INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).
Lazarus Group Deploys Ransomware Against Healthcare Provider in Data Breach
| 2026-09-30 16:44 CRITICAL LOW RANSOMWARE & EXTORTION DATA BREACH STATE-SPONSORED & ESPIONAGE CRITICAL INFRASTRUCTURE & OT
Executive Summary
AI-generated
In the first half of 2026, large healthcare data breaches were reported in 44 U.S. states and Puerto Rico by HIPAA-regulated entities, affecting approximately 33.77 million individuals, a decline of 22.6% compared to H1 2025. The majority of these breaches, nine out of twenty, were due to hacking incidents or ransomware attacks, with the largest breach affecting over 5.8 million individuals. These data breaches occurred at various healthcare providers and business associates, including Lumexa Imaging, TriZetto Provider Solutions, and OpenLoop Health, Inc., among others. The U.S. Department of Health and Human Services Office for Civil Rights reported a total of 397 data breaches in the first six months of the year, with more than 140 million individuals affected in 2025, suggesting that this year could see a major reduction in affected individuals if similar rates continue to be reported in the second half of the year.
Technical Mitigations AI-generated
• Reset credentials and API keys that may have been exposed, and review access logs for the affected accounts or integrations.
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
Target & Sectors
GE
MO
MD
PR
VA
NC
MX
JE
healthhealth
Incident Timeline
late 2019
The HIPAA Right of Access enforcement initiative began its active period in late 2019.
Click on any entity below to view its context and source!
organisation
The HIPAA Right of Access
The HIPAA Right of Access enforcement initiative has been active since late 2019 and has resulted in more than 55 financial penalties.
general_metric
55 financial penalties
The HIPAA Right of Access enforcement initiative has been active since late 2019 and has resulted in more than 55 financial penalties.
December 2020
OCR proposed an update to the HIPAA Privacy Rule in December 2020.
Click on any entity below to view its context and source!
industry
Healthcare
During President Trump’s first term in December 2020, OCR proposed an update to the HIPAA Privacy Rule to support coordinated care and improve individual engagement in healthcare.
January 2021
The proposed rule was formally introduced in the Federal Register in January 2021.
Click on any entity below to view its context and source!
organisation
the Federal Register
The proposed rule was formally introduced in the Federal Register in January 2021, but a final rule stalled, as OCR had other priorities under the Biden Administration.
organisation
the Biden Administration
The proposed rule was formally introduced in the Federal Register in January 2021, but a final rule stalled, as OCR had other priorities under the Biden Administration.
October 2024
The risk analysis enforcement initiative was formally launched in October 2024.
late December 2024
OCR announced a notice of proposed rulemaking in late December 2024.
January 6, 2025
OCR announced a notice of proposed rulemaking in the Federal Register on January 6, 2025.
H1 2025
A single improper disposal incident was reported in H1 2025, resulting in a significant decrease of 97% in the number of affected individuals compared to the previous year.
Click on any entity below to view its context and source!
general_metric
97 %
A single improper disposal incident was also reported in H1 2025, althopugh the number of affected individuals has fallen by 97% year-over-year.
February 16, 2026
Threat actors did not specifically target the entities mentioned in this report, but rather reported healthcare data breaches affecting 500 or more individuals to the HHS' Office for Civil Rights.
Click on any entity below to view its context and source!
industry
Healthcare
While there were no new HIPAA updates in H1 2026, the compliance date for updates to the HIPAA Notice of Privacy Practices requirements was February 16, 2026 – the only surviving part of the now vacated HIPAA update to strengthen reproductive healthcare privacy.
organisation
HIPAA
While there were no new HIPAA updates in H1 2026, the compliance date for updates to the HIPAA Notice of Privacy Practices requirements was February 16, 2026 – the only surviving part of the now vacated HIPAA update to strengthen reproductive healthcare privacy.
organisation
the HHS’ Office for Civil Rights
About this Report
This report is based on healthcare data breaches affecting 500 or more individuals that were reported to the HHS’ Office for Civil Rights in H1 2026.
organisation
The Notice of Privacy Practices
The Notice of Privacy Practices compliance deadline aligned with the compliance deadline for changes to the 42 CFR Part 2 regulations concerning substance use disorder (SUD) patient records to align those regulations more closely with HIPAA.
organisation
CFR
The Notice of Privacy Practices compliance deadline aligned with the compliance deadline for changes to the 42 CFR Part 2 regulations concerning substance use disorder (SUD) patient records to align those regulations more closely with HIPAA.
May 2026
The target release date for the final rule was initially set for May 2026 but has been pushed back to July 2027.
June 30, 2026
OCR reported 397 data breaches in the first half of 2026, affecting approximately 33.77 million individuals and resulting in $1.4 million in fines and settlements.
Click on any entity below to view its context and source!
organisation
OCR
If data breaches continue to be reported at a similar rate in the second half of the year, the end-of-year healthcare data breach total is likely to be lower than 2025, which was a record-breaking year with 804 data breaches currently listed on the OCR breach portal for 2025.
data_breach
804 data breaches
If data breaches continue to be reported at a similar rate in the second half of the year, the end-of-year healthcare data breach total is likely to be lower than 2025, which was a record-breaking year with 804 data breaches currently listed on the OCR breach portal for 2025.
data_breach
37 data breaches
Currently, 37 healthcare data breaches are listed as affecting 500 or 501 individuals.
The majority of those 37 data breaches are likely to see the totals increased, potentially significantly.
organisation
Change Healthcare
The Change Healthcare data breach in 2024 was initially reported to OCR as affecting at least 500 individuals but was subsequently increased to 192.7 million individuals!
organisation
HIPAA Regulated Entities
Data Breaches at HIPAA Regulated Entities
Healthcare providers were the worst affected HIPAA-regulated entities in H1 2026 (290 data breaches), followed by business associates (59 data breaches), and health plans (48 data breaches).
data_breach
290 data breaches
Data Breaches at HIPAA Regulated Entities
Healthcare providers were the worst affected HIPAA-regulated entities in H1 2026 (290 data breaches), followed by business associates (59 data breaches), and health plans (48 data breaches).
data_breach
59 data breaches
Data Breaches at HIPAA Regulated Entities
Healthcare providers were the worst affected HIPAA-regulated entities in H1 2026 (290 data breaches), followed by business associates (59 data breaches), and health plans (48 data breaches).
data_breach
48 data breaches
Data Breaches at HIPAA Regulated Entities
Healthcare providers were the worst affected HIPAA-regulated entities in H1 2026 (290 data breaches), followed by business associates (59 data breaches), and health plans (48 data breaches).
financial
$320,000 $ analysis failure
Healthcare Provider
$320,000
Settlement
Risk analysis failure; impermissible disclosure of the ePHI of 10,023 individuals.
