Publish date
August 5, 2026
{x} minute read
Written by
Reviewed by
Table of contents

Healthcare holds some of the most sensitive personal data in existence, and the 34 incidents ranked below show how far the damage can spread when it leaks. This list is current as of July 2026 and led by Change Healthcare at 192.7 million individuals (final) and Conduent at 62,224,658, the two largest healthcare data breaches on record. Between them, those two incidents alone exposed records for close to three-quarters of the US population.

The scale is structural, not accidental. Care delivery depends on a concentrated web of clearinghouses, insurers, and business associates, so one compromise can reach thousands of providers and payers at once. The ranking draws on the HHS Office for Civil Rights (OCR) breach portal, regulatory filings, and verified reporting.

Healthcare breach statistics from the HHS OCR portal and IBM Cost report

Between October 21, 2009, and April 30, 2026, the HHS OCR breach portal recorded 7,670 large breaches affecting 500 or more individuals, as compiled by the HIPAA Journal. Of those, 936 were listed as under investigation or awaiting investigation, up from 882 in 2024, and that backlog keeps growing while OCR's budget stays flat.

The year 2025 set a record for breach volume with 772 large healthcare breaches, roughly 4% above the previous record of 746 set in 2023, affecting about 138.5 million individuals at an average of 2.1 breaches per day. The year 2024 remains the worst on record for individuals affected, with more than 289 million people exposed, close to 85% of the US population, a total driven overwhelmingly by Change Healthcare. The cause mix has shifted decisively toward external attacks, with hacking and other IT incidents accounting for more than 80% of large healthcare breaches in 2025 while loss and theft, once dominant, are now rare. For the picture beyond this sector, our data breach statistics track the same trends across every industry.

Year-to-date 2026 shows 252 large breaches reported between January 1 and April 30, 9.5% fewer than the same period in 2025. That decline needs a caveat: HHS was largely shut down for 43 days from October 1 to November 12, 2025, during the longest US government shutdown, and OCR was still catching up on March 2026 breaches as of June 2026. The 2026 count should be treated as incomplete rather than as evidence of a real decline. The cost side reinforces why this matters, because the IBM Cost of a Data Breach Report 2025 put the average healthcare breach at USD 7.42 million, the highest of any industry, with the longest lifecycle of any sector at 279 days, against a global all-industry average of USD 4.44 million and a US average of USD 10.22 million.

34 biggest healthcare data breaches

This list ranks breaches by individuals affected as reported to regulators. Counts are shown as finalized where confirmed; disputed, estimated, or attacker-claimed figures are flagged so you can weigh them accordingly.

1. Change Healthcare (UnitedHealth Group)

Records affected: 192,700,000 (final figure, heavily revised)
Date of breach: initial intrusion around February 12, 2024; ransomware deployed February 21, 2024 | Disclosed: February 21, 2024, with the victim count confirmed in stages through July 31, 2025
Country: United States | Sub-sector: healthcare claims clearinghouse and revenue cycle management (HIPAA business associate) | Attack vector: ALPHV/BlackCat ransomware via stolen credentials on a Citrix remote access portal that lacked multi-factor authentication (MFA) | Data exposed: names, addresses, dates of birth, Social Security numbers, government ID numbers, health insurance and policy numbers, Medicaid and Medicare IDs, diagnoses, medications, test results, images, treatment and care plans, billing and claims data, payment card and bank account details

Change Healthcare processes roughly a third of all US patient records and about 15 billion healthcare transactions a year, so taking it offline broke prescription filling, claims submission, and provider payments nationwide for weeks. It also ranks among the largest data breaches on record across every sector, not just healthcare. Attackers used stolen credentials to reach a Citrix portal without MFA, moved laterally for about nine days, then deployed ransomware. UnitedHealth paid a ransom of approximately USD 22 million to ALPHV, which then absconded with the funds, after which affiliate-linked group RansomHub attempted a second extortion round using the same data.

Aftermath: OCR opened an investigation on March 13, 2024, and UnitedHealth reported roughly USD 3.1 billion in cyberattack-related impacts for full-year 2024, the most expensive healthcare cyber incident ever recorded. The affected count climbed from a placeholder of 500 individuals filed in July 2024, to 100 million in October 2024, to 190 million in January 2025, before Change notified OCR of 192.7 million on July 31, 2025. No OCR civil monetary penalty had been announced as of July 2026. (HIPAA Journal, TechTarget)

2. Anthem Inc.

Records affected: 78,800,000
Date of breach: approximately February 18, 2014 to January 27, 2015 | Disclosed: February 4, 2015
Country: United States | Sub-sector: health insurance / health plan | Attack vector: spear phishing leading to credential theft and remote access tools, attributed by US investigators to Chinese state-linked actors | Data exposed: names, dates of birth, Social Security numbers, member IDs, addresses, email addresses, employment and income data (Anthem said medical records and payment card data were not taken)

Anthem held the record for the largest healthcare breach for nearly a decade. Attackers gained a foothold through a phishing email opened by an employee at a subsidiary, then queried the enterprise data warehouse for months without detection. The breach became the sector's canonical wake-up call and drove wide adoption of data segmentation, encryption at rest, and shorter data retention, and it still appears near the top of the biggest US data breaches.

Aftermath: Anthem reached a USD 115 million class action settlement in 2017, then the largest data breach settlement in US history, and a USD 16 million HIPAA settlement with OCR in October 2018 that remains the largest HIPAA monetary settlement OCR has reached. A USD 39.5 million multistate attorney general settlement in 2020 covered 43 states and DC, alongside a separate USD 8.7 million settlement with California. (HHS OCR, HIPAA Journal)

3. Conduent Business Services LLC

Records affected: 62,224,658 (revised upward repeatedly)
Date of breach: unauthorized access from October 21, 2024, detected January 13, 2025 | Disclosed: operational disruption disclosed January 2025, SEC 8-K April 2025, final OCR figure filed mid-2026
Country: United States | Sub-sector: business process outsourcing for health plans, providers, and government agencies (HIPAA business associate) | Attack vector: network intrusion with roughly three months of undetected access and data exfiltration | Data exposed: names, addresses, Social Security numbers, medical records, and for some individuals government benefit information

Conduent provides printing, mailing, document processing, payment integrity, and back-office services to health plans, providers, and state Medicaid and benefits agencies, which is why a single vendor compromise scaled to tens of millions of people. It now ranks as the third-largest healthcare data breach of all time behind Change Healthcare and Anthem, and among the largest US breaches of any kind. The incident is a textbook illustration of concentration risk in the healthcare supply chain.

