissioning
Optalis Management Solutions MI Healthcare Provider 13,723 Network server hacking incident
All About Women’s Care CO Healthcare Provider 12,000 Hacking incident via an employee VPN account – data theft confirmed

In June, nine healthcare data breaches were reported to HHS with totals of 500 or 501 affected individuals. These totals are often used as placeholder figures when data reviews are ongoing and the 60-day reporting deadline under the HIPAA Breach Notification Rule is reached. HIPAA requires an estimate to be provided if the total number of affected individuals has yet to be determined. The data breaches in the table below may prove to be far larger than the initial breach report indicates. It may be several weeks or even months before the total number of affected individuals is confirmed.

HIPAA Regulated Entity State Covered Entity Type Individuals Affected Cause of Breach
Gail J May Ltd d/b/a/ Insight Optical IL Healthcare Provider 501 Network server hacking incident at business associate
Community Health Center of Buffalo Inc. NY Healthcare Provider 501 Network server hacking incident
Cherry Street Services, Inc. MI Healthcare Provider 501 Network server hacking incident
Northeast Professional Caregivers OH Healthcare Provider 500 Email compromise
Columbia Orthopaedic Group MO Healthcare Provider 500 Network server hacking incident
Decatur Diagnostic Laboratory Inc. AL Healthcare Provider 500 Network server hacking incident
Ohio Living OH Healthcare Provider 500 Network server hacking incident
Signature Healthcare Corporation MA Healthcare Provider 500 Network server hacking incident
MVP VIP Holdco dba Heart of America Eye Care MO Healthcare Provider 500 Network server hacking incident

Causes of June 2026 Healthcare Data Breaches

Out of the 25 data breaches affecting 10,000 or more individuals, all but one was due to hacking. Across all of June’s reported data breaches, 81.8% of the breaches were hacking/IT incidents, and 1,481,468 individuals were affected by those incidents – 89.7% of all individuals affected by data breaches in June. The average breach size was 81,091 individuals, and the median breach size was 6,504 individuals.

Causes of June 2026 healthcare data breaches

The largest unauthorized access/disclosure incident of the month – Meridian Health Plan of Illinois – affected 21,027 individuals and was due to employees granting healthcare providers access to a portal for managing patient information and processing claims that should not have been given access. There were 11 unauthorized access/disclosure incidents in June, accounting for 16.7% of the month’s data breaches, and 10,914 individuals were affected – 2.7% of the month’s affected individuals. The average breach size was 10,914 individuals, and the median breach size was 6,721 individuals. One improper disposal incident was reported affecting an estimated 1,000 patients. Paper records were disposed of along with regular trash, rather than being sent for shredding. No loss or theft incidents were reported in June.

Location of Breached Protected Health Information

The bar chart below shows the locations of breached protected health information in June 2026 healthcare data breaches. Network servers were the most common location of breached protected health information, followed by email accounts and electronic health records.

Location of breached protected health information - June 2026

Data Breaches at HIPAA Regulated Entities

When a data breach occurs at a HIPAA-covered entity – healthcare provider, health plan, or healthcare clearinghouse – the HIPAA Breach Notification Rule requires them to report the breach within 60 days of discovery. When a data breach occurs at a business associate of a HIPAA-covered entity, the business associate must notify each affected covered entity within the same time frame.

The affected covered entities are ultimately responsible for ensuring that notifications are issued to the HHS, individuals, and in some cases the media, within 60 days of being notified. A HIPAA-covered entity may delegate the notification responsibilities to the business associate. Some choose to issue notifications themselves. The raw breach data on the OCR breach portal shows data breaches based on the reporting entity, not where the data breach occurred. In June, healthcare providers reported 45 breaches, business associates reported 14 breaches, and 7 breaches were reported by health plans. The pie charts below show where the breach actually occurred rather than the reporting entity to better reflect breaches at business associates.

June 2026 data breaches at HIPAA-regulated entities

Individuals affected by June 2026 data breaches at HIPAA-regulated entities

Geographical Distribution of Healthcare Data Breaches

In June, HIPAA-regulated entities based in 24 U.S. states reported large healthcare data breaches. Florida and Texas were the worst affected states with seven reported breaches per state.

State Breaches
Florida & Texas 7
Illinois 5
Colorado, Michigan & New York 4
California, Connecticut, Minnesota, Missouri, Ohio & Tennessee 3
Idaho, Kentucky, Massachusetts, South Carolina & Washington 2
Alabama, Georgia, Indiana, Kansas, New Jersey, Oklahoma & Pennsylvania 1

While Florida and Texas ranked top for breaches, they ranked 4th and 6th in terms of the number of affected individuals. Tennessee, Georgia, and New Jersey topped the list for affected individuals, with each state only registering one large data breach.

State Individuals Affected State Individuals Affected
Tennessee 1,567,038 Michigan 24,396
Georgia 1,261,464 Idaho 22,750
New Jersey 542,377 Ohio 21,608
Florida 233,367 South Carolina 20,690
Minnesota 164,893 Washington 9,825
Texas 124,459 Missouri 3,311
Illinois 120,089 Indiana 3,070
Connecticut 99,071 Pennsylvania 2,720
Colorado 87,814 Oklahoma 1,607
California 80,783 Massachusetts 1,506
New York 74,733 Kansas 534
Kentucky 31,367 Alabama 500

HIPAA Enforcement Activity in June 2026

In June, OCR announced a single enforcement action to resolve potential violations of the HIPAA Rules by the American mall-based retailer, Spencer Gifts. Retailers are not typically HIPAA-covered entities, but Spencer Gifts is a health plan under HIPAA as it sponsors employee benefits and welfare benefit plans. Spencer Gifts was investigated after OCR received a report about a breach of the protected health information of 10,023 members of its flexible benefits and welfare benefit plans. The OCR investigation determined that Spencer Gifts failed to conduct a HIPAA-compliant risk analysis and failed to implement HIPAA Privacy, Security, and Breach Notification Rule policies and procedures. The alleged HIPAA violations were resolved with a settlement that includes a $450,000 financial penalty and a corrective action plan.