organisation
Assured Imaging Affiliated Covered Entities
Assured Imaging Affiliated Covered Entities
Healthcare Provider
$375,000
Settlement
Risk analysis failure (never conducted); breach notification failure.
financial
$375,000 $ analysis failure
Assured Imaging Affiliated Covered Entities
Healthcare Provider
$375,000
Settlement
Risk analysis failure (never conducted); breach notification failure.
financial
$103,000 $ analysis failure
Top of the World Ranch Treatment Center
Healthcare Provider
$103,000
Settlement
Risk analysis failure
OCR is the main enforcer of the HIPAA Rules, although state attorneys general are also authorized to enforce HIPAA compliance and can impose financial penalties in their respective states.
organisation
the Illinois Department of Human Services
The two largest unauthorized access/disclosure incidents made it into the top 20 largest breaches of the first half of the year and occurred at the Illinois Department of Human Services and Minnesota Department of Human Services.
organisation
MCBS
TN
Business Associate
1,396,519
Hacking Incident
9
MCBS, LLC
GA
Business Associate
1,261,464
Hacking Incident
10
OpenLoop Health, Inc.
IA
Business Associate
716,000
Hacking Incident
11
Illinois Department of Human Services
IL
Health Plan
705,017
Unauthorized Disclosure Incident
12
ApolloMD
organisation
GA
Business Associate
TN
Business Associate
1,396,519
Hacking Incident
9
MCBS, LLC
GA
Business Associate
1,261,464
Hacking Incident
10
OpenLoop Health, Inc.
IA
Business Associate
716,000
Hacking Incident
11
Illinois Department of Human Services
IL
Health Plan
705,017
Unauthorized Disclosure Incident
12
ApolloMD
organisation
OpenLoop Health, Inc.
TN
Business Associate
1,396,519
Hacking Incident
9
MCBS, LLC
GA
Business Associate
1,261,464
Hacking Incident
10
OpenLoop Health, Inc.
IA
Business Associate
716,000
Hacking Incident
11
Illinois Department of Human Services
IL
Health Plan
705,017
Unauthorized Disclosure Incident
12
ApolloMD
organisation
Illinois Department of Human Services
TN
Business Associate
1,396,519
Hacking Incident
9
MCBS, LLC
GA
Business Associate
1,261,464
Hacking Incident
10
OpenLoop Health, Inc.
IA
Business Associate
716,000
Hacking Incident
11
Illinois Department of Human Services
IL
Health Plan
705,017
Unauthorized Disclosure Incident
12
ApolloMD
organisation
IL
Health Plan
TN
Business Associate
1,396,519
Hacking Incident
9
MCBS, LLC
GA
Business Associate
1,261,464
Hacking Incident
10
OpenLoop Health, Inc.
IA
Business Associate
716,000
Hacking Incident
11
Illinois Department of Human Services
IL
Health Plan
705,017
Unauthorized Disclosure Incident
12
ApolloMD
organisation
Civil Monetary
H1 2026 HIPAA Settlements and Civil Monetary Penalties
Covered Entity
Type of Entity
Amount
Settlement / Civil Monetary Penalty
Reason
Spencer Gifts LLC Flexible Benefits and Welfare Benefit Plans
Health Plan
$450,000
Settlement
Risk analysis failure; failure to implement Privacy, Security, and Breach Notification Rule policies and procedures.
organisation
Privacy, Security
H1 2026 HIPAA Settlements and Civil Monetary Penalties
Covered Entity
Type of Entity
Amount
Settlement / Civil Monetary Penalty
Reason
Spencer Gifts LLC Flexible Benefits and Welfare Benefit Plans
Health Plan
$450,000
Settlement
Risk analysis failure; failure to implement Privacy, Security, and Breach Notification Rule policies and procedures.
organisation
Breach Notification Rule
H1 2026 HIPAA Settlements and Civil Monetary Penalties
Covered Entity
Type of Entity
Amount
Settlement / Civil Monetary Penalty
Reason
Spencer Gifts LLC Flexible Benefits and Welfare Benefit Plans
Health Plan
$450,000
Settlement
Risk analysis failure; failure to implement Privacy, Security, and Breach Notification Rule policies and procedures.
financial
$450,000 $ analysis failure
H1 2026 HIPAA Settlements and Civil Monetary Penalties
Covered Entity
Type of Entity
Amount
Settlement / Civil Monetary Penalty
Reason
Spencer Gifts LLC Flexible Benefits and Welfare Benefit Plans
Health Plan
$450,000
Settlement
Risk analysis failure; failure to implement Privacy, Security, and Breach Notification Rule policies and procedures.
data_breach
397 data breaches
Across the 397 reported data breaches, the protected health information of 33.77 million individuals was exposed or impermissibly disclosed.
organisation
Regional Women’s Health Group
Regional Women’s Health Group (Axia Women’s Health)
organisation
Consociate, Inc.
Consociate, Inc. (Consociate Health)
organisation
Consociate Health
Consociate, Inc. (Consociate Health)
organisation
Star Group
Star Group, L.P. Health Benefits Plan
Health Plan
$245,000
Settlement
Risk analysis failure.
organisation
L.P. Health Benefits Plan
Health Plan
Star Group, L.P. Health Benefits Plan
Health Plan
$245,000
Settlement
Risk analysis failure.
financial
$245,000 $ Plan analysis failure
Star Group, L.P. Health Benefits Plan
Health Plan
$245,000
Settlement
Risk analysis failure.
organisation
the Identity Theft Resource Center
As also observed by the Identity Theft Resource Center, there has been a growing trend of breached entities failing to disclose the nature of data breaches, including the cause, whether ransomware was involved, and, concerningly, if data was stolen in the incident.
organisation
Financial
Financial penalties are typically reserved for egregious or particularly impactful HIPAA violations, when there has been a history of noncompliance, and when OCR has an enforcement initiative targeting a specific aspect of the HIPAA regulations.
organisation
the HIPAA Security Rule
Currently, OCR has two main enforcement initiatives, one targeting noncompliance with the HIPAA Right of Access of the HIPAA Privacy Rule, and another targeting noncompliance with the risk analysis implementation specification of the HIPAA Security Rule.
organisation
the HIPAA Breach Notification Rule
While OCR has not announced a specific initiative targeting noncompliance with the HIPAA Breach Notification Rule, two of the seven penalties this year included a fine for breach notification failures.
organisation
MMG Fusion
Business Associate
MMG Fusion
Business Associate
$10,000
Settlement
Risk analysis failure; impermissible use/disclosure of PHI; breach notification rule failure.
organisation
PHI
MMG Fusion
Business Associate
$10,000
Settlement
Risk analysis failure; impermissible use/disclosure of PHI; breach notification rule failure.
financial
$10,000 $ Associate analysis failure
MMG Fusion
Business Associate
$10,000
Settlement
Risk analysis failure; impermissible use/disclosure of PHI; breach notification rule failure.
organisation
the Massachusetts Data Security Regulations
The investigation identified violations of the HIPAA Security Rule and the Massachusetts Data Security Regulations.
financial
$225,000 $ Associate analysis failure
Business Associate
$225,000
Settlement
Risk analysis failure.
financial
$515,000 $ financial penalty
The case was settled with a $515,000 financial penalty.