Aftermath: the affected total climbed from an initial estimate of roughly 10 million, to about 25 million in February 2026, to 62,224,658 in the updated report Conduent filed with OCR in mid-2026. Conduent offered 12 months of complimentary credit monitoring, multiple state attorneys general opened scrutiny of the notification timeline, and class action litigation is pending. No fine had been announced as of July 2026. (HIPAA Journal, Malwarebytes)

4. Viamedis and Almerys (France)

Records affected: approximately 33,000,000 combined, roughly half the French population (CNIL figure)
Date of breach: late January to early February 2024 | Disclosed: February 2024
Country: France | Sub-sector: third-party payment platforms for complementary health insurers | Attack vector: compromise of healthcare professionals' login credentials, likely via phishing | Data exposed: marital status, date of birth, social security number, insurer name, and details of contractual guarantees and coverage (CNIL stated bank details, medical data, reimbursement claims, postal addresses, phone numbers, and email addresses were not affected)

Two separate but near-simultaneous intrusions at Viamedis and Almerys, the intermediaries that handle direct settlement between French health insurers and providers, produced the largest breach ever recorded in France. CNIL confirmed the scale and opened investigations into both operators as well as the insurers relying on them. The exposed combination of social security number and coverage data is highly useful for insurance and benefits fraud, which is what makes this case dangerous, and it tops the list of data breaches in France. Similar cross-border incidents appear in our roundup of breaches across Europe.

Aftermath: CNIL opened formal investigations in February 2024, wrote to the mutual insurers about their notification obligations, and warned of elevated phishing risk to the affected population. Outcomes of the investigations had not been published as of July 2026. (Infosecurity Magazine, SC Media)

5. Welltok, Inc.

Records affected: 14,782,887 (revised upward from an initial estimate of roughly 8.5 million)
Date of breach: May 2023 | Disclosed: first notifications from July 2023, continuing into 2024
Country: United States | Sub-sector: patient communications and population health SaaS (HIPAA business associate) | Attack vector: exploitation of the MOVEit Transfer zero-day (CVE-2023-34362) by the Cl0p ransomware group | Data exposed: names, addresses, dates of birth, phone numbers, email addresses, Social Security numbers, Medicare and Medicaid IDs, health insurance information, and certain health data

Welltok was the largest single healthcare victim of the Cl0p MOVEit mass-exploitation campaign, which hit more than 2,700 organizations globally. Because Welltok handled outreach for dozens of health systems and plans, notifications flowed out under many brand names, including Stanford Health Care, Sutter Health, Corewell Health, and US Radiology Specialists, which obscured the true scale for months. It remains the fourth-largest US healthcare breach on the OCR portal.

Aftermath: the incident produced consolidated class action litigation, and Welltok's parent, Virgin Pulse, faced client contract fallout. No regulatory fine had been announced as of July 2026. (HIPAA Journal, HHS OCR Breach Portal)

6. Aflac Incorporated

Records affected: 13,924,906
Date of breach: intrusion identified June 12, 2025 | Disclosed: SEC 8-K filed June 20, 2025, with OCR filing and individual notifications following
Country: United States | Sub-sector: supplemental health and life insurance (health plan) | Attack vector: social engineering of the help desk and identity infrastructure, consistent with the Scattered Spider playbook targeting US insurers in mid-2025 | Data exposed: Social Security numbers, health information, insurance claims data, and other personal information relating to customers, beneficiaries, employees, agents, and applicants

Aflac was one of several US insurers hit in a coordinated Scattered Spider campaign in June 2025 that relied on human-operated social engineering rather than malware. Aflac said it stopped the intrusion within hours, but the volume of records reachable in that window made it the fifth-largest healthcare breach ever reported to OCR. The case underlines that identity and help desk verification, not endpoint tooling, is now the decisive control, a lesson that also runs through the biggest financial services data breaches.

Aftermath: class action litigation followed within weeks of the 8-K, and Aflac offered 24 months of credit monitoring and identity theft protection to all affected individuals. The OCR investigation was open with no penalty announced as of July 2026. (HIPAA Journal, Reuters)

7. Kaiser Foundation Health Plan (Kaiser Permanente)

Records affected: 13,400,000
Date of breach: ongoing over an extended period, ended April 2024 when tracking code was removed | Disclosed: April 2024
Country: United States | Sub-sector: integrated health plan and provider | Attack vector: no intrusion; third-party website and mobile app tracking technologies transmitted member activity data to Google, Microsoft Bing, and X (formerly Twitter) | Data exposed: member names, IP addresses, indications that a member was signed in, search terms entered into the health encyclopedia, and how members navigated the sites and apps

This is the largest of the healthcare pixel-tracking disclosures and remains the largest breach ever classified by OCR as unauthorized access or disclosure rather than hacking. No attacker was involved. Kaiser's own marketing analytics stack routinely sent identifiable browsing signals about health topics to advertising platforms, which established that ordinary web analytics can produce a reportable HIPAA breach at a scale rivaling a nation-state intrusion.

Aftermath: Kaiser removed the tracking code, reported the incident to OCR, and faced class action litigation. The case sits inside a broader regulatory arc, including a July 2023 joint OCR and FTC warning letter to roughly 130 hospital systems and telehealth providers, and a June 2024 Texas federal court ruling that partly vacated OCR's December 2022 tracking-technologies bulletin. (HIPAA Journal, HHS OCR Breach Portal)

8. MediSecure (Australia)

Records affected: approximately 12,900,000
Date of breach: discovered April 13, 2024 | Disclosed: May 16, 2024, with scale confirmed July 18, 2024
Country: Australia | Sub-sector: electronic prescription exchange service | Attack vector: ransomware, entering via a compromised third-party vendor | Data exposed: names, dates of birth, addresses, Medicare card numbers, healthcare concession card numbers, prescription medication details, and prescriber information

MediSecure was one of two national e-prescription exchanges in Australia, and roughly half the population had records in the stolen dataset, drawn from prescriptions dispensed between March 2019 and November 2023. The company entered voluntary administration in June 2024, saying it could not fund the response, and the Australian government declined a bailout. It is the largest health-sector breach in Australian history by individuals affected, and one of the biggest Australian data breaches of any kind.