In the year to June 30, 2026, OCR resolved seven HIPAA investigations with financial penalties with penalties totaling $1,728,000. All seven of the investigations found risk analysis failures, and two involved breach notification failures. State attorneys general may also investigate data breaches and impose financial penalties for HIPAA violations, although no cases were announced in June 2026.

About this Report

The HIPAA Journal monthly data breach reports are based on data obtained from the HHS Office for Civil Rights and have been combined with breach report data from other sources. The data breaches included in this report were reported in June 2026 but occurred weeks or months previously. The figures in this report may increase or decrease as HIPAA-regulated entities complete their breach investigations, and will be reflected in our healthcare data breach statistics page and our annual HIPAA data breach reports. Further information about HIPAA enforcement actions can be found in our HIPAA violations cases page.

The post June 2026 Healthcare Data Breach Report appeared first on The HIPAA Journal.

Azul Vision Settles HIPAA Right of Access Case for $50,000

The Department of Health and Human Services (HHS) Office for Civil Rights (OCR) has announced its 9th financial penalty of the year to resolve an alleged violation of the HIPAA Rules, and its 55th penalty under its HIPAA Right of Access enforcement initiative.

Azul Vision Inc. is a California-based provider of optometry and ophthalmology services. OCR launched an investigation in response to a complaint from a patient who alleged that she had not been provided with timely access to her medical records. The complaint was filed with OCR in April 2023, three months after the patient submitted a request to Azul Vision for a copy of her health information. She did not receive the requested records until January 2025 – two years after her request was submitted.

The HIPAA Privacy Rule gives patients the right to timely access to their medical records for a reasonable, cost-based fee. When a healthcare provider receives a request from a patient wishing to exercise that right, the healthcare provider has 30 days from receipt of the request to provide the requested records, although under certain circumstances, a 30-day extension is possible. OCR’s investigation determined that Azul Vision failed to take timely action in response to the request, in violation of the right of access standard of the HIPAA Privacy Rule.

Under OCR’s enforcement initiative, the HIPAA violation warranted a financial penalty. Azul Vision was given the opportunity to settle the alleged violation informally, and a $50,000 financial penalty was agreed to resolve the investigation. In addition to the financial penalty, Azul Vision has agreed to adopt a corrective action plan to address the alleged violation and ensure future compliance with the HIPAA Rules.

Get The FREE
HIPAA Compliance Checklist

Immediate Delivery of Checklist Link To Your Email Address

Please Enter Correct Email Address

Your Privacy Respected

HIPAA Journal Privacy Policy

The corrective action plan requires Azul Vision to review and revise its policies and procedures to comply with the HIPAA Privacy Rule and ensure its workforce receives training on the HIPAA right of access and Azul Vision’s policies and procedures.  Azul Vision will be monitored for compliance with the corrective action plan and must submit reports to OCR of all right of access requests, including the date the requests were received and the completion dates.

“OCR’s 55th enforcement action in the Right of Access Initiative demonstrates the Trump Administration’s commitment to enforcing timely access to requested protected health information,” said OCR Director Paula M. Stannard. “The right of access is key to empowering individuals to take control of their own health. It should not be necessary for OCR to initiate a right of access investigation before a covered entity will provide an individual with access to their requested records.”

The post Azul Vision Settles HIPAA Right of Access Case for $50,000 appeared first on The HIPAA Journal.

Privacy Concerns Raised Over Government Demand for Hospital Emergency Room Data

The United States Consumer Product Safety Commission (CPSC) is requesting digital patient data from hospitals as part of its efforts to track consumer product-related injuries. By the end of the year, CPSC hopes that more than 100 hospitals will provide the requested records to the Kansas-based government contractor Konza Health, which was awarded a $15.9 million contract last year to support the National Electronic Injury Surveillance System (NEISS) Remodel project.

NEISS has been in operation for more than 5 decades, and its primary purpose is to collect data on consumer product-related injuries in the United States. NEISS is an important public health research tool; however, data collection is labor-intensive and involves a manual review and coding of medical records from around 70 of the nation’s 5,000+ hospital emergency departments. Currently, 14 states do not have any participating hospitals, which limits the geographic reach of the system and has reduced CPSC’s ability to identify rare and emerging product hazards.

Under the planned NEISS Remodel (NEISS-R) project, coverage will be expanded to all 50 states to ensure data is collected from currently underrepresented and non-represented states. The plan involves automating data collection by leveraging modem technology and the country’s electronic health record infrastructure. In so doing, CPSC said it will be able to identify rare and emerging hazards much more rapidly than the legacy system allows.

NEISS-R will see data exchanged through a federally designated Qualified Health Information Network (QHIN), which CPSC claims “is supported by contractual privacy requirements and standardized security safeguards.” The data collected will be limited, as will data retention, to the minimum necessary information to support CPSC’s statutory mission, and will support de-identification before the data reaches CPSC. CPSC says the project will result in a more timely, more accurate, and more cost-effective system, which will better protect American families.

Under the current system, emergency department nurses are required to review patient charts, manually identify consumer-related accidents, and enter that information into a national database. Under the new system, data collection would be automated, and it would be the responsibility of Konza Health, a TEFCA QHIN, to strip out identifying information prior to data transfers to CPSC.