August 2026
The OCR set a target date of August 2026 for the release of its final rule, but it has yet to be issued.
September 10, 2026
The data breach report was obtained from the OCR on September 10, 2026.
Click on any entity below to view its context and source!
tactic
Data Breach
The data for this report was obtained from OCR on September 10, 2026, and includes supplemental information from data breach reporting from the HIPAA Journal.
organisation
the HIPAA Journal
The data for this report was obtained from OCR on September 10, 2026, and includes supplemental information from data breach reporting from the HIPAA Journal.
Sep 30, 2026
There was a 5.9% decline in healthcare breaches from the first half of 2025 to the same period in 2026, according to the H1 2026 Healthcare Data Breach Report posted on September 30, 2026.
Click on any entity below to view its context and source!
industry
Healthcare
H1 2026 Healthcare Data Breach Report
Posted By
Steve Alder
on Sep 30, 2026
There has been a 5.9% decline in healthcare breaches compared to H1 2025.
tactic
Data Breach
H1 2026 Healthcare Data Breach Report
Posted By
Steve Alder
on Sep 30, 2026
There has been a 5.9% decline in healthcare breaches compared to H1 2025.
general_metric
5.9 %
H1 2026 Healthcare Data Breach Report
Posted By
Steve Alder
on Sep 30, 2026
There has been a 5.9% decline in healthcare breaches compared to H1 2025.
general_metric
2025 H1
H1 2026 Healthcare Data Breach Report
Posted By
Steve Alder
on Sep 30, 2026
There has been a 5.9% decline in healthcare breaches compared to H1 2025.
Between January 1 and June 30, 2026
Between January 1 and June 30, 2026, OCR announced seven settlements to resolve alleged violations of the HIPAA Rules.
Click on any entity below to view its context and source!
industry
Health
Between January 1 and June 30, 2026, 397 data breaches affecting 500 or more individuals were reported to the U.S. Department of Health and Human Services (HHS) Office for Civil Rights – the lowest H1 total since 2023.
organisation
the U.S. Department of Health and Human Services
Between January 1 and June 30, 2026, 397 data breaches affecting 500 or more individuals were reported to the U.S. Department of Health and Human Services (HHS) Office for Civil Rights – the lowest H1 total since 2023.
organisation
HHS) Office for Civil Rights
Between January 1 and June 30, 2026, 397 data breaches affecting 500 or more individuals were reported to the U.S. Department of Health and Human Services (HHS) Office for Civil Rights – the lowest H1 total since 2023.
data_breach
397 data breaches
Between January 1 and June 30, 2026, 397 data breaches affecting 500 or more individuals were reported to the U.S. Department of Health and Human Services (HHS) Office for Civil Rights – the lowest H1 total since 2023.
general_metric
500 individuals
Between January 1 and June 30, 2026, 397 data breaches affecting 500 or more individuals were reported to the U.S. Department of Health and Human Services (HHS) Office for Civil Rights – the lowest H1 total since 2023.
organisation
the HIPAA Rules
Between January 1 and June 30, 2026, OCR announced seven settlements to resolve alleged violations of the HIPAA Rules, all seven of which included a financial penalty for a risk analysis violation.
2026/09/30
Over 1,000,000 individuals were affected by at least 999,999 healthcare data breaches involving regulated entities in the United States.
Click on any entity below to view its context and source!
infrastructure
5 Mississippi
…24
Missouri
3,468,743
4
New York
20
Texas
3,188,111
5
Illinois
16
Washington
2,270,117
6
Michigan
15
New York
2,113,172
7
North Carolina
14
Georgia
2,005,142
8
Pennsylvania
13
Maryland
1,968,198
9
Washington
13
Illinois
1,756,341
10
Massachusetts
12
Florida
846,997
11
Colorado
11
Io…
infrastructure
60,133 Mississippi
…24
Missouri
3,468,743
4
New York
20
Texas
3,188,111
5
Illinois
16
Washington
2,270,117
6
Michigan
15
New York
2,113,172
7
North Carolina
14
Georgia
2,005,142
8
Pennsylvania
13
Maryland
1,968,198
9
Washington
13
Illinois
1,756,341
10
Massachusetts
12
Florida
846,997
11
Colorado
11
Io…
infrastructure
26,937 Mississippi
…24
Missouri
3,468,743
4
New York
20
Texas
3,188,111
5
Illinois
16
Washington
2,270,117
6
Michigan
15
New York
2,113,172
7
North Carolina
14
Georgia
2,005,142
8
Pennsylvania
13
Maryland
1,968,198
9
Washington
13
Illinois
1,756,341
10
Massachusetts
12
Florida
846,997
11
Colorado
11
Io…
infrastructure
36 Mississippi
…24
Missouri
3,468,743
4
New York
20
Texas
3,188,111
5
Illinois
16
Washington
2,270,117
6
Michigan
15
New York
2,113,172
7
North Carolina
14
Georgia
2,005,142
8
Pennsylvania
13
Maryland
1,968,198
9
Washington
13
Illinois
1,756,341
10
Massachusetts
12
Florida
846,997
11
Colorado
11
Io…
organisation
Healthcare Data Breach Report
H1 2026 Healthcare Data Breach Report.