Aftermath: MediSecure appointed administrators on June 3, 2024, and the business was wound up, leaving affected Australians with limited recourse. The Australian Information Commissioner and the National Cyber Security Coordinator both engaged, and the collapse became a case study in what happens when a critical health intermediary cannot absorb breach costs. (OAIC, SecurityWeek)

9. Optum360 / Quest Diagnostics (via American Medical Collection Agency)

Records affected: 11,500,000 (Quest patients, reported to OCR by business associate Optum360)
Date of breach: August 1, 2018 to March 30, 2019 | Disclosed: June 3, 2019
Country: United States | Sub-sector: clinical laboratory / medical debt collection | Attack vector: unauthorized access to the web payment portal of American Medical Collection Agency (AMCA), a debt collector used by Quest's billing vendor Optum360 | Data exposed: names, dates of birth, addresses, phone numbers, dates of service, provider names, balance information, and for some individuals Social Security numbers, bank account details, and payment card data (Quest said lab test results were not affected)

The AMCA breach is the definitive fourth-party risk case in healthcare, because Quest's vendor's vendor was compromised and Quest learned of it only when AMCA payment card data appeared for sale online. More than 20 healthcare organizations ultimately reported AMCA-related breaches. The eight-month dwell time and the delayed notification drew particular criticism.

Aftermath: AMCA's parent, Retrieval-Masters Creditors Bureau, filed for Chapter 11 bankruptcy in June 2019 under the weight of notification costs. A multistate attorney general settlement in 2021 imposed a USD 21 million penalty on AMCA that was suspended based on inability to pay, and California separately reached a USD 5 million settlement with Quest in 2024. (Quest Diagnostics 8-K, KrebsOnSecurity)

10. HCA Healthcare

Records affected: 11,270,000
Date of breach: data theft discovered July 5, 2023 | Disclosed: July 10, 2023
Country: United States | Sub-sector: hospital operator (one of the largest US for-profit health systems) | Attack vector: theft of data from an external storage location used to automate the formatting of patient email messages; the attacker posted samples on a cybercrime forum | Data exposed: names, city, state, postal code, phone number, email address, date of birth, gender, and service date, location, and next-appointment date (HCA said clinical information, payment data, and Social Security numbers were not included)

HCA operates roughly 180 hospitals and 2,000 care sites, and the stolen dataset spanned 20 states. The breach is notable for what it did not include, because the compromised store held only email-formatting fields, so no clinical or financial data was exposed. That is exactly why data minimization in marketing and communications pipelines matters, and even so, 11.27 million records makes it the eighth-largest US healthcare breach.

Aftermath: more than a dozen class actions were consolidated in the Middle District of Tennessee, and HCA offered credit monitoring while stating the incident did not materially disrupt operations. No regulatory penalty had been announced as of July 2026. (HIPAA Journal, HHS OCR Breach Portal)

11. Premera Blue Cross

Records affected: 11,000,000 (OCR portal figure; Premera's own notification cited approximately 10.4 million, so the precise total is disputed)
Date of breach: initial access May 5, 2014, discovered January 29, 2015 | Disclosed: March 17, 2015
Country: United States | Sub-sector: health insurance / health plan | Attack vector: phishing-led intrusion with malware and nearly nine months of undetected access, widely attributed to the same activity cluster as the Anthem intrusion | Data exposed: names, dates of birth, Social Security numbers, member IDs, bank account information, mailing addresses, phone numbers, email addresses, and claims information including clinical data

Premera's breach was announced weeks after Anthem's and confirmed that a state-linked campaign was systematically targeting US health plans for bulk personal data. OCR's investigation found Premera had failed to conduct an accurate enterprise-wide risk analysis, failed to implement adequate audit controls, and had not responded to a known vulnerability that a security assessment had flagged. It is one of the most fully litigated and penalized healthcare breaches on record.

Aftermath: Premera reached a USD 6.85 million HIPAA settlement with OCR in September 2020, a USD 10 million multistate attorney general settlement across 30 states in July 2019, and a USD 74 million class action settlement approved in 2019 that included USD 32 million in direct consumer payments and USD 42 million in mandated security spending. (HHS OCR, HIPAA Journal)

12. Laboratory Corporation of America (LabCorp), via AMCA

Records affected: 10,251,784
Date of breach: August 1, 2018 to March 30, 2019 | Disclosed: June 4, 2019
Country: United States | Sub-sector: clinical laboratory / medical debt collection | Attack vector: the same AMCA web payment portal compromise that hit Quest Diagnostics | Data exposed: names, addresses, dates of birth, phone numbers, dates of service, balance information, and provider details; approximately 200,000 individuals also had payment card or bank account data exposed (LabCorp said no Social Security numbers or test results were involved)

LabCorp and Quest, the two dominant US reference laboratories, were breached through the identical fourth party on the identical timeline, which is why the AMCA incident is cited more than any other in healthcare vendor risk management guidance. Together the two labs account for nearly 22 million affected individuals from a single compromised payment page.

