Utopia Tech
Healthcare4 min read

Report Shows Surge in Malicious Insider Incidents; Mega Data Breaches

There has been a general trend of increasing data breaches over the past decade, with this year on track to set a new record. According to the H1 2026 Data Breach Report from the Identity Theft Resource Center (ITRC), there have been at least 1,803 data compromises in H1 2026, which will give an annual total of more than 3,600 data compromises if they continue to occur at a sim

UT

Utopia Tech

July 23, 2026 · 4 min read

Share

There has been a general trend of increasing data breaches over the past decade, with this year on track to set a new record. According to the H1 2026 Data Breach Report from the Identity Theft Resource Center (ITRC), there have been at least 1,803 data compromises in H1 2026, which will give an annual total of more than 3,600 data compromises if they continue to occur at a similar rate as the first half of the year.

Across those data compromises, there have been 1,394 confirmed data breaches (excluding leaks, exposures, and unknown incidents), accounting for 77% of total events. More than 471 million victim notices have been issued, which already exceeds the total number of victim notices for all of 2025, and there are still six months of the year to go. While at the current rate, this year is unlikely to beat the total for 2024, even with only 6 months of data, 2026 already ranks as one of the worst years to date.

As ITRC explains in the report, part of the reason is the return of mega data breaches, the biggest of which involved the Instructure Holdings’ Canvas platform, which accounted for an estimated 275 million of those notices. A mega data breach at Under Armour involved more than 72. 7 million notices, while the SoundCloud data breach saw 29.

8 million victim notices issued. There were no healthcare data breaches in the top 10 data compromise list, in contrast to H1, 2025, when three healthcare data breaches made it into the top 5. In fact, based on breach reporting to the HHS’ Office for Civil Rights, there have been relatively few mega data breaches in healthcare.

In H1 2026, only 7 healthcare data breaches required more than 1 million notices. HIPAA-Regulated Entity State Entity Type Type of Breach Individuals Affected TriZetto Provider Solutions MO Business Associate Hacking/IT Incident 3,433,965 QualDerm Partners, LLC TN Healthcare Provider Hacking/IT Incident 3,117,874 Nacogdoches Memorial Hospital n TX Healthcare Provider Hacking/IT Incident 2,507,073 Navia Benefit Solutions, Inc.

WA Business Associate Hacking/IT Incident 2,151,330 Insightin Health, Inc. MD Business Associate Hacking/IT Incident 1,949,534 New York City Health and Hospitals Corporation NY Healthcare Provider Hacking/IT Incident 1,800,000 Xsolis, Inc. TN Business Associate Hacking/IT Incident 1,396,519 While very large data breaches may have been reported in lower numbers in the first half of the year, healthcare data breaches continue to be reported in volume.

The ITRC tracking data show 281 healthcare data compromises in the first half of the year, which puts the industry in second spot behind financial services with 387 compromises. The data for 2025 show a slight year-over-year fall in financial services data breaches, from 396 in H1, 2025, and a slight increase in healthcare data breaches, rising from 270 in H1, 2025.

Across the 281 healthcare data breaches, more than 11. 7 million patients have been affected. Current OCR data (from July 23, 2026) show that number has already more than doubled to over 28.

8 million victims, although the total is still well below last year’s H1, 2026 count of 42. 8 million healthcare victims. As ITRC has reported for several years, the trend of withholding important information from breach notices has continued.

ITRC reports that 76% of all notices failed to include information about the attack vector (1,378 notices). Only 24% of notices contained information about the attack vector – the lowest ever rate since ITRC has been producing its data breach reports. “This opacity prevents consumers, businesses and policymakers from understanding their true risk exposure or taking meaningful preventive action,” explained ITRC.

To put that total into perspective, 93% of victim notices included information about the attack vector in 2021. The ITRC data show a significant increase in insider wrongdoing incidents, with 21 such incidents identified in H1, 2026, compared to just 3 in all of 2025 – a sevenfold increase. ITRC tracked 14 zero-day attacks in H1 2026, which is close to the total of 17 for all of 2025.

While there were only 38 tracked supply chain incidents in H1 2026, they required more than 280. 6 million victim notices. “Supply chain cyberattacks alone accounted for 199 of 206 affected entities and 280.

6 million of 280. 6 million combined victim notices,” explained ITRC in the report. Cyberattacks accounted for 69.

7% of data breaches in H1, 2026, and 92. 3% of all victim notices. System and human error accounted for 6.

9% of breaches and 0. 9% of victim notices. By far the main cause of cyberattacks was phishing/smishing/BEC, with 157 incidents, followed by system & human error (125 incidents), and ransomware attacks (76 incidents), although 402 events remain unclassified due to the lack of transparency about breach causes.

Total cyberattacks are down 7. 8% compared to H1, 2025, with ransomware attacks up by 4. 1%.

The post Report Shows Surge in Malicious Insider Incidents; Mega Data Breaches appeared first on The HIPAA Journal .

Originally published at hipaajournal.com

Share
▸ Want a deeper look?

Talk to an architect about applying this to your stack.

60-minute technical evaluation, no obligation. We'll map the ideas in this article to your environment.

Skip to main content