organisation
Lumexa Imaging
Rank
Regulated Entity
State
Covered Entity Type
Individuals Affected
Type of Breach
1
Lumexa Imaging
NC
Healthcare Provider
5,830,949
Hacking Incident
2
TriZetto Provider Solutions
MO
Business Associate
3,433,965
Hacking Incident
3
QualDerm Partners, LLC
TN
Healthcare Provider
2,951,318
Hacking Incident
4
Nacogdoches Memorial Hosp…
organisation
Healthcare Provider
Rank
Regulated Entity
State
Covered Entity Type
Individuals Affected
Type of Breach
1
Lumexa Imaging
NC
Healthcare Provider
5,830,949
Hacking Incident
2
TriZetto Provider Solutions
MO
Business Associate
3,433,965
Hacking Incident
3
QualDerm Partners, LLC
TN
Healthcare Provider
2,951,318
Hacking Incident
4
Nacogdoches Memorial Hosp…
organisation
Hacking Incident
Rank
Regulated Entity
State
Covered Entity Type
Individuals Affected
Type of Breach
1
Lumexa Imaging
NC
Healthcare Provider
5,830,949
Hacking Incident
2
TriZetto Provider Solutions
MO
Business Associate
3,433,965
Hacking Incident
3
QualDerm Partners, LLC
TN
Healthcare Provider
2,951,318
Hacking Incident
4
Nacogdoches Memorial Hosp…
organisation
TriZetto Provider Solutions
Rank
Regulated Entity
State
Covered Entity Type
Individuals Affected
Type of Breach
1
Lumexa Imaging
NC
Healthcare Provider
5,830,949
Hacking Incident
2
TriZetto Provider Solutions
MO
Business Associate
3,433,965
Hacking Incident
3
QualDerm Partners, LLC
TN
Healthcare Provider
2,951,318
Hacking Incident
4
Nacogdoches Memorial Hosp…
organisation
Business Associate
Rank
Regulated Entity
State
Covered Entity Type
Individuals Affected
Type of Breach
1
Lumexa Imaging
NC
Healthcare Provider
5,830,949
Hacking Incident
2
TriZetto Provider Solutions
MO
Business Associate
3,433,965
Hacking Incident
3
QualDerm Partners, LLC
TN
Healthcare Provider
2,951,318
Hacking Incident
4
Nacogdoches Memorial Hosp…
organisation
LLC
Rank
Regulated Entity
State
Covered Entity Type
Individuals Affected
Type of Breach
1
Lumexa Imaging
NC
Healthcare Provider
5,830,949
Hacking Incident
2
TriZetto Provider Solutions
MO
Business Associate
3,433,965
Hacking Incident
3
QualDerm Partners, LLC
TN
Healthcare Provider
2,951,318
Hacking Incident
4
Nacogdoches Memorial Hosp…
organisation
TN
Rank
Regulated Entity
State
Covered Entity Type
Individuals Affected
Type of Breach
1
Lumexa Imaging
NC
Healthcare Provider
5,830,949
Hacking Incident
2
TriZetto Provider Solutions
MO
Business Associate
3,433,965
Hacking Incident
3
QualDerm Partners, LLC
TN
Healthcare Provider
2,951,318
Hacking Incident
4
Nacogdoches Memorial Hosp…
organisation
Nacogdoches Memorial Hospital
Rank
Regulated Entity
State
Covered Entity Type
Individuals Affected
Type of Breach
1
Lumexa Imaging
NC
Healthcare Provider
5,830,949
Hacking Incident
2
TriZetto Provider Solutions
MO
Business Associate
3,433,965
Hacking Incident
3
QualDerm Partners, LLC
TN
Healthcare Provider
2,951,318
Hacking Incident
4
Nacogdoches Memorial Hosp…
organisation
TX
Rank
Regulated Entity
State
Covered Entity Type
Individuals Affected
Type of Breach
1
Lumexa Imaging
NC
Healthcare Provider
5,830,949
Hacking Incident
2
TriZetto Provider Solutions
MO
Business Associate
3,433,965
Hacking Incident
3
QualDerm Partners, LLC
TN
Healthcare Provider
2,951,318
Hacking Incident
4
Nacogdoches Memorial Hosp…
organisation
Navia Benefit Solutions, Inc.
Rank
Regulated Entity
State
Covered Entity Type
Individuals Affected
Type of Breach
1
Lumexa Imaging
NC
Healthcare Provider
5,830,949
Hacking Incident
2
TriZetto Provider Solutions
MO
Business Associate
3,433,965
Hacking Incident
3
QualDerm Partners, LLC
TN
Healthcare Provider
2,951,318
Hacking Incident
4
Nacogdoches Memorial Hosp…
organisation
Insightin Health, Inc.
Rank
Regulated Entity
State
Covered Entity Type
Individuals Affected
Type of Breach
1
Lumexa Imaging
NC
Healthcare Provider
5,830,949
Hacking Incident
2
TriZetto Provider Solutions
MO
Business Associate
3,433,965
Hacking Incident
3
QualDerm Partners, LLC
TN
Healthcare Provider
2,951,318
Hacking Incident
4
Nacogdoches Memorial Hosp…
organisation
Xsolis
Rank
Regulated Entity
State
Covered Entity Type
Individuals Affected
Type of Breach
1
Lumexa Imaging
NC
Healthcare Provider
5,830,949
Hacking Incident
2
TriZetto Provider Solutions
MO
Business Associate
3,433,965
Hacking Incident
3
QualDerm Partners, LLC
TN
Healthcare Provider
2,951,318
Hacking Incident
4
Nacogdoches Memorial Hosp…
organisation
Scale of Breach
…each – Affected Individuals
Data Breaches
Over 1,000,000
9
100,000 – 999,999
21
10,000 – 99,999
102
1000 – 9,999
175
Under 1000
90
Causes of H1 2026 Healthcare Data Breaches
While the number of large healthcare data breaches has fallen year-over-year, the lower H1 figures this year are due to fewer unauthorized access/disclosure and loss/theft…
data_breach
999,999 Data Breaches
…each – Affected Individuals
Data Breaches
Over 1,000,000
9
100,000 – 999,999
21
10,000 – 99,999
102
1000 – 9,999
175
Under 1000
90
Causes of H1 2026 Healthcare Data Breaches
While the number of large healthcare data breaches has fallen year-over-year, the lower H1 figures this year are due to fewer unauthorized access/disclosure and loss/theft…
data_breach
10,000 Data Breaches
…each – Affected Individuals
Data Breaches
Over 1,000,000
9
100,000 – 999,999
21
10,000 – 99,999
102
1000 – 9,999
175
Under 1000
90
Causes of H1 2026 Healthcare Data Breaches
While the number of large healthcare data breaches has fallen year-over-year, the lower H1 figures this year are due to fewer unauthorized access/disclosure and loss/theft…
data_breach
1000 Data Breaches
…each – Affected Individuals
Data Breaches
Over 1,000,000
9
100,000 – 999,999
21
10,000 – 99,999
102
1000 – 9,999
175
Under 1000
90
Causes of H1 2026 Healthcare Data Breaches
While the number of large healthcare data breaches has fallen year-over-year, the lower H1 figures this year are due to fewer unauthorized access/disclosure and loss/theft…
H1 2026
In H1 2026, unauthorized access and disclosure incidents were the second leading cause of healthcare data breaches.