Aftermath: LabCorp terminated AMCA and stopped sending it new collection work, class actions were consolidated, and a court dismissed several claims in 2022 on standing grounds. AMCA's bankruptcy limited recovery, and Senate Finance Committee inquiries followed. (KrebsOnSecurity, HIPAA Journal)

13. Medibank Private (Australia)

Records affected: approximately 9,700,000 (current and former customers)
Date of breach: access from around August 12, 2022, detected October 12, 2022 | Disclosed: October 13, 2022, with escalating confirmations through November 2022
Country: Australia | Sub-sector: private health insurance | Attack vector: stolen credentials belonging to a third-party IT contractor, used via a misconfigured firewall that did not require a digital certificate on an account that lacked MFA; attributed to REvil-linked Russian actors | Data exposed: names, dates of birth, addresses, phone numbers, email addresses, Medicare numbers, passport numbers for international students, and for around 480,000 people health claims data including diagnoses and procedures

Medibank refused to pay the ransom on the stated grounds that paying would incentivize further attacks, and the attackers responded by publishing stolen health data on the dark web in themed tranches, including files labeled to expose abortions, mental health treatment, and addiction care. That deliberate weaponization of sensitive diagnoses, aimed at individuals rather than the company, changed the Australian policy conversation and directly informed the 2022 amendments raising privacy penalties to the greater of AUD 50 million, three times the benefit obtained, or 30% of adjusted turnover.

Aftermath: the Australian Information Commissioner commenced Federal Court civil penalty proceedings in June 2024, APRA imposed an additional AUD 250 million capital adequacy requirement, and Medibank reported total expected costs of AUD 126 million to AUD 132 million. The Australian government imposed cyber sanctions on Russian national Aleksandr Ermakov in January 2024, its first use of that power. (OAIC, Reuters)

14. Excellus Health Plan (Excellus BlueCross BlueShield)

Records affected: 9,358,891
Date of breach: December 23, 2013 to May 11, 2015, discovered August 5, 2015 | Disclosed: September 9, 2015
Country: United States | Sub-sector: health insurance / health plan | Attack vector: sustained intrusion with attackers installing malware and conducting reconnaissance for roughly 17 months | Data exposed: names, dates of birth, Social Security numbers, mailing addresses, telephone numbers, member identification numbers, financial account information, and claims data

Excellus went undetected for close to a year and a half, one of the longest dwell times in a major healthcare breach. OCR's investigation found failures in risk analysis, information system activity review, technical access controls, and business associate management. The case is frequently cited for the gap between having security policies and actually operating monitoring capability.

Aftermath: Excellus reached a USD 5.1 million HIPAA settlement with OCR in January 2021 and a USD 17.3 million class action settlement, alongside multiple state attorney general inquiries. (HHS OCR, HIPAA Journal)

15. Episource, LLC

Records affected: 6,725,572 (revised upward from an initial estimate of approximately 5.4 million)
Date of breach: January 27, 2025 to February 6, 2025, detected February 6, 2025 | Disclosed: notifications began April 24, 2025
Country: United States | Sub-sector: medical coding, risk adjustment, and analytics vendor (HIPAA business associate) | Attack vector: unauthorized network access with data exfiltration over an 11-day window; ransomware-adjacent activity | Data exposed: names, addresses, phone numbers, email addresses, dates of birth, Social Security numbers, health insurance information, Medicaid and Medicare numbers, and clinical data including diagnoses, test results, medications, and treatment information

Episource performs risk adjustment coding for health plans and provider groups, which means it holds unusually complete clinical records for the members it processes. It was the largest healthcare breach reported in the first half of 2025 and the second-largest reported for calendar 2025 after Conduent. Sharp Healthcare and Sharp Community Medical Group were among the largest downstream clients notified.

Aftermath: Episource offered 12 months of credit monitoring and identity protection, class actions were filed in California, and the OCR investigation was open with no penalty announced as of July 2026. (HIPAA Journal, HHS OCR Breach Portal)

16. Community Health Systems

Records affected: 6,121,158 under the provider-entity OCR report, plus a separate 4,500,000 theft report filed as a business associate (the originally announced 2014 figure was 4.5 million, later revised upward on the OCR portal)
Date of breach: April to June 2014 | Disclosed: August 18, 2014 via SEC 8-K
Country: United States | Sub-sector: hospital operator | Attack vector: exploitation of the Heartbleed vulnerability (CVE-2014-0160) in a Juniper networking device to steal credentials, then VPN access; attributed by Mandiant to Chinese group APT18 | Data exposed: names, addresses, dates of birth, telephone numbers, and Social Security numbers of patients referred to or treated by CHS-affiliated physicians over the prior five years (CHS said clinical and payment card data were not taken)

CHS was the first major demonstration that a widely publicized open-source vulnerability could be turned into a mass healthcare data theft within weeks of disclosure. It was also one of the earliest healthcare breaches disclosed via an SEC 8-K, presaging the disclosure regime that became mandatory in December 2023. CHS separately suffered a second major exposure in 2023 through the Fortra GoAnywhere zero-day, affecting roughly 1 million people.

Aftermath: CHS reached a USD 3.1 million class action settlement approved in 2019 and a 2020 multistate attorney general settlement imposing a USD 5 million penalty across 28 states, with total incident costs the company disclosed exceeding USD 100 million. (SEC 8-K, HIPAA Journal)

17. Yale New Haven Health System

Records affected: 5,556,702
Date of breach: March 8, 2025, detected the same day | Disclosed: April 11, 2025
Country: United States | Sub-sector: academic health system (Connecticut's largest) | Attack vector: unauthorized third-party access to the network with data copied out; no ransomware deployment and no disruption to clinical operations | Data exposed: names, dates of birth, addresses, phone numbers, email addresses, race and ethnicity, Social Security numbers, patient type, and medical record numbers (no financial account information, treatment records, or test results were involved)

Yale New Haven detected the intrusion on the day it happened and kept every hospital and clinic running, which is the operational outcome the sector aims for. The exfiltrated dataset was still large enough to make this the largest single-provider breach reported in 2025. It shows that fast detection limits disruption but does not necessarily limit data loss.

Aftermath: Yale New Haven offered credit monitoring and identity protection, at least a dozen class actions were filed in Connecticut and consolidated, and the OCR investigation was open with no penalty announced as of July 2026. (Yale New Haven Health, BleepingComputer)

18. Ascension

Records affected: 5,466,931
Date of breach: detected May 8, 2024 | Disclosed: May 8, 2024 (incident), December 20, 2024 (scope and count)
Country: United States | Sub-sector: non-profit health system (140 hospitals across 19 states and DC) | Attack vector: Black Basta ransomware; Ascension concluded an employee downloaded a malicious file they believed to be legitimate | Data exposed: names, addresses, phone numbers, email addresses, dates of birth, Social Security numbers, taxpayer IDs, medical record numbers, insurance and payment information, and clinical data including diagnoses, admission and discharge dates, physician names, test results, and prescriptions

Ascension diverted ambulances, reverted to paper charting, and lost access to electronic health records, e-prescribing, and phone systems across 19 states for several weeks. It is the most operationally severe US hospital ransomware event after Change Healthcare, and it was caused by a single mis-clicked download rather than an exploited vulnerability. Ascension reported a separate 2025 breach affecting approximately 437,000 people through a former business partner's software vulnerability.

