Large healthcare breaches hit a record 772 incidents in 2025, yet the number of people affected actually fell to about 61.6 million, down from 289 million the year before. That gap is the story this healthcare data breach report is really about. Breach counts and breach damage do not move together, and one mega breach can distort an entire year of data.
What the HHS OCR Data Actually Shows
The HHS Office for Civil Rights breach portal is the federal government’s public record of every healthcare breach affecting 500 or more individuals, published under the HITECH Act. It is the closest thing the industry has to a single source of truth, and it is the dataset behind almost every healthcare data breach report you will read this year.
Here is how the last three years compare, according to the HHS OCR breach portal.
| Year | Large breaches reported | Individuals affected | Notable driver |
|---|---|---|---|
| 2024 | 725 | About 289 million | Change Healthcare, about 192.7 million individuals in one incident |
| 2025 | 772 (record year) | About 61.6 million | No single mega breach, but the highest incident count on record |
| 2026 year to date (first half) | 189 | More than 19 million | Reporting still incomplete, see note below |
A single incident, the Change Healthcare ransomware attack, accounted for roughly two thirds of every individual affected in 2024. Remove that one event and 2024 looks unremarkable next to 2025’s record breach count. This is the pattern to watch for in any healthcare data breach report. Total records exposed tells you almost nothing about how many organizations were actually breached, and incident count tells you almost nothing about how bad the worst breach was. You need both numbers, and you need to know whether a mega breach is skewing one of them.
One important caveat on the 2026 figures. A 43 day federal government shutdown from October to November of 2025 slowed OCR’s intake and publication process, and the portal has been adding backlogged reports from late 2025 and early 2026 throughout this year. The 189 breaches and 19 million individuals reflected in the first half of 2026 will almost certainly increase as OCR works through that backlog, so treat early year totals as a floor, not a final count.
Why Hacking Dominates the Breach Causes
If you only remember one number from this healthcare data breach report, make it this one. Hacking and other IT incidents accounted for more than 80 percent of large healthcare breaches in 2025, and the pattern has held into 2026.
| Cause | Share of 2026 year to date breaches |
|---|---|
| Hacking or IT incident | About 92 percent |
| Unauthorized access or disclosure | About 7 percent |
| Theft | Under 1 percent |
| Loss | Under 1 percent |
This is not a story about lost laptops or misplaced paper files anymore. It is almost entirely a story about external attackers getting into systems, most often through compromised credentials, unpatched software, or a remote access point that lacked multi factor authentication. The average healthcare breach now costs 7.42 million dollars and takes 279 days, roughly nine months, to identify and contain, according to IBM’s Cost of a Data Breach Report. Nine months is a long time for an attacker to sit inside a system undetected, which is exactly why detection controls matter as much as prevention controls in any healthcare security program.
If your HealthTech startup handles PHI and has not had a risk assessment mapped to where these breach causes actually originate, a scoping call is the fastest way to find out where you stand. Book a scoping call and we will walk through what a HIPAA risk assessment should actually cover for your environment.
What This Means for HealthTech Startups
The breach causes above map almost directly onto what a HIPAA compliant pentest is supposed to catch before an attacker finds it first. Compromised credentials point to authentication and session management. Unpatched systems point to external and internal network testing. Misconfigured remote access points to the exact kind of access control testing that a scoped web application and API assessment is built to surface.
In our HIPAA risk assessments, we run a two part methodology, a structured interview mapped against NIST 800-66 alongside a Prowler based technical verification of the actual cloud environment, then score each finding on a numeric likelihood and impact scale. The point of pairing an interview with technical verification is that policy documents and actual system configuration frequently do not match, and a healthcare data breach report full of hacking incidents is really a report full of gaps between what a company believes its safeguards are and what its systems actually enforce.
For a growing HealthTech company, the practical takeaway is not that breaches are inevitable. It is that the overwhelming majority of large breaches trace back to a small number of preventable causes, and a pentest vendor who understands where those causes actually show up in your architecture is worth more than one who just runs a generic vulnerability scan and calls it a HIPAA assessment.
The data is consistent year over year on this point. Hacking dominates, detection is slow, and the cost of getting it wrong keeps climbing. These HIPAA breach statistics are worth revisiting each time OCR publishes new numbers, since the underlying pattern has held for three years running and shows no sign of changing before next year’s report.
If you want a HIPAA risk assessment that actually tests for the causes behind these numbers instead of checking a compliance box, book a scoping call and we will map out what your environment needs before your next audit or enterprise deal.
Source: HHS Office for Civil Rights breach portal, as analyzed by HIPAA Journal and HealthTechSecurity, data through July 2026. View the OCR breach portal directly.
Packet33 is a penetration testing and compliance advisory firm serving SaaS and HealthTech startups in the US, Canada, and UK.
