Utopia Tech
Healthcare4 min read

H1 2026 Healthcare Data Breach Report

There has been a 5.9% decline in healthcare breaches compared to H1 2025. Between January 1 and June 30, 2026, 397 data breaches affecting 500 or more individuals were reported to the U.S. Department of Health and Human Services (HHS) Office for Civil Rights – the lowest H1 total since 2023. While the year-over-year reduction in healthcare data breaches is a step in the right d

UT

Utopia Tech

September 30, 2026 · 4 min read

Share

There has been a 5. 9% decline in healthcare breaches compared to H1 2025. Between January 1 and June 30, 2026, 397 data breaches affecting 500 or more individuals were reported to the U.

S. Department of Health and Human Services (HHS) Office for Civil Rights – the lowest H1 total since 2023. While the year-over-year reduction in healthcare data breaches is a step in the right direction, healthcare data breaches continue to be reported in high numbers.

In the first six months of the year, large healthcare data breaches were reported at a rate of more than 2. 2 per day. Across the 397 reported data breaches, the protected health information of 33.

77 million individuals was exposed or impermissibly disclosed. That represents a 22. 6% reduction in affected individuals compared to H1 2025, and it is the lowest number of affected individuals in H1 since 2023.

If data breaches continue to be reported at a similar rate in the second half of the year, the end-of-year healthcare data breach total is likely to be lower than 2025, which was a record-breaking year with 804 data breaches currently listed on the OCR breach portal for 2025. The current total also suggests that this year could see a major reduction in affected individuals, as more than 140 million individuals were affected in 2025.

That said, several very large data breaches have yet to be added to the OCR breach portal for this year. The Biggest Healthcare Data Breaches in H1 2026 In the first half of the year, nine healthcare data breaches were reported that affected more than 1 million individuals, the largest breach of which affected more than 5. 8 million individuals.

All but two of the top twenty data breaches were due to hacking incidents or ransomware attacks. The two non-hacking breaches were unauthorized access/disclosure incidents, and both occurred at state departments of human services. Get The FREE HIPAA Compliance Checklist Immediate Delivery of Checklist Link To Your Email Address Please enable JavaScript in your browser to complete this form.

Business Email * Name * First Last Number * Company Name * Get Free Checklist Please Enter Correct Email Address Your Privacy Respected HIPAA Journal Privacy Policy Rank Regulated Entity State Covered Entity Type Individuals Affected Type of Breach 1 Lumexa Imaging NC Healthcare Provider 5,830,949 Hacking Incident 2 TriZetto Provider Solutions MO Business Associate 3,433,965 Hacking Incident 3 QualDerm Partners, LLC TN Healthcare Provider 2,951,318 Hacking Incident 4 Nacogdoches Memorial Hospital TX Healthcare Provider 2,507,073 Hacking Incident 5 Navia Benefit Solutions, Inc.

WA Business Associate 2,151,330 Hacking Incident 6 Insightin Health, Inc. MD Business Associate 1,949,534 Hacking Incident 7 New York City Health and Hospitals Corporation NY Healthcare Provider 1,800,000 Hacking Incident 8 Xsolis, Inc . TN Business Associate 1,396,519 Hacking Incident 9 MCBS, LLC GA Business Associate 1,261,464 Hacking Incident 10 OpenLoop Health, Inc.

IA Business Associate 716,000 Hacking Incident 11 Illinois Department of Human Services IL Health Plan 705,017 Unauthorized Disclosure Incident 12 ApolloMD Business Services, LLC GA Business Associate 626,540 Hacking Incident (Ransomware) 13 Erie Family Health Centers IL Healthcare Provider 570,000 Hacking Incident 14 Centers Lab NJ LLC NJ Healthcare Provider 542,377 Hacking Incident 15 Networking Technology, Inc.

(RXNT) NC Business Associate 353,844 Hacking Incident 16 Minnesota Department of Human Services MN Health Plan 303,965 Unauthorized Access Incident 17 North Texas Behavioral Health Authority TX Healthcare Provider 285,086 Hacking Incident 18 Florida Physician Specialists FL Healthcare Provider 276,498 Hacking Incident 19 Radiology Associates of Richmond VA Healthcare Provider 266,183 Hacking Incident 20 Anatomic and Clinical Laboratory Associates, P.

C. TN Healthcare Provider 169,626 Hacking Incident The majority of the data breaches reported in H1 2026 were relatively small, affecting fewer than 10,000 individuals. Currently, 37 healthcare data breaches are listed as affecting 500 or 501 individuals.

These are commonly used placeholder figures when data reviews are incomplete by the breach reporting deadline. The majority of those 37 data breaches are likely to see the totals increased, potentially significantly. The Change Healthcare data breach in 2024 was initially reported to OCR as affecting at least 500 individuals but was subsequently increased to 192.

7 million individuals! Scale of Breach – Affected Individuals Data Breaches Over 1,000,000 9 100,000 – 999,999 21 10,000 – 99,999 102 1000 – 9,999 175 Under 1000 90 Causes of H1 2026 Healthcare Data Breaches While the number of large healthcare data breaches has fallen year-over-year, the lower H1 figures this year are due to fewer unauthorized access/disclosure and loss/theft incidents, rather than hacking/IT incidents, which increased for the third consecutive year.

H1 2026 Hacking/IT Incidents Hacking/IT incidents remain the leading cause of healthcare data breaches and increased again in 2026. Ransomware groups continue to attack the healthcare sector, and there has been an increasing trend of data theft and extortion incidents, where data is stolen and threats are issued to publish the stolen data, but files are not encrypted.

As also observed by the Identity Theft Resource Center, there has been a growing trend of breached entities failing to disclose the nature of data breaches, including the cause, whether ransomware was involved, and, concerningly, if data was stolen in the incident. The lack of a breach cause makes it difficult to assess trends, while the failure to disclose whether data has been stolen makes it difficult for individuals to gauge the level of risk they face.

In H1, 343 hacking/IT incidents were reported, affecting an average of 94,167 individuals (median breach size: 4,800 individuals). Hacking/IT incidents have increased by 2.

Originally published at hipaajournal.com

Share
▸ Want a deeper look?

Talk to an architect about applying this to your stack.

60-minute technical evaluation, no obligation. We'll map the ideas in this article to your environment.

Skip to main content