Aftermath: Ascension reported roughly USD 1.3 billion in operating losses for FY2024 with the cyberattack a contributing factor, more than 30 class actions were consolidated, and congressional letters were sent to leadership. The OCR investigation was open with no penalty announced as of July 2026. (Ascension, HIPAA Journal)

19. Science Applications International Corporation (SAIC) / TRICARE

Records affected: 4,900,000
Date of breach: September 13, 2011 | Disclosed: September 29, 2011
Country: United States | Sub-sector: military health system (TRICARE Management Activity), via defense contractor and business associate SAIC | Attack vector: physical loss; unencrypted backup tapes stolen from the parked car of an SAIC employee in San Antonio, Texas | Data exposed: names, Social Security numbers, addresses, dates of birth, phone numbers, and clinical data including lab test results, prescriptions, and clinical notes for military personnel, retirees, and families treated in the San Antonio area since 1992

This remains the largest healthcare breach in US history caused by physical loss rather than hacking, and one of the largest breaches of military personnel data. Nineteen years of clinical records for service members and their dependents sat unencrypted on tapes in a private vehicle. It is the reference case for why encryption at rest for backup media became non-negotiable and why OCR's safe harbor for encrypted data matters.

Aftermath: class actions seeking USD 4.9 billion were largely dismissed for lack of demonstrated harm, a ruling that shaped US breach litigation standing doctrine for years, and the Department of Defense reviewed contractor data handling requirements. SAIC lost the contract renewal, and no OCR penalty was imposed. (HHS OCR Breach Portal, Reuters)

20. Blue Shield of California

Records affected: 4,700,000
Date of breach: April 2021 to January 2024 | Disclosed: April 2025, reported to OCR April 9, 2025
Country: United States | Sub-sector: health plan (reported to OCR as a business associate) | Attack vector: no intrusion; a Google Analytics configuration on member-facing pages allowed protected health information to flow into Google Ads | Data exposed: insurance plan name, type, and group number, city, postal code, gender, family size, Blue Shield-assigned member identifiers, and information about members' online searches and interactions including find-a-doctor searches and claim details

Blue Shield of California discovered in February 2025 that a misconfiguration had been leaking member data to Google's advertising stack for nearly three years before it was severed in January 2024. Together with Kaiser's 13.4 million, this made analytics and advertising misconfiguration one of the largest single categories of healthcare data exposure in the 2024 to 2025 period, and both incidents involved zero adversary activity. Blue Shield said it found no evidence the data was used for anything other than Google's own advertising purposes.

Aftermath: Blue Shield severed the connection in January 2024 and notified OCR in April 2025, and multiple class actions were filed in California, including claims under the California Invasion of Privacy Act and CMIA. The OCR investigation was open with no penalty announced as of July 2026. (HIPAA Journal, HHS OCR Breach Portal)

21. Advocate Medical Group (Advocate Health and Hospitals Corporation)

Records affected: 4,029,530
Date of breach: July 15, 2013, with two related 2013 incidents | Disclosed: August 2013
Country: United States | Sub-sector: physician group / health system | Attack vector: theft; four unencrypted desktop computers stolen from an administrative office, plus a related unencrypted laptop theft and a business associate network compromise | Data exposed: names, addresses, dates of birth, Social Security numbers, credit card numbers with expiration dates, demographic data, and clinical information including diagnoses, medical record numbers, service codes, and health insurance information

Three separate 2013 incidents at Advocate were investigated together by OCR and produced what was then the largest HIPAA settlement against a single entity. OCR found Advocate had failed to conduct an accurate enterprise-wide risk assessment, failed to implement policies limiting physical access, failed to obtain adequate business associate assurances, and failed to safeguard an unencrypted laptop left in an unlocked vehicle overnight.

Aftermath: Advocate reached a USD 5.55 million HIPAA settlement with OCR in August 2016, the largest to that date, plus a corrective action plan and class action litigation in Illinois. The case is OCR's most cited example of cumulative penalty exposure from multiple related lapses. (HHS OCR, HIPAA Journal)

22. TriZetto Provider Solutions (Cognizant)

Records affected: 3,433,965
Date of breach: 2025 (breach report submitted to OCR in 2026) | Disclosed: 2026
Country: United States | Sub-sector: revenue cycle management and claims clearinghouse (HIPAA business associate, part of Cognizant) | Attack vector: hacking / IT incident with data exfiltration | Data exposed: protected health information handled on behalf of provider clients, including identifiers and claims and billing data (exact field list unverified pending fuller notification detail)

TriZetto Provider Solutions is a large claims clearinghouse serving tens of thousands of provider organizations, and this is the biggest new healthcare breach to surface on the OCR portal in 2026. It is another clearinghouse-layer compromise, the same structural position that made Change Healthcare and Conduent so damaging, where one vendor sits between thousands of providers and hundreds of payers so a single intrusion aggregates records across the chain.

Aftermath: notifications were issued and credit monitoring offered, and an OCR investigation is expected given the size. Litigation and regulatory outcomes were not yet known as of July 2026, so details other than the OCR-posted count should be treated as provisional. (HHS OCR Breach Portal, HIPAA Journal)

23. Trinity Health (via Blackbaud)

Records affected: 3,320,726
Date of breach: April 7, 2020 to May 16, 2020 | Disclosed: July 2020
Country: United States | Sub-sector: non-profit Catholic health system, breached through its donor management platform | Attack vector: ransomware and data theft at Blackbaud, the cloud fundraising and CRM provider, which paid the attackers for assurances the data would be destroyed | Data exposed: names, addresses, dates of birth, phone numbers, email addresses, and for some individuals Social Security numbers, financial account information, and limited clinical data held in the philanthropy database

Trinity Health was the largest of the roughly 100 healthcare victims of the Blackbaud incident and remains the single largest breach originating from a fundraising or donor system rather than a clinical one. It matters because philanthropy databases are typically outside the scope of clinical security programs yet frequently contain patient status, department, and physician data that is squarely PHI under HIPAA.