According to the letters sent by Konza Health to hospitals, “Using accident-related diagnosis codes, Konza Health will identify patients that may have experienced a consumer product-related accident. For identified accidents, Konza Health will gather additional patient clinical information and provide it to CPSC for follow-up.” The letters request meetings with the selected hospitals to establish connectivity methods to allow secure data exchange for the project.

The NEISS-R project has sparked privacy fears, as under the manual system, nurses were instructed not to provide identifiable information such as patient names, addresses, or birth dates; however, the automated system would involve sending identifiable patient data Konza Health. While it is claimed that the data provided to CPSC will be unchanged from the information it has obtained for the past five decades, far broader access to patient data is sought.

KFF Health News reports that, based on emails shared by hospitals and interviews with people involved or familiar with the discussions between the hospitals and Konza Health, the data requested falls well outside of the CPSC’s consumer product safety mission. “In a stark departure from its product-focused mission, the agency’s goal is to obtain millions of Americans’ medical records from emergency room visits for most injuries, from a broken bone to a childhood vaccine reaction or even a suicide attempt,” explained KFF Health News. “A CPSC official also insisted in the emails that the institutions provide all ER patients’ identifiable information — such as names, addresses, diagnoses, and other personal details — to the contractor, Konza Health, for analysis.” According to communications between Konza Health and technology officials at one hospital, ER data is requested for more than 10,000 conditions, including injuries totally unrelated to consumer products.

CPSC and Konza Health have faced resistance from some hospitals over the mandatory provision of the data, and have suggested that refusing to provide the required data could be viewed as information blocking, potentially leading to significant penalties; however, the information being sought raises HIPAA concerns. Under HIPAA, hospitals are permitted, but not required, to submit data to CPSC for public health purposes, but any disclosure should be limited to the minimum necessary information to achieve the purpose for the disclosure. Since CPSC is collecting data to fulfil its consumer product safety mission, any data disclosed should be limited to that purpose. Should CPSC require more data than it has previously collected, further rulemaking would be necessary.

Participating hospitals could find themselves between a rock and a hard place – potential fines for information blocking if they do not agree to provide the requested data and potential HIPAA fines if they do. However, under the current information blocking regulations, there is a privacy exception, the purpose of which is to ensure that health information is not required to be disclosed in a way that is prohibited under state or federal privacy laws, and under the HIPAA minimum necessary standard, disclosures should be restricted to information required for CPSC’s public health activities, which concern consumer product safety.

The post Privacy Concerns Raised Over Government Demand for Hospital Emergency Room Data appeared first on The HIPAA Journal.

OSF Healthcare System Pays $552,250 to Settle OCR HIPAA Investigation

OSF Healthcare System and its Affiliated Covered Entities (OSF Healthcare) have agreed to pay a penalty of $552,250 to resolve alleged violations of the HIPAA Privacy, Security, and Breach Notification Rules.

OSF Healthcare is a Peoria, Illinois-based integrated health system that serves patients at 174 locations in Illinois and Michigan, including 16 hospitals. On April 23, 2021, OSF Healthcare discovered that ransomware had been used to encrypt files on its network. The threat group deployed a variant of Nephilim ransomware to encrypt files and demanded payment to prevent a data leak and to obtain the keys to unlock the encrypted files.

The forensic investigation determined on August 24, 2021, that the protected health information (PHI) of 53,907 patients was exfiltrated from its network, including names, driver’s license numbers, diagnosis and treatment information, prescription information, medical record numbers, provider names, dates of services, financial account information, and health insurance information. OCR was notified about the attack on October 1, 2021, and individual notification letters started to be sent on the same date.

As with all breaches of the PHI of 500 or more individuals, OCR initiated an investigation to assess compliance with the HIPAA Rules. OCR determined that OSF Healthcare had not conducted a comprehensive and accurate risk analysis to identify risks and vulnerabilities to the confidentiality, integrity, and availability of patients’ PHI, as required by 45C.F.R. § 164.308(a)(l)(ii)(A), and that there had been an impermissible disclosure of the PHI of 53,907 patients, in violation of 45 C.F.R. § 164.502(a).

OCR also determined that OSF Healthcare failed to issue timely notifications to the individuals affected by the data breach and did not provide a timely notification to the Secretary of the HHS, in violation of 45 C.F.R. § 164.404(b) and § 164.408(b). OCR determined that the alleged HIPAA violations were severe enough to warrant a financial penalty, and after advising OSF Healthcare System of the findings of the investigation and the intention to impose a financial penalty, a settlement was agreed to resolve the alleged violations informally.

Under the terms of the settlement, in addition to the $552,250 financial penalty, OSF Healthcare agreed to implement a corrective action plan and will be monitored for compliance with the plan for a period of two years. The corrective action plan includes the requirement to conduct an accurate and thorough risk analysis, and develop and implement a risk management plan to address and mitigate security risks and vulnerabilities identified in its risk analysis.

“An accurate and thorough HIPAA risk analysis is not only required by law, but it is also necessary to protect health information and prevent or mitigate ransomware attacks,” said OCR Director Paula M. Stannard. “If a HIPAA-regulated entity doesn’t know what threats and vulnerabilities exist to its electronic protected health information, they will often learn the hard way when their systems are hacked.”

OCR has resolved eight HIPAA investigations with settlements so far this year, collecting $2,280,250 in penalties. The OSF Healthcare settlement is the largest penalty of the year to date. All eight investigations identified risk analysis failures, and this is the second case involving a penalty to resolve breach notification failures.