Click on any entity below to view its context and source!
target_region
Puerto Rico
Geographic Distribution of Healthcare Data Breaches
In H1 2026, large healthcare data breaches were reported by HIPAA-regulated entities in 44 U.S. states, the District of Columbia, and Puerto Rico.
industry
Healthcare
Geographic Distribution of Healthcare Data Breaches
In H1 2026, large healthcare data breaches were reported by HIPAA-regulated entities in 44 U.S. states, the District of Columbia, and Puerto Rico.
The Biggest Healthcare Data Breaches in H1 2026
Business Services, LLC
GA
Business Associate
626,540
Hacking Incident (Ransomware)
13
Erie Family Health Centers
IL
Healthcare Provider
570,000
Hacking Incident
14
Centers Lab NJ LLC
NJ
Healthcare Provider
542,377
Hacking Incident
15
Networking Technology, Inc. (RXNT)
NC
Business Associate
353,844
Hacking Incident
16
Minnesota Depar…
H1 2026 Unauthorized Access/Disclosure Incidents
Unauthorized access and disclosure incidents were the second leading cause of healthcare data breaches in H1 2026.
While there were no new HIPAA updates in H1 2026, the compliance date for updates to the HIPAA Notice of Privacy Practices requirements was February 16, 2026 – the only surviving part of the now vacated HIPAA update to strengthen reproductive healthcare privacy.
general_metric
44 U.S. states
Geographic Distribution of Healthcare Data Breaches
In H1 2026, large healthcare data breaches were reported by HIPAA-regulated entities in 44 U.S. states, the District of Columbia, and Puerto Rico.
organisation
The Biggest Healthcare Data Breaches
The Biggest Healthcare Data Breaches in H1 2026
general_metric
20 Texas
Business Services, LLC
GA
Business Associate
626,540
Hacking Incident (Ransomware)
13
Erie Family Health Centers
IL
Healthcare Provider
570,000
Hacking Incident
14
Centers Lab NJ LLC
NJ
Healthcare Provider
542,377
Hacking Incident
15
Networking Technology, Inc. (RXNT)
NC
Business Associate
353,844
Hacking Incident
16
Minnesota Depar…
general_metric
16 Washington
Business Services, LLC
GA
Business Associate
626,540
Hacking Incident (Ransomware)
13
Erie Family Health Centers
IL
Healthcare Provider
570,000
Hacking Incident
14
Centers Lab NJ LLC
NJ
Healthcare Provider
542,377
Hacking Incident
15
Networking Technology, Inc. (RXNT)
NC
Business Associate
353,844
Hacking Incident
16
Minnesota Depar…
general_metric
15 New York
Business Services, LLC
GA
Business Associate
626,540
Hacking Incident (Ransomware)
13
Erie Family Health Centers
IL
Healthcare Provider
570,000
Hacking Incident
14
Centers Lab NJ LLC
NJ
Healthcare Provider
542,377
Hacking Incident
15
Networking Technology, Inc. (RXNT)
NC
Business Associate
353,844
Hacking Incident
16
Minnesota Depar…
general_metric
14 Georgia
Business Services, LLC
GA
Business Associate
626,540
Hacking Incident (Ransomware)
13
Erie Family Health Centers
IL
Healthcare Provider
570,000
Hacking Incident
14
Centers Lab NJ LLC
NJ
Healthcare Provider
542,377
Hacking Incident
15
Networking Technology, Inc. (RXNT)
NC
Business Associate
353,844
Hacking Incident
16
Minnesota Depar…
general_metric
13 Maryland
Business Services, LLC
GA
Business Associate
626,540
Hacking Incident (Ransomware)
13
Erie Family Health Centers
IL
Healthcare Provider
570,000
Hacking Incident
14
Centers Lab NJ LLC
NJ
Healthcare Provider
542,377
Hacking Incident
15
Networking Technology, Inc. (RXNT)
NC
Business Associate
353,844
Hacking Incident
16
Minnesota Depar…
general_metric
17 Indiana
Business Services, LLC
GA
Business Associate
626,540
Hacking Incident (Ransomware)
13
Erie Family Health Centers
IL
Healthcare Provider
570,000
Hacking Incident
14
Centers Lab NJ LLC
NJ
Healthcare Provider
542,377
Hacking Incident
15
Networking Technology, Inc. (RXNT)
NC
Business Associate
353,844
Hacking Incident
16
Minnesota Depar…
general_metric
18 Kentucky
Business Services, LLC
GA
Business Associate
626,540
Hacking Incident (Ransomware)
13
Erie Family Health Centers
IL
Healthcare Provider
570,000
Hacking Incident
14
Centers Lab NJ LLC
NJ
Healthcare Provider
542,377
Hacking Incident
15
Networking Technology, Inc. (RXNT)
NC
Business Associate
353,844
Hacking Incident
16
Minnesota Depar…
general_metric
19 Maryland
Business Services, LLC
GA
Business Associate
626,540
Hacking Incident (Ransomware)
13
Erie Family Health Centers
IL
Healthcare Provider
570,000
Hacking Incident
14
Centers Lab NJ LLC
NJ
Healthcare Provider
542,377
Hacking Incident
15
Networking Technology, Inc. (RXNT)
NC
Business Associate
353,844
Hacking Incident
16
Minnesota Depar…
industry
Health
Business Services, LLC
GA
Business Associate
626,540
Hacking Incident (Ransomware)
13
Erie Family Health Centers
IL
Healthcare Provider
570,000
Hacking Incident
14
Centers Lab NJ LLC
NJ
Healthcare Provider
542,377
Hacking Incident
15
Networking Technology, Inc. (RXNT)
NC
Business Associate
353,844
Hacking Incident
16
Minnesota Depar…
In H1 2026, health plan breaches were less severe.