Aftermath: Blackbaud paid a USD 3 million SEC penalty in March 2023 for misleading disclosures, a USD 49.5 million multistate attorney general settlement in October 2023, and settled with the FTC in February 2024 with an order to delete unnecessary data. Trinity Health faced consolidated class action litigation. (SEC, FTC)

24. QualDerm Partners, LLC

Records affected: 3,117,874
Date of breach: 2025 (breach report submitted to OCR in 2026) | Disclosed: 2026
Country: United States | Sub-sector: dermatology practice management group (150-plus clinics across multiple states) | Attack vector: hacking / IT incident with data exfiltration | Data exposed: patient identifiers and clinical and billing data across QualDerm's affiliated practices (exact field list unverified pending fuller notification detail)

QualDerm is one of the two largest new healthcare breaches posted to the OCR portal in 2026 and shows that private-equity-consolidated specialty practice groups now carry the same aggregation risk as hospital systems. Because the parent entity operates shared IT for dozens of clinic brands, a single compromise reaches every practice in the platform, and patients often will not recognize the notifying entity's name.

Aftermath: notifications were issued and credit monitoring offered, and an OCR investigation is expected given the size. Litigation and regulatory outcomes were not yet known as of July 2026, so details other than the OCR-posted count should be treated as provisional. (HHS OCR Breach Portal, HIPAA Journal)

25. Advocate Aurora Health (pixel tracking)

Records affected: 3,000,000
Date of breach: ongoing exposure ending October 2022 when tracking code was disabled | Disclosed: October 12, 2022
Country: United States | Sub-sector: health system | Attack vector: no intrusion; Meta Pixel and Google Analytics tags on patient portals, scheduling pages, and MyChart-linked properties transmitted patient interaction data to Meta and Google | Data exposed: IP address, scheduled appointment information including type, date, location, and provider, proximity to an Advocate Aurora location, MyChart communications including name and provider, and information entered into the online scheduling widget

Advocate Aurora was the first health system to formally report pixel tracking to OCR as a HIPAA breach at multi-million scale, and it triggered the wave that later included Kaiser, Novant Health, and Cedars-Sinai. The significance is doctrinal, because Advocate Aurora conceded that routine marketing analytics on patient-facing pages constituted an impermissible disclosure of PHI to third parties. That admission reframed adtech as a HIPAA compliance problem rather than a marketing decision.

Aftermath: Advocate Aurora disabled the tracking code and notified OCR and affected patients, and class actions were filed in Wisconsin and Illinois. Novant Health separately settled a comparable pixel case for USD 6.6 million. (HIPAA Journal, FTC and HHS OCR joint letter)

26. PIH Health

Records affected: 2,947,264
Date of breach: December 1, 2024 | Disclosed: December 2024, with the full count reported to OCR in 2025
Country: United States | Sub-sector: regional non-profit health system (three hospitals in Southern California) | Attack vector: ransomware; attackers encrypted systems and exfiltrated approximately 17 terabytes of data | Data exposed: names, addresses, dates of birth, Social Security numbers, driver's license numbers, medical record numbers, health insurance information, and clinical data including diagnoses, treatment, and prescription information

PIH Health's phone systems, internet, email, and electronic medical records all went down, and the system diverted patients and canceled procedures across three hospitals for more than a week. The attackers publicly threatened to leak the stolen data unless paid. It is one of the largest ransomware breaches of a purely regional US health system, showing that scale of impact does not require scale of organization, and it reinforces the case for the steps to prevent data breaches that hospitals of any size can adopt.

Aftermath: PIH Health notified affected individuals and offered credit monitoring, class actions were filed in California, and the OCR investigation was open with no penalty announced as of July 2026. (PIH Health, HIPAA Journal)

27. DaVita Inc.

Records affected: 2,689,826
Date of breach: discovered April 12, 2025 | Disclosed: SEC 8-K filed April 14, 2025; count reported to OCR later in 2025
Country: United States | Sub-sector: dialysis services provider (approximately 2,650 US outpatient centers) | Attack vector: Interlock ransomware, which encrypted part of the network and exfiltrated data, claiming close to 1.5 terabytes | Data exposed: names, addresses, dates of birth, Social Security numbers, health insurance information, and clinical data including dialysis lab test results, treatment information, and for some individuals images of checks

DaVita treats patients who cannot safely miss appointments, so a ransomware event in dialysis carries direct clinical risk rather than just administrative disruption. DaVita kept centers open using contingency processes but confirmed the attack affected some operations. It is the largest healthcare breach reported in 2025 by a specialty outpatient provider.

Aftermath: DaVita disclosed in its Q2 2025 results that it expected roughly USD 13.5 million in incident-related costs for the year alongside revenue impacts, and class actions were consolidated. The OCR investigation was open with no penalty announced as of July 2026. (SEC 8-K, HIPAA Journal)

28. Nacogdoches Memorial Hospital

Records affected: 2,507,073
Date of breach: 2025 or 2026 (breach report submitted to OCR in 2026) | Disclosed: 2026
Country: United States | Sub-sector: community hospital (Texas) | Attack vector: hacking / IT incident with data exfiltration | Data exposed: patient identifiers and clinical and billing data (exact field list unverified pending fuller notification detail)

At more than 2.5 million individuals, this is by far the largest breach ever reported by a single community hospital, and the count vastly exceeds the population Nacogdoches Memorial serves directly, implying the compromised systems held historical or affiliated-network records. It is the third of the very large 2026 OCR postings alongside TriZetto and QualDerm. The entity name is truncated on the OCR portal.