The post OSF Healthcare System Pays $552,250 to Settle OCR HIPAA Investigation appeared first on The HIPAA Journal.

May 2026 Healthcare Data Breach Report

Based on the current data on the HHS’ Office for Civil Rights (OCR) breach portal, 61 healthcare data breaches affecting 500 or more individuals were reported in May 2026. May’s current total represents a 27.1% month-over-month increase in data breaches. Over the past 12 months, an average of 64 large healthcare data breaches were reported each month.

Healthcare data breaches in the past 12 months - May 2026

From January 1, 2026, to May 31, 2026, 319 data breaches affecting 500 or more individuals have been reported to OCR. This time last year, the total stood at 342 large data breaches.

HEalthcare data breaches - January 1 - May 31 - 2022-2026

While data breaches increased from April, the number of affected individuals fell by 34.8% to 879,447 individuals. In May, an average of 14,417 individuals were affected by healthcare data breaches, down from an average of 28,116 individuals in April. Over the past 12 months, an average of 10.6 million individuals have been affected by healthcare data breaches each month.

Individuals affected by healthcare data breaches in the past 12 months - May 2026

Data breaches are down slightly year-over-year, but there has been a massive reduction in the number of affected individuals. Very large data breaches have not been reported to OCR in the numbers seen in previous years. From January 1, 2026, to May 31, 2026, across the 319 data breaches, at least 21,085,405 individuals have been affected. The OCR breach portal shows that from January 2025 to May 2025, 33,116,809 individuals were affected by data breaches.

Individuals affected by healthcare data breaches - jan 1 - May 31, 2022-2026

Biggest Healthcare Data Breaches of May 2026

In May 2026, 17 data breaches affecting 10,000 or more individuals were reported to OCR, all of which were hacking incidents. The biggest data breach of the month was reported by Radiology Associates of Richmond, affecting more than 266,000 individuals, followed by a hacking incident at Western Orthopaedics which affected more than 113,000 individuals.

Regulated Entity State Covered Entity Type Individuals Affected Cause of Breach
Radiology Associates of Richmond VA Healthcare Provider 266,183 Hacking incident
Western Orthopaedics, P.C. CO Healthcare Provider 113,330 Hacking incident
ERMI LLC GA Healthcare Provider 74,074 Hacking incident
Singing River Health System MS Healthcare Provider 53,888 Hacking incident
Southern Illinois Ob-Gyn Associates, S.C. IL Healthcare Provider 38,700 Hacking incident
Gastro Health FL Healthcare Provider 35,632 Unauthorized access to email accounts
Eyemart Express, LLC TX Healthcare Provider 25,000 Hacking incident
Connecticut Department of Social Services CT Health Plan 22,500 Unauthorized access to provider portal website
Bridle Trails Family Dentistry WA Healthcare Provider 20,976 Unauthorized access to email account
Community Connections DC Healthcare Provider 18,943 Ransomware attack (INCRansom)
Virta Medical PC CO Healthcare Provider 14,636 Hacking incident (Lapsus$)
Saurabh N. Patel, M.D – Florida Retina Center LA Healthcare Provider 13,652 Hacking incident
Greenbaum Rowe Smith & Davis LLP NJ Business Associate 12,801 Hacking incident
Wellpoint Washington, Inc. IN Health Plan 12,020 Unauthorized access to email account
Defense Health Agency (TriWest) VA Health Plan 11,848 Hacking incident
IKRON Corporation OH Healthcare Provider 11,845 Hacking incident
Elara Caring TX Healthcare Provider 10,490 Hacking incident at third-party vendor

May’s total number of affected individuals may increase considerably over the coming weeks and months, as healthcare organizations complete their data breach investigations. HIPAA-regulated entities have 60 days from the date of discovery of a data breach to issue notifications to the HHS’ Office for Civil Rights and the affected individuals. HIPAA requires OCR to be notified even if the total number of individuals has yet to be determined by the 60-day deadline. In such cases, an estimate should be provided. Many regulated entities use a placeholder estimate of 500 or 501 individuals in such cases, and in May, 7 regulated entities appear to have used these placeholder figures.

Regulated Entity State Covered Entity Type Individuals Affected Cause of Breach
United Medical Doctors CA Healthcare Provider 501 Hacking/IT Incident
NJ Pain Care Specialists, LLC NJ Healthcare Provider 501 Hacking/IT Incident
Palomar Health Medical Group CA Healthcare Provider 501 Hacking/IT Incident
Aroostook Mental Health Center ME Healthcare Provider 501 Hacking/IT Incident
Campbell University NC Healthcare Provider 500 Hacking/IT Incident
BAYADA Home Health Care, Inc. NJ Healthcare Provider 500 Hacking/IT Incident
Integrated Pain Associates TX Healthcare Provider 500 Hacking/IT Incident

Causes of May 2026 Healthcare Data Breaches

Hacking and other IT incidents dominated the breach reports in May, as has been the case each month for several years. Out of the month’s 61 large healthcare data breaches, 54 were classed as hacking/IT incidents – 88.5% of the month’s data breaches. Across those incidents, the protected health information of 853,532 individuals was compromised- 88.5% of the month’s total affected individuals. On average, hacking/IT incidents affected 15,806 individuals in May, with a median breach size of 3,619 individuals.

Causes of May 2026 healthcare data breaches

There were 7 data breaches classed as unauthorized access/disclosure incidents, representing 11.5% of the month’s breaches. Across those incidents, the protected health information of 25,915 individuals was unlawfully accessed or disclosed. On average, 3,702 individuals were affected by each incident in May. The median breach size was 3,086 individuals. There were no reported theft, loss, or improper disposal incidents in May.

