Healthcare Data Breach Statistics in US 2026 | Records, Attacks & Facts

Healthcare Data Breach Statistics in the US

Healthcare Data Breach in the US 2026

Healthcare Data Breach Statistics in the US 2026 describe a sector still absorbing the shockwaves of the largest cyberattack in the history of American medicine while simultaneously showing genuine signs of improvement in breach frequency. According to the HHS Office for Civil Rights (OCR) breach portal, cumulative healthcare data breach totals crossed 935 million individuals affected since 2009 by early 2026, a figure that exceeds 2.6 times the entire US population. Just this week, NYC Health + Hospitals confirmed that a months-long, third-party vendor breach exposed highly sensitive data — including medical records, government IDs, and fingerprint and palm-print biometrics — for at least 1.8 million individuals, making it one of the largest healthcare breaches disclosed so far in 2026.

At the same time, monthly OCR reporting data shows a genuine decline in large breach frequency compared to the record-setting pace of 2025, when 772 large breaches were reported, a new annual record at a rate of 2.1 per day. This report breaks down the latest verified Healthcare Data Breach Statistics in the US 2026 — covering record counts, attack methods, costs, ransomware impact, and the biggest incidents of the year — using data from HHS OCR, the HIPAA Journal, IBM, and Verizon.

Interesting Facts About Healthcare Data Breach Statistics in the US 2026

Fact Category Details
Cumulative Individuals Affected (2009–early 2026) 935 million+, or 2.6x the US population
Large Breaches Reported in 2025 (Annual Record) 772 breaches, a rate of 2.1 per day
Individuals Affected in 2025 ~138.5 million, about 379,306 people per day
Largest Healthcare Breach in History Change Healthcare, 192.7 million individuals affected
NYC Health + Hospitals Breach (2026) At least 1.8 million individuals affected
Average Cost of a Healthcare Data Breach (2025) $7.42 million, highest of any industry for 14 consecutive years
Hacking/IT Incidents Share of Large Breaches Over 80% of all large healthcare breaches
Average Time to Identify and Contain a Breach 241 to 279 days, longest of any sector
2026 Year-to-Date Breach Trend (Jan–Apr) 252 breaches, down 8.7% from 2025’s same period
Healthcare’s Share of All Global Ransomware Attacks 17% to 22%

Data Source: HHS Office for Civil Rights (OCR) Breach Portal, HIPAA Journal, IBM Cost of a Data Breach Report 2025

The 935 million cumulative figure is the statistic that best captures just how thoroughly American healthcare data has been compromised over the past decade and a half — it means, on average, every person in the United States has had their protected health information exposed more than twice since OCR began tracking large breaches in 2009. That number was skewed dramatically by a single incident: the 2024 Change Healthcare ransomware attack, which alone exposed data for 192.7 million individuals, nearly two-thirds of the US population, and permanently reshaped how analysts talk about aggregate healthcare breach risk.

Set against that backdrop, 2025’s 772 large breaches — a new annual record by count, even though records affected didn’t set a new high — shows that breach frequency and breach severity are now tracking somewhat independently. Hacking and other IT incidents, which accounted for just 49% of large breaches in 2019, now represent over 80% of all large healthcare breaches, confirming that healthcare has definitively shifted from an era dominated by lost laptops and improper disposal to one dominated by external cyberattacks, ransomware, and third-party vendor compromises like the one that hit NYC Health + Hospitals this year.

Healthcare Data Breach Trends by Year Statistics in US 2026

Year Large Breaches Reported Individuals Affected
2022 ~710–746 Elevated, pre-Change Healthcare baseline
2023 ~710–746 Elevated, pre-Change Healthcare baseline
2024 739 Over 276 million (highest on record, driven by Change Healthcare)
2025 772 (new annual record) ~138.5 million
2026 (Jan–Apr YTD) 252 Declining pace vs. 2025 and 2024
2026 YTD Comparison to 2025 -8.7% Fewer breaches reported year-to-date
2026 YTD Comparison to 2024 -15.7% Continued year-over-year decline
12-Month Rolling Average (into 2026) 62.4 breaches/month Baseline for monthly comparison

Data Source: HIPAA Journal Healthcare Data Breach Statistics, HHS OCR Breach Portal

Large Healthcare Data Breaches Reported to OCR, by Year
2024  |######################################## | 739
2025  |#########################################| 772 (record)
2026* |####################                     | 252 (Jan-Apr, on pace for decline)

The year-over-year trend data reveals two distinct and somewhat contradictory patterns unfolding simultaneously. 2025’s total of 772 large breaches set a new annual record for sheer breach count, averaging 2.1 reported incidents every single day of the year. Yet the individuals-affected total of roughly 138.5 million for 2025 was actually far below 2024’s 276 million, because 2024’s number was inflated by the singular scale of the Change Healthcare incident. This divergence between breach frequency and breach severity is the central analytical challenge facing healthcare security teams in 2026: more organizations are being breached, but few incidents match the catastrophic scale of a single dominant vendor compromise.