Aftermath: notifications were issued and an OCR investigation is expected given the size. No litigation or regulatory outcome was known as of July 2026, so all details other than the OCR-posted count should be treated as provisional and unverified. (HHS OCR Breach Portal, HIPAA Journal)

29. 21st Century Oncology

Records affected: 2,213,597
Date of breach: October 2015, with FBI notifications November 13, 2015 and March 25, 2016 | Disclosed: March 2016
Country: United States | Sub-sector: cancer care provider (radiation oncology network) | Attack vector: unauthorized third-party access to a company database via an unauthorized remote connection, discovered by the FBI rather than the company | Data exposed: names, Social Security numbers, physicians' names, diagnoses, treatment information, and insurance data

21st Century Oncology learned of its own breach twice from the FBI and delayed notification at the FBI's request pending investigation. OCR's investigation found the company had failed to conduct an accurate risk analysis, failed to regularly review information system activity such as audit logs and access reports, and had disclosed PHI to third-party vendors without business associate agreements. It is the clearest healthcare case of a breach found only because law enforcement stumbled on the data.

Aftermath: the company filed for Chapter 11 bankruptcy in May 2017, and its USD 2.3 million HIPAA settlement with OCR in December 2017 had to be approved by the bankruptcy court. It also reached a USD 2.9 million class action settlement over the breach. (HHS OCR, HIPAA Journal)

30. Cencora (formerly AmerisourceBergen)

Records affected: aggregate total not confirmed by Cencora; public reporting compiled notifications from more than 25 manufacturers into a combined figure widely put at over 1.4 million individuals, which should be treated as unverified
Date of breach: data exfiltration detected February 21, 2024 | Disclosed: SEC 8-K filed February 27, 2024; downstream patient notifications ran from May 2024 into 2025
Country: United States (with affected patients in multiple countries) | Sub-sector: pharmaceutical distribution and patient support services | Attack vector: unauthorized access with data exfiltration; Cencora has not detailed the initial access method | Data exposed: names, addresses, dates of birth, health diagnoses, and medications prescribed, held in connection with patient support and copay assistance programs

Cencora ran patient support programs for manufacturers including Novartis, AbbVie, Bayer, Regeneron, Genentech, GSK, Bristol Myers Squibb, and Novo Nordisk, so the stolen dataset amounted to a list of named individuals matched to specific, often stigmatizing diagnoses and drug regimens. Because each manufacturer notified its own patients separately, the incident was never aggregated into a single public count, which is precisely why it is under-recognized relative to its true scale. Cencora reportedly paid a ransom of approximately USD 75 million in bitcoin, which Cencora has never confirmed and remains unverified.

Aftermath: Cencora stated the incident did not have a material adverse effect on operations, class actions were filed in the Eastern District of Pennsylvania, and breach reporting obligations fell across many entities, producing dozens of separate OCR portal entries. No regulatory penalty had been announced as of July 2026. (SEC 8-K, HIPAA Journal)

31. Frederick Health Medical Group

Records affected: 934,326
Date of breach: ransomware detected January 27, 2025 | Disclosed: reported to OCR March 28, 2025, with notifications from late March 2025
Country: United States | Sub-sector: regional health system (Maryland: one hospital plus a large medical group) | Attack vector: ransomware; an unauthorized actor gained network access and copied files from a file share server, while the electronic medical record system itself was not accessed | Data exposed: names, addresses, dates of birth, Social Security numbers, driver's license numbers, medical record numbers, health insurance information, and clinical information relating to patient care

Frederick Health had to take its entire network offline, divert ambulances, and revert to paper for roughly two weeks, affecting a hospital and around 25 outpatient locations serving most of Frederick County. The breach illustrates the standing risk of unstructured file shares, because the well-defended EMR was untouched and the damage came entirely from copies of records sitting on a general-purpose server. Nearly a million records from a single county-level system is disproportionate to its patient population.

Aftermath: Frederick Health offered complimentary credit monitoring and identity theft protection, multiple class actions were filed in Maryland, and the OCR investigation was open with no penalty announced as of July 2026. (HIPAA Journal, BleepingComputer)

32. Synnovis and NHS pathology services (United Kingdom)

Records affected: disputed and not officially confirmed; security firm CaseMatrix estimated data on more than 900,000 NHS patients was published, a figure Synnovis has neither corroborated nor disputed, so the 900,000 number is unverified
Date of breach: June 3, 2024 | Disclosed: June 3, 2024 (incident); NHS organizations notified by November 21, 2025; some individual notifications continued into mid-2026
Country: United Kingdom | Sub-sector: hospital pathology and diagnostic laboratory services provider to NHS trusts in south east London | Attack vector: Qilin ransomware, which encrypted Synnovis systems and exfiltrated data, later publishing roughly 400 GB on its leak site | Data exposed: patient names, NHS numbers, dates of birth, test descriptions and results including STI and cancer test data, and blood test records, along with some financial and staff data

The Synnovis attack is the most clinically harmful cyberattack in NHS history and sits high among the biggest UK data breaches. King's College Hospital and Guy's and St Thomas' NHS Foundation Trusts lost pathology capability, forcing more than 10,000 outpatient appointments and around 1,700 elective procedures to be postponed, and triggering a national call for O-negative blood donors after hospitals lost the ability to match blood types at speed. In June 2025 King's College Hospital confirmed a patient death was partly attributable to a delayed blood test result caused by the attack, the first officially acknowledged death linked to a UK cyberattack.

Aftermath: Synnovis closed its forensic investigation in November 2025, roughly 18 months after the attack, and the notification burden shifted to individual NHS trusts as data controllers. The scope kept widening, with Mid and South Essex NHS Foundation Trust confirming in June 2026 that its patients were also in the stolen dataset, and the ICO investigation remained open as of July 2026. (The Record, The Register)

33. Advanced Computer Software Group and NHS 111 (United Kingdom)

Records affected: 79,404 people had personal data taken (ICO finding); service disruption affected NHS 111 and other services used by millions
Date of breach: August 4, 2022 | Disclosed: August 2022
Country: United Kingdom | Sub-sector: IT and software supplier to the NHS, including the Adastra system used by NHS 111 and Carenotes used in mental health services | Attack vector: LockBit ransomware; attackers accessed Advanced's health and care environment through a customer account without multi-factor authentication, then moved laterally | Data exposed: phone numbers, medical records, and, for 890 people receiving care at home, details of how to gain access to their homes

The Advanced breach took NHS 111 triage systems offline and forced ambulance services, out-of-hours GP services, and mental health trusts onto paper processes, with some services degraded for months. The exposure of home access instructions for vulnerable people receiving domiciliary care was the aspect the ICO singled out as most serious. It is the leading UK enforcement precedent for holding a health-sector processor, rather than the NHS controller, directly liable.