Given the large number of hacking incidents, it is no surprise that the most common location of breached protected health information was network servers. Email incidents were also reported in high numbers.

Location of breached PHI in May 2026 healthcare data breaches

States Affected by May 2026 Healthcare Data Breaches

Large healthcare data breaches were reported by HIPAA-regulated entities in 26 U.S. states and the District of Columbia. California was the worst affected state with 6 breaches.

State Breaches
California 6
Florida, New Jersey, New York, North Carolina, Ohio, Texas & Virginia 4
Colorado 3
Indiana, Maine, Michigan, Pennsylvania, South Carolina & the District of Columbia 2
Arizona, Connecticut, Georgia, Illinois, Iowa, Louisiana, Massachusetts, Mississippi, Oregon, Tennessee, Washington & Wisconsin 1

In terms of affected individuals, Virginia topped the list with almost 300,000 state residents affected.

State Individuals Affected State Individuals Affected
Virginia 290,254 Louisiana 13,652
Colorado 128,661 Pennsylvania 7,095
Georgia 74,074 South Carolina 6,946
Mississippi 53,888 Iowa 6,666
Florida 44,649 Michigan 6,456
Texas 40,045 California 5,303
Illinois 38,700 North Carolina 4,949
Ohio 28,540 Massachusetts 3,086
Connecticut 22,500 Maine 3,024
Washington 20,976 Oregon 2,856
District of Columbia 20,014 Arizona 2,316
New York 19,674 Tennessee 1,807
Indiana 17,325 Wisconsin 1,080
New Jersey 14,911

Data Breaches at HIPAA -Regulated Entities

In May 2026, 42 data breaches were reported by healthcare providers, 9 breaches were reported by health plans, and 10 data breaches were reported by business associates. When a breach occurs at a business associate, the affected covered entities must be informed. Each covered entity may delegate the breach notification responsibilities to the business associate, but it is ultimately the responsibility of each covered entity to ensure that breach notifications are issued. In many cases, a breach at a business associate is reported by the covered entity.

The pie charts below show where the data breach occurred, rather than the reporting entity, which shows that 22 of the 61 breaches (rather than 10) occurred at business associates in May.

May 2026 data breaches at HIPAA-regulated entities

Individuasl affected by data breaches at HIPAA-regulated entities in May 2026

HIPAA Enforcement Activity in May 2026

No enforcement actions were announced by OCR or state attorneys general in May.

The post May 2026 Healthcare Data Breach Report appeared first on The HIPAA Journal.

HIPAA Security Rule Update Postponed: More Time Given to Implement Major HIPAA Security Rule Changes

There has been some good news for the HIPAA-regulated entities that feel unprepared for the proposed changes to the HIPAA Security Rule. The Department of Health and Human Services (HHS) had proposed a May 2026 release date for a final rule implementing the proposed changes to the HIPAA Security Rule; however, the U.S. Office of Management and Budget (OMB) website has been updated, showing the final rule has been pushed back a year, with the final action due in July 2027.

Why HIPAA Security Rule Changes Have Been Proposed

The HHS’ Office for Civil Rights (OCR), under the Biden administration, issued a Notice of Proposed Rulemaking (NPRM) to strengthen the HIPAA Security Rule in December 2024, and published the proposed rule in the Federal Register on January 6, 2025.  The original HIPAA Security Rule was enacted more than two decades ago in 2003 and was updated by the HIPAA Omnibus Final Rule in 2013, but there have been no substantial changes to the Security Rule in the past 13 years.

Today, almost all aspects of healthcare rely on computer and network technologies, and cybersecurity is far more of a concern than when the Security Rule was first published. Over the past 10 years, cyberattacks on healthcare organizations and breaches of electronic protected health information (ePHI) – that the Security Rule was introduced to protect – have been steadily increasing, especially in 2018, when there was a rampant escalation in hacking incidents and healthcare ransomware attacks. Not only have these incidents increased substantially, but there has also been an alarming upward trend in the number of individuals affected and the harm these incidents cause.

Take the ALPHV/BlackCat ransomware attack on Change Healthcare in February 2024. The attack on this key healthcare technology company and clearinghouse had massive implications for the healthcare industry. The company’s systems touch one in every three patient records and are relied on by hospitals, physicians, pharmacies, and laboratories across the country for billing and payment processing. The attack caused severe cash flow problems for the company’s clients, care delivery was affected, and some providers were forced to temporarily close. The outage caused by the attack lasted for weeks, while the disruption for providers continued for much longer. The ePHI of an estimated 192.7 million Americans was stolen in the attack. The attackers breached the Change Healthcare network via a Citrix remote access portal using stolen credentials, and crucially, multifactor authentication was not enabled. Multifactor authentication is one of the requirements of the Security Rule update, as is network segmentation to limit the impact of cyberattacks.   

New Security Rule Requirements

The proposed HIPAA Security Rule update is intended to address changes in the healthcare environment and technology, force HIPAA-regulated entities to make cybersecurity updates to combat cyberattacks and prevent data breaches, and correct deficiencies in the HIPAA Security Rule that OCR has identified from its investigations of data breaches, complaints, and its HIPAA audit program. The updates are based on current cybersecurity best practices and methodologies, and are common sense updates given the extent to which the healthcare industry is being targeted by cyber actors and how frequently they breach healthcare networks.

The proposed changes are substantial, and include the elimination of the addressable implementation classification; strict mandatory cybersecurity requirements such as encryption, multifactor authentication, network segmentation, and anti-malware protection; annual penetration tests, vulnerability scans every 6 months, and annual audits of Security Rule compliance; more prescriptive requirements for risk analyses, which must be conducted at least annually and be based on a comprehensive and accurate technology asset inventory and network map showing how ePHI flows; dedicated backup and recovery controls for ePHI; shorter timelines for business associates and verification of their technical safeguards; and extensive documentation requirements.