target_region
New Caledonia
Business Services, LLC
GA
Business Associate
626,540
Hacking Incident (Ransomware)
13
Erie Family Health Centers
IL
Healthcare Provider
570,000
Hacking Incident
14
Centers Lab NJ LLC
NJ
Healthcare Provider
542,377
Hacking Incident
15
Networking Technology, Inc. (RXNT)
NC
Business Associate
353,844
Hacking Incident
16
Minnesota Depar…
industry
Technology
Business Services, LLC
GA
Business Associate
626,540
Hacking Incident (Ransomware)
13
Erie Family Health Centers
IL
Healthcare Provider
570,000
Hacking Incident
14
Centers Lab NJ LLC
NJ
Healthcare Provider
542,377
Hacking Incident
15
Networking Technology, Inc. (RXNT)
NC
Business Associate
353,844
Hacking Incident
16
Minnesota Depar…
organisation
Ransomware
Business Services, LLC
GA
Business Associate
626,540
Hacking Incident (Ransomware)
13
Erie Family Health Centers
IL
Healthcare Provider
570,000
Hacking Incident
14
Centers Lab NJ LLC
NJ
Healthcare Provider
542,377
Hacking Incident
15
Networking Technology, Inc. (RXNT)
NC
Business Associate
353,844
Hacking Incident
16
Minnesota Depar…
organisation
Business Services
Business Services, LLC
GA
Business Associate
626,540
Hacking Incident (Ransomware)
13
Erie Family Health Centers
IL
Healthcare Provider
570,000
Hacking Incident
14
Centers Lab NJ LLC
NJ
Healthcare Provider
542,377
Hacking Incident
15
Networking Technology, Inc. (RXNT)
NC
Business Associate
353,844
Hacking Incident
16
Minnesota Depar…
organisation
Hacking Incident (
Business Services, LLC
GA
Business Associate
626,540
Hacking Incident (Ransomware)
13
Erie Family Health Centers
IL
Healthcare Provider
570,000
Hacking Incident
14
Centers Lab NJ LLC
NJ
Healthcare Provider
542,377
Hacking Incident
15
Networking Technology, Inc. (RXNT)
NC
Business Associate
353,844
Hacking Incident
16
Minnesota Depar…
organisation
Erie Family Health Centers
IL
Business Services, LLC
GA
Business Associate
626,540
Hacking Incident (Ransomware)
13
Erie Family Health Centers
IL
Healthcare Provider
570,000
Hacking Incident
14
Centers Lab NJ LLC
NJ
Healthcare Provider
542,377
Hacking Incident
15
Networking Technology, Inc. (RXNT)
NC
Business Associate
353,844
Hacking Incident
16
Minnesota Depar…
organisation
Centers Lab NJ
Business Services, LLC
GA
Business Associate
626,540
Hacking Incident (Ransomware)
13
Erie Family Health Centers
IL
Healthcare Provider
570,000
Hacking Incident
14
Centers Lab NJ LLC
NJ
Healthcare Provider
542,377
Hacking Incident
15
Networking Technology, Inc. (RXNT)
NC
Business Associate
353,844
Hacking Incident
16
Minnesota Depar…
organisation
NJ
Business Services, LLC
GA
Business Associate
626,540
Hacking Incident (Ransomware)
13
Erie Family Health Centers
IL
Healthcare Provider
570,000
Hacking Incident
14
Centers Lab NJ LLC
NJ
Healthcare Provider
542,377
Hacking Incident
15
Networking Technology, Inc. (RXNT)
NC
Business Associate
353,844
Hacking Incident
16
Minnesota Depar…
organisation
Networking Technology, Inc.
Business Services, LLC
GA
Business Associate
626,540
Hacking Incident (Ransomware)
13
Erie Family Health Centers
IL
Healthcare Provider
570,000
Hacking Incident
14
Centers Lab NJ LLC
NJ
Healthcare Provider
542,377
Hacking Incident
15
Networking Technology, Inc. (RXNT)
NC
Business Associate
353,844
Hacking Incident
16
Minnesota Depar…
organisation
Minnesota Department of Human Services
Business Services, LLC
GA
Business Associate
626,540
Hacking Incident (Ransomware)
13
Erie Family Health Centers
IL
Healthcare Provider
570,000
Hacking Incident
14
Centers Lab NJ LLC
NJ
Healthcare Provider
542,377
Hacking Incident
15
Networking Technology, Inc. (RXNT)
NC
Business Associate
353,844
Hacking Incident
16
Minnesota Depar…
organisation
MN
Health Plan
Business Services, LLC
GA
Business Associate
626,540
Hacking Incident (Ransomware)
13
Erie Family Health Centers
IL
Healthcare Provider
570,000
Hacking Incident
14
Centers Lab NJ LLC
NJ
Healthcare Provider
542,377
Hacking Incident
15
Networking Technology, Inc. (RXNT)
NC
Business Associate
353,844
Hacking Incident
16
Minnesota Depar…
organisation
Unauthorized Access Incident
Business Services, LLC
GA
Business Associate
626,540
Hacking Incident (Ransomware)
13
Erie Family Health Centers
IL
Healthcare Provider
570,000
Hacking Incident
14
Centers Lab NJ LLC
NJ
Healthcare Provider
542,377
Hacking Incident
15
Networking Technology, Inc. (RXNT)
NC
Business Associate
353,844
Hacking Incident
16
Minnesota Depar…
organisation
North Texas Behavioral Health Authority
Business Services, LLC
GA
Business Associate
626,540
Hacking Incident (Ransomware)
13
Erie Family Health Centers
IL
Healthcare Provider
570,000
Hacking Incident
14
Centers Lab NJ LLC
NJ
Healthcare Provider
542,377
Hacking Incident
15
Networking Technology, Inc. (RXNT)
NC
Business Associate
353,844
Hacking Incident
16
Minnesota Depar…
organisation
Radiology Associates
Business Services, LLC
GA
Business Associate
626,540
Hacking Incident (Ransomware)
13
Erie Family Health Centers
IL
Healthcare Provider
570,000
Hacking Incident
14
Centers Lab NJ LLC
NJ
Healthcare Provider
542,377
Hacking Incident
15
Networking Technology, Inc. (RXNT)
NC
Business Associate
353,844
Hacking Incident
16
Minnesota Depar…
target_region
Holy See (Vatican City State)
Business Services, LLC
GA
Business Associate
626,540
Hacking Incident (Ransomware)
13
Erie Family Health Centers
IL
Healthcare Provider
570,000
Hacking Incident
14
Centers Lab NJ LLC
NJ
Healthcare Provider
542,377
Hacking Incident
15
Networking Technology, Inc. (RXNT)
NC
Business Associate
353,844
Hacking Incident
16
Minnesota Depar…
organisation
Anatomic and Clinical Laboratory Associates
Business Services, LLC
GA
Business Associate
626,540
Hacking Incident (Ransomware)
13
Erie Family Health Centers
IL
Healthcare Provider
570,000
Hacking Incident
14
Centers Lab NJ LLC
NJ
Healthcare Provider
542,377
Hacking Incident
15
Networking Technology, Inc. (RXNT)
NC
Business Associate
353,844
Hacking Incident
16
Minnesota Depar…
general_metric
626,540 LLC GA Business Associate
Business Services, LLC
GA
Business Associate
