Healthcare Data Breach in the US 2026
Healthcare Data Breach Statistics in the US 2026 describe a sector still absorbing the shockwaves of the largest cyberattack in the history of American medicine while simultaneously showing genuine signs of improvement in breach frequency. According to the HHS Office for Civil Rights (OCR) breach portal, cumulative healthcare data breach totals crossed 935 million individuals affected since 2009 by early 2026, a figure that exceeds 2.6 times the entire US population. Just this week, NYC Health + Hospitals confirmed that a months-long, third-party vendor breach exposed highly sensitive data — including medical records, government IDs, and fingerprint and palm-print biometrics — for at least 1.8 million individuals, making it one of the largest healthcare breaches disclosed so far in 2026.
At the same time, monthly OCR reporting data shows a genuine decline in large breach frequency compared to the record-setting pace of 2025, when 772 large breaches were reported, a new annual record at a rate of 2.1 per day. This report breaks down the latest verified Healthcare Data Breach Statistics in the US 2026 — covering record counts, attack methods, costs, ransomware impact, and the biggest incidents of the year — using data from HHS OCR, the HIPAA Journal, IBM, and Verizon.
Interesting Facts About Healthcare Data Breach Statistics in the US 2026
| Fact Category | Details |
|---|---|
| Cumulative Individuals Affected (2009–early 2026) | 935 million+, or 2.6x the US population |
| Large Breaches Reported in 2025 (Annual Record) | 772 breaches, a rate of 2.1 per day |
| Individuals Affected in 2025 | ~138.5 million, about 379,306 people per day |
| Largest Healthcare Breach in History | Change Healthcare, 192.7 million individuals affected |
| NYC Health + Hospitals Breach (2026) | At least 1.8 million individuals affected |
| Average Cost of a Healthcare Data Breach (2025) | $7.42 million, highest of any industry for 14 consecutive years |
| Hacking/IT Incidents Share of Large Breaches | Over 80% of all large healthcare breaches |
| Average Time to Identify and Contain a Breach | 241 to 279 days, longest of any sector |
| 2026 Year-to-Date Breach Trend (Jan–Apr) | 252 breaches, down 8.7% from 2025’s same period |
| Healthcare’s Share of All Global Ransomware Attacks | 17% to 22% |
Data Source: HHS Office for Civil Rights (OCR) Breach Portal, HIPAA Journal, IBM Cost of a Data Breach Report 2025
The 935 million cumulative figure is the statistic that best captures just how thoroughly American healthcare data has been compromised over the past decade and a half — it means, on average, every person in the United States has had their protected health information exposed more than twice since OCR began tracking large breaches in 2009. That number was skewed dramatically by a single incident: the 2024 Change Healthcare ransomware attack, which alone exposed data for 192.7 million individuals, nearly two-thirds of the US population, and permanently reshaped how analysts talk about aggregate healthcare breach risk.
Set against that backdrop, 2025’s 772 large breaches — a new annual record by count, even though records affected didn’t set a new high — shows that breach frequency and breach severity are now tracking somewhat independently. Hacking and other IT incidents, which accounted for just 49% of large breaches in 2019, now represent over 80% of all large healthcare breaches, confirming that healthcare has definitively shifted from an era dominated by lost laptops and improper disposal to one dominated by external cyberattacks, ransomware, and third-party vendor compromises like the one that hit NYC Health + Hospitals this year.
Healthcare Data Breach Trends by Year Statistics in US 2026
| Year | Large Breaches Reported | Individuals Affected |
|---|---|---|
| 2022 | ~710–746 | Elevated, pre-Change Healthcare baseline |
| 2023 | ~710–746 | Elevated, pre-Change Healthcare baseline |
| 2024 | 739 | Over 276 million (highest on record, driven by Change Healthcare) |
| 2025 | 772 (new annual record) | ~138.5 million |
| 2026 (Jan–Apr YTD) | 252 | Declining pace vs. 2025 and 2024 |
| 2026 YTD Comparison to 2025 | -8.7% | Fewer breaches reported year-to-date |
| 2026 YTD Comparison to 2024 | -15.7% | Continued year-over-year decline |
| 12-Month Rolling Average (into 2026) | 62.4 breaches/month | Baseline for monthly comparison |
Data Source: HIPAA Journal Healthcare Data Breach Statistics, HHS OCR Breach Portal
Large Healthcare Data Breaches Reported to OCR, by Year
2024 |######################################## | 739
2025 |#########################################| 772 (record)
2026* |#################### | 252 (Jan-Apr, on pace for decline)
The year-over-year trend data reveals two distinct and somewhat contradictory patterns unfolding simultaneously. 2025’s total of 772 large breaches set a new annual record for sheer breach count, averaging 2.1 reported incidents every single day of the year. Yet the individuals-affected total of roughly 138.5 million for 2025 was actually far below 2024’s 276 million, because 2024’s number was inflated by the singular scale of the Change Healthcare incident. This divergence between breach frequency and breach severity is the central analytical challenge facing healthcare security teams in 2026: more organizations are being breached, but few incidents match the catastrophic scale of a single dominant vendor compromise.