Proposed Regulatory Update Attracts Considerable Criticism

The 390-page proposed update was not particularly well received and attracted considerable criticism from hospitals, health systems, and industry groups. OCR received almost 5,000 comments in response to the proposed rule. While industry stakeholders accepted the need for improvements to security to combat the cybersecurity crisis in healthcare, they viewed the proposed rule as an impossible mandate, as it would place substantial financial burdens on healthcare organizations, cause massive operational disruptions, create a huge administrative burden, and has an unworkable timeframe for implementation.

The proposed rule lacks much of the flexibility of the original rule, attracting criticism for the one-size-fits-all approach to cybersecurity. Since the new requirements are extensive, forcing HIPAA-regulated entities to commit substantial funds to compliance will require many to divert funds away from patient care. The pain would be particularly acute for small and rural healthcare providers who are already working on razor-thin margins. The HHS accepts that compliance will not be cheap, calculating that the proposed changes will have a one-year industry cost of $9 billion, with annual industry costs of $6 billion a year for years two through five.

More Time to Prepare for Inevitable New Security Requirements

The timeframes released by government entities for implementing new rules are not legally binding. The final rule may have been delayed by a year and could be delayed further; however, OCR could press ahead and release a final rule ahead of the proposed July 2027 date.

Changes to the HIPAA Security Rule are inevitable to ensure it remains effective. One of the criticisms of the proposed rule was the short implementation timeframe, which was viewed by industry groups as unworkable. While there may be a huge collective sigh of relief at the delay, it is important to use the extra time wisely. Waiting for the final rule to be issued before implementing the required changes runs the risk of missing the implementation deadline and facing the regulatory risks associated with late compliance.

If regulated entities use the time to plan and they start implementing some of the proposed requirements over the coming 12 months, the pain will be eased when the final rule drops. In the meantime, cybersecurity will be improved, helping to prevent cyberattacks, costly downtime, and many data breaches.

Steve Alder, Editor-in-Chief, The HIPAA Journal.

The post HIPAA Security Rule Update Postponed: More Time Given to Implement Major HIPAA Security Rule Changes appeared first on The HIPAA Journal.

April 2026 Healthcare Data Breach Report

In April 2026, 47 healthcare data breaches affecting 500 or more individuals were reported to the HHS’ Office for Civil Rights (OCR). That represents a 33.8% reduction in large healthcare data breaches from the 71 large data breaches reported in March 2026, and well below the 12-month average of 62.4 data breaches per month.

healthcare data breaches in the past 12 months - April 2026

The year-to-date figures also show a reduction in large healthcare data breaches. From January 1 to April 30, 252 large healthcare data breaches have been reported by HIPAA-regulated entities, compared to 276 (-8.7%) for the corresponding period in 2025 and 299 (-15.7%) for the corresponding period in 2024.

Healthcare data breaches - January 1 to April 30 (2022-2026)

Across the 47 data breaches, the protected health information of 1,336,264 individuals was exposed or impermissibly disclosed – the second lowest monthly total in the past 12 months, and currently an 84.9% reduction from March 2026. The number of affected individuals is likely to increase, as some regulated entities have reported breaches with placeholder estimates of 500 or 501 affected individuals.

Individuals affected by healthcare data breaches in the past 12 months (April 2026)

The year-to-date figures for affected individuals are encouraging. From January 1 to April 30, the protected health information of 20.1 million individuals has been breached, and while that is a sizeable figure, it is a reduction of 25.5% from the corresponding period in 2025 and a reduction of 48.8% from the corresponding period in 2024.

Individuals affected by healthcare data breaches - january 1 to April 30 (2022-2026)

The Biggest Healthcare Data Breaches Reported in April 2026

In April, 15 data breaches affecting 10,000 or more individuals were reported to the HHS’ Office for Civil Rights, all but one of which were hacking incidents. The biggest data breach of the month was reported by the medical group Florida Physician Specialists, involving unauthorized access to the protected health information of 276,498 individuals.  Two of the 15 data breaches were confirmed ransomware attacks, and one incident involved unauthorized access by “a business counterparty” after access was thought to have been terminated.

Regulated Entity State Covered Entity Type Individuals Affected Type of Breach Location of Breached Information Cause of Breach
Florida Physician Specialists FL Healthcare Provider 276,498 Hacking/IT Incident Network Server Hacking incident – Data theft confirmed
Southern Illinois Dermatology IL Healthcare Provider 160,312 Hacking/IT Incident Network Server Hacking incident
Laurel Eye Clinic PA Healthcare Provider 145,221 Hacking/IT Incident Network Server Hacking incident – Data theft confirmed
Innovative Scientific Solutions, LLC SC Healthcare Provider 143,842 Hacking/IT Incident Network Server Hacking incident
Hospital Caribbean Medical Center PR Healthcare Provider 92,000 Hacking/IT Incident Network Server Ransomware attack (The Gentlemen) – Data theft confirmed
Tri-Cities Gastroenterology TN Healthcare Provider 67,115 Hacking/IT Incident Network Server Hacking incident – Data theft confirmed
City Health, a medical corporation CA Healthcare Provider 65,000 Unauthorized Access/Disclosure Electronic Medical Record Access to its electronic medical record system by a former business counterparty after termination
Hematology Oncology Consultants MI Healthcare Provider 62,972 Hacking/IT Incident Network Server Hacking incident – Data theft likely
GrayRobinson, P.A. FL Business Associate 54,131 Hacking/IT Incident Network Server Hacking incident – Data theft confirmed
Rocky Mountain Associated Physicians, P.C. UT Healthcare Provider 50,640 Hacking/IT Incident Network Server Hacking incident
Heart South Cardiovascular Group AL Healthcare Provider 46,666 Hacking/IT Incident Network Server Hacking incident
Mt. Spokane Pediatrics WA Healthcare Provider 32,021 Hacking/IT Incident Network Server Hacking incident – Data theft confirmed
University of Nebraska Medical Center NE Healthcare Provider 26,937 Hacking/IT Incident Network Server Hacking of a third-party software application
Liberty Bankers Life Ins. Co. TX Health Plan 20,202 Hacking/IT Incident Network Server Hacking incident at a business associate
Bayside Dental WA Healthcare Provider 10,216 Hacking/IT Incident Network Server Ransomware attack (Sinobi) – Data theft claimed