626,540
Hacking Incident (Ransomware)
13
Erie Family Health Centers
IL
Healthcare Provider
570,000
Hacking Incident
14
Centers Lab NJ LLC
NJ
Healthcare Provider
542,377
Hacking Incident
15
Networking Technology, Inc. (RXNT)
NC
Business Associate
353,844
Hacking Incident
16
Minnesota Depar…
general_metric
570,000 Hacking Incident
Business Services, LLC
GA
Business Associate
626,540
Hacking Incident (Ransomware)
13
Erie Family Health Centers
IL
Healthcare Provider
570,000
Hacking Incident
14
Centers Lab NJ LLC
NJ
Healthcare Provider
542,377
Hacking Incident
15
Networking Technology, Inc. (RXNT)
NC
Business Associate
353,844
Hacking Incident
16
Minnesota Depar…
general_metric
542,377 Hacking Incident
Business Services, LLC
GA
Business Associate
626,540
Hacking Incident (Ransomware)
13
Erie Family Health Centers
IL
Healthcare Provider
570,000
Hacking Incident
14
Centers Lab NJ LLC
NJ
Healthcare Provider
542,377
Hacking Incident
15
Networking Technology, Inc. (RXNT)
NC
Business Associate
353,844
Hacking Incident
16
Minnesota Depar…
general_metric
353,844 Hacking Incident
Business Services, LLC
GA
Business Associate
626,540
Hacking Incident (Ransomware)
13
Erie Family Health Centers
IL
Healthcare Provider
570,000
Hacking Incident
14
Centers Lab NJ LLC
NJ
Healthcare Provider
542,377
Hacking Incident
15
Networking Technology, Inc. (RXNT)
NC
Business Associate
353,844
Hacking Incident
16
Minnesota Depar…
general_metric
303,965 Unauthorized Access Incident
Business Services, LLC
GA
Business Associate
626,540
Hacking Incident (Ransomware)
13
Erie Family Health Centers
IL
Healthcare Provider
570,000
Hacking Incident
14
Centers Lab NJ LLC
NJ
Healthcare Provider
542,377
Hacking Incident
15
Networking Technology, Inc. (RXNT)
NC
Business Associate
353,844
Hacking Incident
16
Minnesota Depar…
general_metric
285,086 Hacking Incident
Business Services, LLC
GA
Business Associate
626,540
Hacking Incident (Ransomware)
13
Erie Family Health Centers
IL
Healthcare Provider
570,000
Hacking Incident
14
Centers Lab NJ LLC
NJ
Healthcare Provider
542,377
Hacking Incident
15
Networking Technology, Inc. (RXNT)
NC
Business Associate
353,844
Hacking Incident
16
Minnesota Depar…
general_metric
276,498 Hacking Incident
Business Services, LLC
GA
Business Associate
626,540
Hacking Incident (Ransomware)
13
Erie Family Health Centers
IL
Healthcare Provider
570,000
Hacking Incident
14
Centers Lab NJ LLC
NJ
Healthcare Provider
542,377
Hacking Incident
15
Networking Technology, Inc. (RXNT)
NC
Business Associate
353,844
Hacking Incident
16
Minnesota Depar…
general_metric
266,183 Hacking Incident
Business Services, LLC
GA
Business Associate
626,540
Hacking Incident (Ransomware)
13
Erie Family Health Centers
IL
Healthcare Provider
570,000
Hacking Incident
14
Centers Lab NJ LLC
NJ
Healthcare Provider
542,377
Hacking Incident
15
Networking Technology, Inc. (RXNT)
NC
Business Associate
353,844
Hacking Incident
16
Minnesota Depar…
general_metric
169,626 TN Healthcare Provider
Business Services, LLC
GA
Business Associate
626,540
Hacking Incident (Ransomware)
13
Erie Family Health Centers
IL
Healthcare Provider
570,000
Hacking Incident
14
Centers Lab NJ LLC
NJ
Healthcare Provider
542,377
Hacking Incident
15
Networking Technology, Inc. (RXNT)
NC
Business Associate
353,844
Hacking Incident
16
Minnesota Depar…
general_metric
10,000 individuals
Business Services, LLC
GA
Business Associate
626,540
Hacking Incident (Ransomware)
13
Erie Family Health Centers
IL
Healthcare Provider
570,000
Hacking Incident
14
Centers Lab NJ LLC
NJ
Healthcare Provider
542,377
Hacking Incident
15
Networking Technology, Inc. (RXNT)
NC
Business Associate
353,844
Hacking Incident
16
Minnesota Depar…
organisation
HIPAA
While there were no new HIPAA updates in H1 2026, the compliance date for updates to the HIPAA Notice of Privacy Practices requirements was February 16, 2026 – the only surviving part of the now vacated HIPAA update to strengthen reproductive healthcare privacy.
the first half of 2026
There were no new updates to the HIPAA Rules in the first half of 2026, but two pending final rules remained.
Click on any entity below to view its context and source!
organisation
HIPAA Regulatory Updates
HIPAA Regulatory Updates
There were no new updates to the HIPAA Rules in the first half of 2026, although there are two pending final rules.
July 2027
The target release date for the final rule was pushed back from May 2026 to July 2027.
Tactical Metrics
Metrics
infrastructure
5
Mississippi
Click for context!
…24
Missouri
3,468,743
4
New York
20
Texas
3,188,111
5
Illinois
16
Washington
2,270,117
6
Michigan
15
New York
2,113,172
7
North Carolina
14
Georgia
2,005,142
8
Pennsylvania
13
Maryland
1,968,198
9
Washington
13
Illinois
1,756,341
10
Massachusetts
12
Florida
846,997
11
Colorado
11
Io…
Metrics
infrastructure
60,133
Mississippi
…24
Missouri
3,468,743
4
New York
20
Texas
3,188,111
5
Illinois
16
Washington
2,270,117
6
Michigan
15
New York
2,113,172
7
North Carolina
14
Georgia
2,005,142
8
Pennsylvania
13
Maryland
1,968,198
9
Washington
13
Illinois
1,756,341
10
Massachusetts
12
Florida
846,997
11
Colorado
11
Io…
Metrics
infrastructure
26,937
Mississippi
…24
Missouri
3,468,743
4
New York
20
Texas
3,188,111
5
Illinois
16
Washington
2,270,117
6
Michigan
15
New York
2,113,172
7
North Carolina
14
Georgia
2,005,142
8
Pennsylvania
13
Maryland
1,968,198
9
Washington
13
Illinois
1,756,341
10
Massachusetts
12
Florida
846,997
11
Colorado
11
Io…
Metrics
infrastructure
36
Mississippi
…24
Missouri
3,468,743
4
New York
20
Texas
3,188,111
5
Illinois
16
Washington
2,270,117
6
Michigan
15
New York
2,113,172
7
North Carolina
14
Georgia
2,005,142
8
Pennsylvania
13
Maryland
1,968,198
9
Washington
13
Illinois
1,756,341
10
Massachusetts
12
Florida
846,997
11
Colorado
11
Io…
Metrics
data_breach
397
Data Breaches
Between January 1 and June 30, 2026, 397 data breaches affecting 500 or more individuals were reported to the U.S. Department of Health and Human Services (HHS) Office for Civil Rights – the lowest H1 total since 2023.