Aftermath: the ICO issued a notice of intent in August 2024 proposing a fine of GBP 6,090,000, then confirmed a final penalty of GBP 3,076,320 in March 2025, reduced in recognition of Advanced's cooperation. The ICO found Advanced had failed to implement appropriate measures including comprehensive MFA, adequate vulnerability scanning, and adequate patch management. (ICO, Computer Weekly)

34. Australian Clinical Labs (Medlab Pathology, Australia)

Records affected: approximately 223,000 (including around 128,600 Medicare numbers and 17,500 credit card numbers)
Date of breach: February 25, 2022, with data published on the dark web by June 27, 2022 | Disclosed: October 27, 2022, eight months after the incident
Country: Australia | Sub-sector: pathology and diagnostic laboratory (Medlab Pathology, an ACL subsidiary) | Attack vector: Quantum ransomware group intrusion with data exfiltration and dark web publication | Data exposed: names, addresses, dates of birth, Medicare numbers, credit card numbers with some CVVs, and pathology test results including HIV status

The significance here is regulatory rather than scale. The Australian Information Commissioner alleged ACL took more than nine months from the ransomware attack to notify affected individuals, failed to carry out a reasonable and expeditious assessment of the breach, and failed to take reasonable steps to protect personal information despite a prior consultant report identifying deficiencies. This became the OAIC's first-ever civil penalty proceeding under the Privacy Act for a data breach.

Aftermath: the OAIC commenced Federal Court civil penalty proceedings in October 2023, and a Federal Court penalty was subsequently ordered, though the exact amount should be verified against the judgment because figures in secondary reporting are inconsistent and remain unverified. The case set the precedent that slow breach assessment and notification is independently actionable in Australia. (OAIC, OAIC proceedings)

2026 healthcare breaches confirmed so far

Three of the largest new entries on the OCR portal in 2026 are already ranked above: TriZetto Provider Solutions at 3,433,965, QualDerm Partners at 3,117,874, and Nacogdoches Memorial Hospital at 2,507,073. Beyond those, the picture for the first half of 2026 is genuinely incomplete rather than quiet.

252 large breaches were posted to the OCR portal for January 1 to April 30, 2026, 9.5% fewer than the same period in 2025, but this reflects OCR's publishing backlog after the 43-day HHS shutdown from October 1 to November 12, 2025, not a real decline. As of June 2026, OCR was still adding March 2026 breaches to the portal, so any statement that healthcare breaches fell in 2026 is not yet supportable. The largest breach reported in May 2026 was Radiology Associates of Richmond at more than 266,000 individuals, followed by a hacking incident at Western Orthopaedics affecting more than 113,000 individuals. Conduent's revision to 62,224,658, filed with OCR in mid-2026, means the third-largest healthcare breach of all time only became visible at full scale during the first half of the year. (HIPAA Journal, May 2026 report, HIPAA Journal statistics)

Reducing third-party and supply chain breach exposure

The pattern across this ranking is hard to miss. Change Healthcare, Conduent, the AMCA breaches at Quest and LabCorp, Welltok, Trinity Health through Blackbaud, and TriZetto all originated at a vendor, clearinghouse, or fourth party rather than inside the covered entity itself. Concentration is the reason a single intrusion aggregates records across thousands of providers and payers, and the same structural exposure is now spreading to private-equity-consolidated practice groups. Our guide to preventing third-party data breaches walks through how to get ahead of that exposure.

Reducing that exposure comes down to controls practitioners already know work. Enforce multi-factor authentication on every remote access portal, since missing MFA enabled both Change Healthcare and the Advanced NHS 111 breach. Run an accurate enterprise-wide risk analysis under the HIPAA Security Rule, apply real vendor due diligence before and during each engagement, and monitor your external attack surface and vendor ecosystem continuously rather than at contract renewal. Continuous visibility is where the UpGuard Breach Risk product fits, giving security teams an ongoing view of exposed assets before an attacker finds them. To see that in practice, start a free trial.

How UpGuard helps healthcare organizations manage breach risk

UpGuard gives healthcare security and risk teams unified visibility across their own attack surface, their vendors, and their workforce, so the concentration risk behind the breaches above becomes measurable and manageable:

  • Breach Risk: external attack surface management and threat intelligence that continuously discovers exposed assets, dark web exposure, and impersonation across a single view.
  • Vendor Risk: third-party risk management that assesses and continuously monitors the cybersecurity posture of clearinghouses, business associates, and other vendors across the healthcare supply chain.
  • User Risk: human risk management that surfaces workforce exposures such as compromised credentials, the entry point behind several of the intrusions on this list.

Frequently asked questions

What is the largest healthcare data breach in history?

The Change Healthcare breach is the largest, with a final total of 192.7 million individuals affected. It is more than double the Anthem breach and reached close to two-thirds of the US population.

What is the most recent major healthcare data breach?

The largest new incidents posted to the OCR portal in 2026 are TriZetto Provider Solutions, QualDerm Partners, and Nacogdoches Memorial Hospital, while the largest breach reported in May 2026 was Radiology Associates of Richmond at more than 266,000 individuals.

What are the most common causes of healthcare data breaches?

Hacking and IT incidents accounted for more than 80% of large healthcare breaches in 2025, most often through compromised credentials, third-party and business associate intrusions, and, in several cases, misconfigured web tracking technologies.

How much does a healthcare data breach cost?

The IBM Cost of a Data Breach Report 2025 put the average healthcare breach at USD 7.42 million, the highest of any industry, with the longest breach lifecycle at 279 days.

Are healthcare data breaches increasing in 2026?

It is too early to say, because the 2026 OCR figures are depressed by the publishing backlog that followed the 43-day HHS shutdown, so the year-to-date decline should be treated as incomplete data rather than a real drop.