Three data breaches were reported in April before data reviews had been completed. Placeholder figures of 500 or 501 affected individuals were used and will be updated when the file reviews are concluded.

Regulated Entity State Covered Entity Type Individuals Affected Cause of Breach
Spokane Digestive Disease Center, P.S. WA Healthcare Provider 501 Unauthorized access to its email environment
FMRS Health Systems, Inc. WV Healthcare Provider 500 Hacking incident – data theft confirmed
CARE Clinic MN Healthcare Provider 500 Unauthorized access to its email environment

Causes of April 2026 Healthcare Data Breaches

Hacking and other types of IT incidents dominated the breach reports in April, accounting for 36 (76.6%) of the 47 reported large data breaches. Across those incidents, the protected health information of 1,240,571 individuals was exposed or impermissibly disclosed. Hacking/IT incidents accounted for 92.8% of the affected individuals in April. The average breach size was 32,883 individuals, and the median breach size was 4,547 individuals.

Causes of APril 2026 healthcare data breaches

There were 9 unauthorized access/disclosure incidents in April, which accounted for 19.1% of the month’s data breaches. Across those incidents, the protected health information of 86,717 individuals was accessed without authorization or was impermissibly disclosed – 6.5% of the month’s affected individuals. The average breach size was 9,635 individuals, and the median breach size was 1,467 individuals. There were no loss, theft, or improper disposal incidents in April.

Location of breached PHI in April 2026

States Affected by April 2026 Healthcare Data Breaches

Data breaches were reported by HIPAA-regulated entities in 25 states, the District of Columbia, and Puerto Rico in April. California was the worst-affected state in terms of data breaches, while Florida was the worst-affected state in terms of the number of individuals affected.

April 2026 Healthcare Data Breaches

State Breaches
California 6
Texas & Washington 4
Florida & Virginia 3
Illinois, Minnesota, Oklahoma, Pennsylvania & West Virginia 2
Alabama, Delaware, Iowa, Indiana, Kentucky, Maryland, Michigan, Missouri, Nebraska, New Jersey, New York, South Carolina, Tennessee, Utah, Vermont, the District of Columbia & Puerto Rico 1

Individuals Affected by April 2026 Healthcare Data Breaches

State Individuals Affected State Individuals Affected
Florida 331,316 Oklahoma 8,233
Illinois 162,203 Maryland 7,213
Pennsylvania 145,976 Iowa 6,717
South Carolina 143,842 Indiana 5,900
Pouerto Rico 92,000 Vermont 5,892
California 78,846 Minnesota 5,885
Tennessee 67,115 Kentucky 3,677
Michigan 62,972 Virginia 2,552
Utah 50,640 New York 2,123
Alabama 46,666 Missouri 2,027
Washington 46,202 West Virginia 1,500
Nebraska 26,937 District of Columbia 1,467
Texas 26,648

April 2026 Data Breaches at HIPAA Regulated Entities

In April 2026, 36 data breaches were reported by healthcare providers, 8 breaches were reported by health plans, and 3 data breaches were reported by business associates. When a breach occurs at a business associate, the affected covered entities must be informed. Each covered entity may delegate the breach notification responsibilities to the business associate, but it is ultimately the responsibility of each covered entity to ensure that breach notifications are issued. In many cases, a breach at a business associate is reported by the covered entity.

The pie charts below show where the data breach occurred, rather than the reporting entity, which shows that 11 of the 47 breaches (rather than 3) occurred at business associates in April.

Data breaches at HIPAA-regulated entities in April 2026

Individuals affected by healthcare data breaches at HIPAA-regulated entities in April 2026

HIPAA Enforcement Activity in April 2026

The HHS’ Office for Civil Rights, the main enforcer of HIPAA compliance, announced 4 settlements with HIPAA-regulated entities in April to resolve alleged violations of the HIPAA Rules. When alleged HIPAA violations are settled, the settlement agreement includes a corrective action plan to address the areas of noncompliance identified by OCR. When a civil monetary penalty is imposed, OCR cannot compel the regulated entity to adopt a corrective action plan.

All four of the settlements related to ransomware attacks, and in all cases, OCR identified a risk analysis failure. The HIPAA Security Rule requires regulated entities to conduct a comprehensive and accurate risk analysis to identify risks and vulnerabilities to electronic protected health information. It is the most commonly identified HIPAA Security Rule violation.  You can read more about each enforcement action in this post. No state attorneys general announced any HIPAA penalties in April.