Early 2026 data offers a genuinely encouraging signal: from January through April, only 252 large breaches were reported, down 8.7% from the same period in 2025 and 15.7% below the same period in 2024. If this pace holds, 2026 could see the lowest annual breach count in several years, according to HIPAA Journal analysis of OCR reporting patterns. However, this reporting decline should be read cautiously — breach notification carries a 60-day reporting window, meaning any given month’s figures can still rise as investigations conclude, and a single major incident like the NYC Health + Hospitals breach can quickly reverse an otherwise positive trend.

Healthcare Data Breach Attack Method Statistics in US 2026

Attack Method Share of Large Breaches
Hacking/IT Incidents (2019) 49%
Hacking/IT Incidents (2023) 79.7%
Hacking/IT Incidents (2025, estimated) Over 80%
Ransomware Increase (2018–2023) 278% increase
Hacking-Related Breach Increase (2018–2023) 239% increase
Healthcare Share of Global Ransomware Attacks 17% to 22%
Documented Ransomware Attacks on Healthcare (2025) Over 450 attacks
Business Associate/Third-Party Involvement (Trend) Rising, cited in multiple 2026 large breaches

Data Source: HHS OCR, HIPAA Journal, Microsoft Digital Defense Report, FBI IC3 2024 Annual Report

Hacking/IT Incidents as Share of Large Healthcare Breaches
2019  |####################                    | 49%
2023  |################################        | 79.7%
2025  |#################################       | 80%+

The single most important structural shift in healthcare breach data over the past several years is the near-total dominance of hacking and IT incidents as the root cause. In 2019, hacking accounted for roughly half of all large reported breaches; by 2023, that share had climbed to 79.7%, and industry trackers estimate it now sits above 80% heading into 2026. This mirrors the documented 239% increase in hacking-related breaches and 278% increase in ransomware attacks that OCR identified between January 2018 and September 2023 — a trajectory that has continued rather than reversed.

Ransomware remains the most operationally disruptive subset of this hacking category. Healthcare now accounts for an estimated 17% to 22% of all ransomware attacks globally, nearly double the share of any other single industry, with over 450 documented attacks specifically targeting medical practices, hospitals, and healthcare organizations throughout 2025 alone. The FBI’s IC3 2024 Annual Report separately recorded 460 ransomware incidents in the healthcare and public health sector specifically, the highest of any critical infrastructure subsector tracked by the bureau — a distinction that underscores why regulators increasingly treat healthcare cybersecurity as a patient-safety issue, not merely a data-privacy one.

Biggest Healthcare Data Breaches Statistics in US 2026

Incident Individuals Affected Year Disclosed
Change Healthcare 192.7 million 2024 (largest in US healthcare history)
NYC Health + Hospitals 1.8 million+ 2026 (third-party vendor breach)
Ascension ~437,000 (separate 2025 incident, plus operational disruption across 19 states) 2024–2025
DaVita (dialysis provider) ~2.5 million+ affected across incidents 2025
Texas Community Hospital Breach 2,507,073 2026
Defense Health Agency Incident ~100,000 2026
Radiology Associates of Richmond 266,000+ 2026 (May)
Western Orthopaedics 113,000+ 2026 (May)

Data Source: HHS OCR Breach Portal, UpGuard, HIPAA Journal Monthly Breach Reports

Scale Comparison: Largest 2026 Breaches vs. Change Healthcare (2024)
Change Healthcare (2024)     |########################################| 192.7M
NYC Health + Hospitals (2026)|#                                       | 1.8M
Texas Hospital Breach (2026) |#                                       | 2.5M

No single 2026 incident has come close to matching the scale of the Change Healthcare attack, which remains the largest healthcare data breach in US history and continues to define how analysts contextualize every subsequent incident. That said, 2026 has already produced several breaches serious enough to rank among the year’s most consequential: the NYC Health + Hospitals breach, detected in February 2026 and reported to HHS on March 24, exposed not just medical and financial records but fingerprint and palm-print biometric data for at least 1.8 million people — a category of exposure with no straightforward remediation path, since biometric identifiers, unlike passwords or even Social Security numbers, cannot simply be reissued.

The Ascension and DaVita incidents from 2024–2025 illustrate a different kind of severity: operational, not just informational. Ascension’s ransomware attack forced the health system to divert ambulances, revert to paper charting, and lose access to electronic health records, e-prescribing, and phone systems across 19 states for several weeks, contributing to roughly $1.3 billion in operating losses for fiscal year 2024. DaVita, a dialysis provider whose patients cannot safely miss appointments, faced direct clinical risk during its ransomware event, ultimately disclosing roughly $13.5 million in incident-related costs. For a broader picture of how phishing-driven attacks — the initial entry point behind many of these breaches — are trending across all US industries, see our Phishing Statistics in US report, which documents the same attacker sophistication driving healthcare’s largest 2026 incidents.

