Utopia Tech
Healthcare4 min read

June 2026 Healthcare Data Breach Report

In June 2026, 66 large healthcare data breaches – data breaches involving the protected health information of 500 or more individuals – were reported to the U.S. Department of Health and Human Services (HHS) Office for Civil Rights (OCR) – a slight increase from the 64 data breaches reported in May. More than two large data breaches a day is the new normal. Over the past 12 mon

UT

Utopia Tech

September 7, 2026 · 4 min read

Share

In June 2026, 66 large healthcare data breaches – data breaches involving the protected health information of 500 or more individuals – were reported to the U. S. Department of Health and Human Services (HHS) Office for Civil Rights (OCR) – a slight increase from the 64 data breaches reported in May.

More than two large data breaches a day is the new normal. Over the past 12 months, an average of 65 large healthcare data breaches have been reported per day; eight years ago in 2018, large healthcare data breaches occurred at a rate of around one per day. The year-to-date figures (Jan 1-Jun 30) show that healthcare data breaches are down 3.

2% from the corresponding period in 2024 and down 6. 4% from the corresponding period last year, although they are still occurring in significantly higher numbers than in 2022 and 2023. Across June’s 66 large healthcare data breaches, the protected health information of at least 4,499,972 individuals was exposed, stolen, or impermissibly disclosed.

As data breach investigations continue, that figure is likely to increase. Based on current data, on average, 68,181 individuals were affected by each breach. The median data breach size was 6,306 individuals.

While June’s victim total is substantial, the victim count is down 36. 3% month-over-month, and 58. 7% lower than the 12-month average of 10,906,096 individuals per month.

It should be noted that the 12-month average is skewed by an unusually high total for October 2025. The year-to-date figures for 2026 show a substantial improvement compared to recent years, and while almost 34 million individuals have had their protected health information exposed, stolen, or impermissibly disclosed so far in 2026, the victim count is down 37.

7% from a high of 54. 4 million individuals in 2024, and down 22. 1% from 2025.

Get The FREE HIPAA Compliance Checklist Immediate Delivery of Checklist Link To Your Email Address Please enable JavaScript in your browser to complete this form. Business Email * Name * First Last Number * Company Name * Get Free Checklist Please Enter Correct Email Address Your Privacy Respected HIPAA Journal Privacy Policy The Biggest Healthcare Data Breaches Reported in June 2026 In June, 25 healthcare data breaches affecting 10,000 or more individuals were reported to the HHS.

The two largest data breaches of the month occurred at business associates of HIPAA-covered entities, the largest of which was reported by Xsolis and affected almost 1. 4 million individuals. Xsolis is a technology company that provides healthcare organizations with AI-powered solutions for case and utilization management.

The incident occurred in January 2026 and started with a phishing email. The phishing attack provided the threat actor with access to systems and data for four days. Files exposed in the incident contained names, dates of birth, Social Security numbers, health insurance information, and medical treatment information.

The second-largest data breach of the month occurred at MCBS (Medical Computer Business Services) and affected more than 1. 25 million individuals. MCBS is a healthcare billing, management, and revenue cycle management company.

A data theft and extortion group called PEAR breached its network, exfiltrated files, and demanded a ransom to prevent the publication of the data. The threat group had access to the network for four days in September 2025 and stole files containing names, addresses, dates of birth, Social Security numbers, medical histories, health insurance information, and other sensitive data.

A significant breach was reported by the New Jersey-based Centers Lab NJ, a diagnostic testing laboratory for hospitals and other healthcare providers. This was also a data theft and extortion incident, involving the protected health information of more than 542,000 individuals. A threat group called Worldleaks claimed responsibility for the incident and had access to its network for 5 days in August 2025.

Data stolen in the incident included names, dates of birth, Social Security numbers, passport numbers, driver’s license number/state ID numbers, medical information, and health insurance information. HIPAA-Regulated Entity State Covered Entity Type Individuals Affected Cause of Breach Xsolis, Inc. TN Business Associate 1,396,519 Network server hacking incident MCBS, LLC GA Business Associate 1,261,464 Data theft and extortion incident (PEAR) Centers Lab NJ LLC NJ Healthcare Provider 542,377 Data theft and extortion incident (Worldleaks) Anatomic and Clinical Laboratory Associates, P.

C. TN Healthcare Provider 169,626 Network server hacking incident Operation PAR, Inc. FL Business Associate 145,714 Data theft and extortion incident (Worldleaks) Chicago Family Health Center IL Healthcare Provider 90,000 Network server hacking incident Aitkin County Health and Human Services MN Business Associate 83,114 Phishing incident Minnesota Epilepsy Group, P.

A. MN Healthcare Provider 80,061 Network server hacking incident Gay & Lesbian Community Services Center of Orange County, Inc. CA Healthcare Provider 75,532 Network server hacking incident Colorado Health Network Inc.

CO Healthcare Provider 68,212 Network server hacking incident – data theft confirmed Women’s Center for Radiology FL Healthcare Provider 66,422 Network server hacking incident Blue Fish Pediatrics TX Healthcare Provider 62,150 Network server hacking incident NYC Health + Hospitals NY Healthcare Provider 58,778 Hacking incident at business associate UnitedHealth Care Services, Inc.

Single Affiliated Covered Entity CT Health Plan 37,384 Phishing incident at business associate UnitedHealth Care Services, Inc.

Originally published at hipaajournal.com

Share
▸ Want a deeper look?

Talk to an architect about applying this to your stack.

60-minute technical evaluation, no obligation. We'll map the ideas in this article to your environment.

Skip to main content