Early 2026 data offers a genuinely encouraging signal: from January through April, only 252 large breaches were reported, down 8.7% from the same period in 2025 and 15.7% below the same period in 2024. If this pace holds, 2026 could see the lowest annual breach count in several years, according to HIPAA Journal analysis of OCR reporting patterns. However, this reporting decline should be read cautiously — breach notification carries a 60-day reporting window, meaning any given month’s figures can still rise as investigations conclude, and a single major incident like the NYC Health + Hospitals breach can quickly reverse an otherwise positive trend.
Healthcare Data Breach Attack Method Statistics in US 2026
| Attack Method | Share of Large Breaches |
|---|---|
| Hacking/IT Incidents (2019) | 49% |
| Hacking/IT Incidents (2023) | 79.7% |
| Hacking/IT Incidents (2025, estimated) | Over 80% |
| Ransomware Increase (2018–2023) | 278% increase |
| Hacking-Related Breach Increase (2018–2023) | 239% increase |
| Healthcare Share of Global Ransomware Attacks | 17% to 22% |
| Documented Ransomware Attacks on Healthcare (2025) | Over 450 attacks |
| Business Associate/Third-Party Involvement (Trend) | Rising, cited in multiple 2026 large breaches |
Data Source: HHS OCR, HIPAA Journal, Microsoft Digital Defense Report, FBI IC3 2024 Annual Report
Hacking/IT Incidents as Share of Large Healthcare Breaches
2019 |#################### | 49%
2023 |################################ | 79.7%
2025 |################################# | 80%+
The single most important structural shift in healthcare breach data over the past several years is the near-total dominance of hacking and IT incidents as the root cause. In 2019, hacking accounted for roughly half of all large reported breaches; by 2023, that share had climbed to 79.7%, and industry trackers estimate it now sits above 80% heading into 2026. This mirrors the documented 239% increase in hacking-related breaches and 278% increase in ransomware attacks that OCR identified between January 2018 and September 2023 — a trajectory that has continued rather than reversed.
Ransomware remains the most operationally disruptive subset of this hacking category. Healthcare now accounts for an estimated 17% to 22% of all ransomware attacks globally, nearly double the share of any other single industry, with over 450 documented attacks specifically targeting medical practices, hospitals, and healthcare organizations throughout 2025 alone. The FBI’s IC3 2024 Annual Report separately recorded 460 ransomware incidents in the healthcare and public health sector specifically, the highest of any critical infrastructure subsector tracked by the bureau — a distinction that underscores why regulators increasingly treat healthcare cybersecurity as a patient-safety issue, not merely a data-privacy one.
Biggest Healthcare Data Breaches Statistics in US 2026
| Incident | Individuals Affected | Year Disclosed |
|---|---|---|
| Change Healthcare | 192.7 million | 2024 (largest in US healthcare history) |
| NYC Health + Hospitals | 1.8 million+ | 2026 (third-party vendor breach) |
| Ascension | ~437,000 (separate 2025 incident, plus operational disruption across 19 states) | 2024–2025 |
| DaVita (dialysis provider) | ~2.5 million+ affected across incidents | 2025 |
| Texas Community Hospital Breach | 2,507,073 | 2026 |
| Defense Health Agency Incident | ~100,000 | 2026 |
| Radiology Associates of Richmond | 266,000+ | 2026 (May) |
| Western Orthopaedics | 113,000+ | 2026 (May) |
Data Source: HHS OCR Breach Portal, UpGuard, HIPAA Journal Monthly Breach Reports
Scale Comparison: Largest 2026 Breaches vs. Change Healthcare (2024)
Change Healthcare (2024) |########################################| 192.7M
NYC Health + Hospitals (2026)|# | 1.8M
Texas Hospital Breach (2026) |# | 2.5M
No single 2026 incident has come close to matching the scale of the Change Healthcare attack, which remains the largest healthcare data breach in US history and continues to define how analysts contextualize every subsequent incident. That said, 2026 has already produced several breaches serious enough to rank among the year’s most consequential: the NYC Health + Hospitals breach, detected in February 2026 and reported to HHS on March 24, exposed not just medical and financial records but fingerprint and palm-print biometric data for at least 1.8 million people — a category of exposure with no straightforward remediation path, since biometric identifiers, unlike passwords or even Social Security numbers, cannot simply be reissued.
The Ascension and DaVita incidents from 2024–2025 illustrate a different kind of severity: operational, not just informational. Ascension’s ransomware attack forced the health system to divert ambulances, revert to paper charting, and lose access to electronic health records, e-prescribing, and phone systems across 19 states for several weeks, contributing to roughly $1.3 billion in operating losses for fiscal year 2024. DaVita, a dialysis provider whose patients cannot safely miss appointments, faced direct clinical risk during its ransomware event, ultimately disclosing roughly $13.5 million in incident-related costs. For a broader picture of how phishing-driven attacks — the initial entry point behind many of these breaches — are trending across all US industries, see our Phishing Statistics in US report, which documents the same attacker sophistication driving healthcare’s largest 2026 incidents.