HIPAA -Regulated Entity Entity Type Reason for Investigation Alleged HIPAA violation(s) Settlement Amount
Regional Women’s Health Group (Axia Women’s Health) Healthcare Provider Reported ransomware attack involving the protected health information of 37,989 individuals Risk analysis failure; impermissible disclosure of ePHI $320,000
Assured Imaging Affiliated Covered Entities Healthcare Provider Reported ransomware attack involving the protected health information of 244,813 individuals Risk analysis failure (never conducted); breach notification failure $375,000
Consociate, Inc. (Consociate Health) Business Associate Reported ransomware attack involving the protected health information of 136,539 individuals Risk analysis failure $225,000
Star Group, L.P. Health Benefits Plan Health Plan Reported ransomware attack involving the protected health information of 9,316 individuals Risk analysis failure $245,000

 

The post April 2026 Healthcare Data Breach Report appeared first on The HIPAA Journal.

Spencer Gifts Pays $450,000 Penalty to Resolve HIPAA Failures

The national retail company Spencer Gifts LLC has agreed to a $450,000 settlement to resolve alleged violations of the HIPAA Rules that OCR identified while investigating a data breach affecting 10,023 members of its employer-sponsored group health plan (Spencer Gifts LLC Flexible Benefits and Welfare Benefit Plans).

In November 2021, staff were prevented from connecting to the company’s virtual private network. The IT issue was investigated, and the access issues were determined to be due to a ransomware attack. A threat actor had accessed the company’s network between November 24, 2021, and November 26, 2021, and used ransomware to encrypt files, including files on servers that stored plan members’ electronic protected health information (ePHI). Data exposed and potentially stolen in the incident included names, addresses, zip codes, phone numbers, email addresses, and Social Security numbers. OCR was notified about the data breach on January 24, 2022.

OCR investigates all reported breaches affecting 500 or more individuals to determine whether they were the result of HIPAA noncompliance. Under its current enforcement initiative, OCR is laser-focused on the risk analysis provision of the HIPAA Security Rule. OCR requires evidence to demonstrate that a regulated entity has conducted a thorough and accurate risk analysis to identify risks and vulnerabilities to the confidentiality, integrity, and availability of ePHI.

OCR determined that Spencer Gifts had failed to conduct a HIPAA-compliant risk analysis, in violation of 45 C.F.R. § 164.308(a)(1)(ii)(A) of the HIPAA Security Rule.  Spencer Gifts was also found to have failed to implement policies and procedures to comply with the HIPAA Privacy, Security, and Breach Notification Rules, in violation of 45 C.F.R. § 164.316(a) and 45 C.F.R. § 164.530(i)(1).

OCR determined that the HIPAA violations warranted a financial penalty. Spencer Gifts was informed of OCR’s determination and intention to impose a financial penalty, and the health plan was given the opportunity to settle the alleged violations informally. Spencer Gifts agreed to pay a $450,000 financial penalty and adopt a corrective action plan to address the alleged areas of noncompliance.

The corrective action plan requires Spencer Gifts to conduct a comprehensive and accurate risk analysis, review and update its HIPAA policies and procedures, distribute those policies and procedures to the workforce, and provide HIPAA training to its workforce.

This is the 20th OCR investigation of a ransomware attack resulting in a financial penalty for noncompliance with the HIPAA Rules, the 14th enforcement action under OCR’s risk analysis enforcement initiative, and the 7th HIPAA penalty to be announced this year. So far this year, OCR has collected $1,728,000 in penalties to resolve alleged violations of the HIPAA Rules from three healthcare providers, two health plans, and two business associates.

The post Spencer Gifts Pays $450,000 Penalty to Resolve HIPAA Failures appeared first on The HIPAA Journal.

Compliancy Group Acquires Healthicity

Compliancy Group has acquired Healthicity in a deal that combines two healthcare compliance software companies and expands Compliancy Group’s platform to include healthcare compliance, workforce compliance, risk assessment, third-party risk management, incident management, provider auditing, coding auditing, and documentation auditing.

The acquisition was announced on June 17, 2026. Financial terms of the transaction were not disclosed. Compliancy Group said the combined organization will serve more than 3,000 healthcare organizations across the United States and selected global markets.

Healthicity provides healthcare compliance and medical auditing software and advisory services. Its products include Compliance Manager, Audit Manager+, and Compliance Advisory Services, which are used by health systems, hospitals, physician groups, and other healthcare organizations to manage compliance programs and auditing activities.

Compliancy Group said the acquisition will allow healthcare organizations to manage more elements of their compliance programs through a single platform ecosystem. The expanded offering will combine Healthicity’s provider, coding, and documentation auditing capabilities with Compliancy Group’s existing compliance management tools, including workforce compliance, risk assessment, third-party risk, and incident management.

Darin Johnson, Chief Executive Officer of Healthicity, said Compliancy Group was selected as the right strategic partner for Healthicity’s software and customers because of its service reputation, regulatory expertise, and product innovation. Johnson said the two companies share a customer-focused approach and are positioned to deliver greater value together than either company could independently.

Crispin Vary, Chief Executive Officer of Compliancy Group, said the transaction will allow healthcare organizations to run broader compliance programs from a single partner. “For the first time, a healthcare organization can run its entire compliance program, from workforce training and risk assessment to vendor oversight, incident management, and now provider, coding, and documentation auditing, from a single trusted partner with one conformance score,” said Vary. Compliancy Group provides healthcare compliance software and advisory support for organizations that need to build, manage, and maintain compliance programs. Healthicity provides software and expert guidance for healthcare compliance management and medical auditing.

The acquisition brings the two businesses together at a time when healthcare organizations face increasing pressure to document the effectiveness of their compliance programs and demonstrate that required risk management, auditing, training, vendor oversight, and incident response activities are being performed.

The post Compliancy Group Acquires Healthicity appeared first on The HIPAA Journal.