Healthcare Data Breach Cost and Impact Statistics in US 2026

Cost/Impact Metric Figure
Average Cost per Healthcare Breach (2025) $7.42 million
Average Cost per Breach (2024, prior year) $9.77 million
Healthcare Cost Ranking vs. All Industries #1 for 14 consecutive years
Average Time to Identify/Contain Breach (Healthcare) 241–279 days
Downtime Cost for Healthcare Organizations Up to $900,000 per day
In-Hospital Mortality Increase During Active Ransomware Attack 34% to 38% higher (Medicare patients)
Patient Volume Drop, First Week of Ransomware Attack 17% to 24%
Estimated Medicare Patient Deaths Linked to Ransomware (2016–2021) 42 to 67 patients

Data Source: IBM Cost of a Data Breach Report 2025, American Economic Journal: Economic Policy (Feb. 2026), Microsoft Threat Intelligence

Average Healthcare Data Breach Cost by Year (USD Millions)
2024  |########################################| $9.77M
2025  |#################################       | $7.42M

While the $7.42 million average breach cost for 2025 represents a $2.35 million decline from 2024’s $9.77 million, largely because the outsized Change Healthcare incident is no longer inside the sampling window, healthcare still costs organizations far more per breach than any other industry, a distinction it has held for 14 consecutive years according to IBM’s Cost of a Data Breach Report. Part of what keeps healthcare costs so elevated is detection speed: healthcare organizations take an average of 241 to 279 days to identify and contain a breach, roughly five weeks longer than the cross-industry average, giving attackers extended dwell time inside clinical and administrative networks.

The most sobering 2026 research findings move beyond dollar figures entirely and into direct patient-safety consequences. A Medicare-claims study published in the American Economic Journal: Economic Policy in February 2026 found that among Medicare patients already admitted to a hospital when a ransomware attack begins, in-hospital mortality increases by 34% to 38%, while hospital patient volume drops 17% to 24% in the first week of an attack, with recovery typically taking about three weeks. Researchers separately estimate that 42 to 67 Medicare patients died as a direct result of ransomware attacks between 2016 and 2021 — a figure that reframes healthcare cybersecurity from a compliance and financial concern into a matter of measurable clinical harm.

HIPAA Enforcement and Regulatory Response Statistics in US 2026

Enforcement Metric Figure
OCR Settlements, 2025 21, second-highest on record
OCR Settlements, 2024 16
OCR Settlements, 2022 (all-time record) 22
Total OCR Complaints Logged Since 2003 374,322
Annual Cap, Single-Tier Civil Monetary Penalty $2,190,294
Largest HIPAA Settlement in History $16 million (Anthem Inc., 2018)
April 2026 Settlements — Common Root Cause All 4 related to ransomware attacks; risk analysis failure identified in each
Proposed HIPAA Security Rule Update Published Dec. 2024; expected to finalize May 2026 with 180-day compliance period

Data Source: HHS OCR, HIPAA Journal, FaxSIPit HIPAA Violation Statistics 2026

OCR Settlement Actions by Year
2022  |########################################| 22 (record)
2024  |#############################           | 16
2025  |######################################  | 21

Regulatory enforcement intensified again in 2025, with OCR announcing 21 settlements, the second-highest annual total on record, trailing only 2022’s all-time high of 22. A pattern evident in OCR’s own 2026 monthly reports is instructive: in April 2026 alone, OCR announced four settlements, and in every single case, investigators identified a risk analysis failure as a contributing factor — meaning the breached organization had not adequately assessed where its vulnerabilities lay before the attack occurred. This consistency suggests that basic risk-assessment compliance, rather than exotic or unpreventable attack techniques, remains the most common regulatory failure point across the healthcare sector.

Looking ahead, the most consequential regulatory development for 2026 is the proposed update to the HIPAA Security Rule, first published in December 2024 and expected to finalize in May 2026 with a 180-day compliance period for covered entities. These represent the first major HIPAA Security Rule updates since 2013 and are specifically designed to address the ransomware and hacking threats that now dominate breach causation data, including stricter requirements around risk analysis, multifactor authentication, and encryption. Given that healthcare breaches frequently trace back to hospital-adjacent financial and operational strain — many smaller, rural, or already-struggling facilities lack the security budget the new rules will demand — readers may find useful context in our Hospital Closure Statistics in US report, which documents the broader financial pressures facing the same hospital sector now expected to absorb significant new cybersecurity compliance costs. The rise in healthcare-linked identity theft stemming from these breaches also connects closely to the patterns tracked in our Consumer Fraud Statistics in US report, particularly the FTC’s documented 9.5% increase in medical and general identity theft reports.

Disclaimer: This research report is compiled from publicly available sources. While reasonable efforts have been made to ensure accuracy, no representation or warranty, express or implied, is given as to the completeness or reliability of the information. We accept no liability for any errors, omissions, losses, or damages of any kind arising from the use of this report.