Healthcare Data Breach Cost and Impact Statistics in US 2026
| Cost/Impact Metric | Figure |
|---|---|
| Average Cost per Healthcare Breach (2025) | $7.42 million |
| Average Cost per Breach (2024, prior year) | $9.77 million |
| Healthcare Cost Ranking vs. All Industries | #1 for 14 consecutive years |
| Average Time to Identify/Contain Breach (Healthcare) | 241–279 days |
| Downtime Cost for Healthcare Organizations | Up to $900,000 per day |
| In-Hospital Mortality Increase During Active Ransomware Attack | 34% to 38% higher (Medicare patients) |
| Patient Volume Drop, First Week of Ransomware Attack | 17% to 24% |
| Estimated Medicare Patient Deaths Linked to Ransomware (2016–2021) | 42 to 67 patients |
Data Source: IBM Cost of a Data Breach Report 2025, American Economic Journal: Economic Policy (Feb. 2026), Microsoft Threat Intelligence
Average Healthcare Data Breach Cost by Year (USD Millions)
2024 |########################################| $9.77M
2025 |################################# | $7.42M
While the $7.42 million average breach cost for 2025 represents a $2.35 million decline from 2024’s $9.77 million, largely because the outsized Change Healthcare incident is no longer inside the sampling window, healthcare still costs organizations far more per breach than any other industry, a distinction it has held for 14 consecutive years according to IBM’s Cost of a Data Breach Report. Part of what keeps healthcare costs so elevated is detection speed: healthcare organizations take an average of 241 to 279 days to identify and contain a breach, roughly five weeks longer than the cross-industry average, giving attackers extended dwell time inside clinical and administrative networks.
The most sobering 2026 research findings move beyond dollar figures entirely and into direct patient-safety consequences. A Medicare-claims study published in the American Economic Journal: Economic Policy in February 2026 found that among Medicare patients already admitted to a hospital when a ransomware attack begins, in-hospital mortality increases by 34% to 38%, while hospital patient volume drops 17% to 24% in the first week of an attack, with recovery typically taking about three weeks. Researchers separately estimate that 42 to 67 Medicare patients died as a direct result of ransomware attacks between 2016 and 2021 — a figure that reframes healthcare cybersecurity from a compliance and financial concern into a matter of measurable clinical harm.
HIPAA Enforcement and Regulatory Response Statistics in US 2026
| Enforcement Metric | Figure |
|---|---|
| OCR Settlements, 2025 | 21, second-highest on record |
| OCR Settlements, 2024 | 16 |
| OCR Settlements, 2022 (all-time record) | 22 |
| Total OCR Complaints Logged Since 2003 | 374,322 |
| Annual Cap, Single-Tier Civil Monetary Penalty | $2,190,294 |
| Largest HIPAA Settlement in History | $16 million (Anthem Inc., 2018) |
| April 2026 Settlements — Common Root Cause | All 4 related to ransomware attacks; risk analysis failure identified in each |
| Proposed HIPAA Security Rule Update | Published Dec. 2024; expected to finalize May 2026 with 180-day compliance period |
Data Source: HHS OCR, HIPAA Journal, FaxSIPit HIPAA Violation Statistics 2026
OCR Settlement Actions by Year
2022 |########################################| 22 (record)
2024 |############################# | 16
2025 |###################################### | 21
Regulatory enforcement intensified again in 2025, with OCR announcing 21 settlements, the second-highest annual total on record, trailing only 2022’s all-time high of 22. A pattern evident in OCR’s own 2026 monthly reports is instructive: in April 2026 alone, OCR announced four settlements, and in every single case, investigators identified a risk analysis failure as a contributing factor — meaning the breached organization had not adequately assessed where its vulnerabilities lay before the attack occurred. This consistency suggests that basic risk-assessment compliance, rather than exotic or unpreventable attack techniques, remains the most common regulatory failure point across the healthcare sector.
Looking ahead, the most consequential regulatory development for 2026 is the proposed update to the HIPAA Security Rule, first published in December 2024 and expected to finalize in May 2026 with a 180-day compliance period for covered entities. These represent the first major HIPAA Security Rule updates since 2013 and are specifically designed to address the ransomware and hacking threats that now dominate breach causation data, including stricter requirements around risk analysis, multifactor authentication, and encryption. Given that healthcare breaches frequently trace back to hospital-adjacent financial and operational strain — many smaller, rural, or already-struggling facilities lack the security budget the new rules will demand — readers may find useful context in our Hospital Closure Statistics in US report, which documents the broader financial pressures facing the same hospital sector now expected to absorb significant new cybersecurity compliance costs. The rise in healthcare-linked identity theft stemming from these breaches also connects closely to the patterns tracked in our Consumer Fraud Statistics in US report, particularly the FTC’s documented 9.5% increase in medical and general identity theft reports.
Disclaimer: This research report is compiled from publicly available sources. While reasonable efforts have been made to ensure accuracy, no representation or warranty, express or implied, is given as to the completeness or reliability of the information. We accept no liability for any errors, omissions, losses, or damages of any kind arising from the use of this report.