Across the 397 reported data breaches, the protected health information of 33.77 million individuals was exposed or impermissibly disclosed.
Metrics
data_breach
804
Data Breaches
If data breaches continue to be reported at a similar rate in the second half of the year, the end-of-year healthcare data breach total is likely to be lower than 2025, which was a record-breaking year with 804 data breaches currently listed on the OCR breach portal for 2025.
Metrics
data_breach
37
Data Breaches
Currently, 37 healthcare data breaches are listed as affecting 500 or 501 individuals.
The majority of those 37 data breaches are likely to see the totals increased, potentially significantly.
Metrics
data_breach
999,999
Data Breaches
…each – Affected Individuals
Data Breaches
Over 1,000,000
9
100,000 – 999,999
21
10,000 – 99,999
102
1000 – 9,999
175
Under 1000
90
Causes of H1 2026 Healthcare Data Breaches
While the number of large healthcare data breaches has fallen year-over-year, the lower H1 figures this year are due to fewer unauthorized access/disclosure and loss/theft…
Metrics
data_breach
10,000
Data Breaches
…each – Affected Individuals
Data Breaches
Over 1,000,000
9
100,000 – 999,999
21
10,000 – 99,999
102
1000 – 9,999
175
Under 1000
90
Causes of H1 2026 Healthcare Data Breaches
While the number of large healthcare data breaches has fallen year-over-year, the lower H1 figures this year are due to fewer unauthorized access/disclosure and loss/theft…
Metrics
data_breach
1,000
Data Breaches
…each – Affected Individuals
Data Breaches
Over 1,000,000
9
100,000 – 999,999
21
10,000 – 99,999
102
1000 – 9,999
175
Under 1000
90
Causes of H1 2026 Healthcare Data Breaches
While the number of large healthcare data breaches has fallen year-over-year, the lower H1 figures this year are due to fewer unauthorized access/disclosure and loss/theft…
Metrics
data_breach
290
Data Breaches
Data Breaches at HIPAA Regulated Entities
Healthcare providers were the worst affected HIPAA-regulated entities in H1 2026 (290 data breaches), followed by business associates (59 data breaches), and health plans (48 data breaches).
Metrics
data_breach
59
Data Breaches
Data Breaches at HIPAA Regulated Entities
Healthcare providers were the worst affected HIPAA-regulated entities in H1 2026 (290 data breaches), followed by business associates (59 data breaches), and health plans (48 data breaches).
Metrics
data_breach
48
Data Breaches
Data Breaches at HIPAA Regulated Entities
Healthcare providers were the worst affected HIPAA-regulated entities in H1 2026 (290 data breaches), followed by business associates (59 data breaches), and health plans (48 data breaches).
Metrics
financial
450,000
$ Analysis Failure
H1 2026 HIPAA Settlements and Civil Monetary Penalties
Covered Entity
Type of Entity
Amount
Settlement / Civil Monetary Penalty
Reason
Spencer Gifts LLC Flexible Benefits and Welfare Benefit Plans
Health Plan
$450,000
Settlement
Risk analysis failure; failure to implement Privacy, Security, and Breach Notification Rule policies and procedures.
Metrics
financial
320,000
$ Analysis Failure
Healthcare Provider
$320,000
Settlement
Risk analysis failure; impermissible disclosure of the ePHI of 10,023 individuals.
Metrics
financial
375,000
$ Analysis Failure
Assured Imaging Affiliated Covered Entities
Healthcare Provider
$375,000
Settlement
Risk analysis failure (never conducted); breach notification failure.
Metrics
financial
245,000
$ Plan Analysis Failure
Star Group, L.P. Health Benefits Plan
Health Plan
$245,000
Settlement
Risk analysis failure.
Metrics
financial
103,000
$ Analysis Failure
Top of the World Ranch Treatment Center
Healthcare Provider
$103,000
Settlement
Risk analysis failure
OCR is the main enforcer of the HIPAA Rules, although state attorneys general are also authorized to enforce HIPAA compliance and can impose financial penalties in their respective states.
Metrics
financial
10,000
$ Associate Analysis Failure
MMG Fusion
Business Associate
$10,000
Settlement
Risk analysis failure; impermissible use/disclosure of PHI; breach notification rule failure.
Metrics
financial
225,000
$ Associate Analysis Failure
Business Associate
$225,000
Settlement
Risk analysis failure.
Metrics
financial
515,000
$ Financial Penalty
The case was settled with a $515,000 financial penalty.
Intelligence Sources
HIPAA Journal
2026-09-30
H1 2026 Healthcare Data Breach Report
HIPAA Journal
Unpublish from Social Media?
Are you sure you want to delete this podcast video from all synchronized social networks (YouTube, Facebook, Threads)?
Important:
Due to Meta API restrictions, Instagram Reels cannot be deleted automatically via API by third-party apps.
View Profile to Delete Manually
View Profile to Delete Manually
Tactical Intelligence
Report Intelligence Issue
Podcast Options
Generate
Incident Version History
CURRENT VERSION
Last Updated: 2026-10-05T10:38
Comprehensive Tactical Telemetry
Highly Correlated Entities
68x
organisation
Identified Entity
Healthcare Data Breach Report
entity
26x
timeline
Temporal Reference
H1 2026
date
21x
general metric
Individuals
500
individuals
13x
general metric
Hacking Incident
5,830,949
hacking incident
9x
general metric
%
6
%
9x
data breach
Data Breaches
397
data breaches
8x
target region
Target Country
Puerto Rico
country
5x
tactic
Cyber Operation Type
Data Breach
tactic
4x
industry
Targeted Sector
Healthcare
sector
4x
general metric
New York
4
new york
4x
general metric
Georgia Colorado Indiana Connecticut Delaware Enforcement Activity
846,997
georgia colorado indiana connecticut delaware enforcement activity
4x
infrastructure
Mississippi
5
mississippi
4x
financial
$ Analysis Failure
450,000
$ analysis failure
3x
general metric
North Carolina
38
north carolina
3x
general metric
Texas
2
texas
3x
general metric
Missouri
24
missouri
3x
general metric
Washington
16
washington
3x
general metric
Georgia
14
georgia
2x
general metric
California
1
california
2x
general metric
Tennessee
36
tennessee
2x
general metric
Michigan
6
michigan
2x
general metric
Maryland
13
maryland
2x
general metric
Pennsylvania
1,968,198
pennsylvania
2x
general metric
Massachusetts
1,756,341
massachusetts
2x
general metric
Colorado
11
colorado
2x
general metric
Indiana
17
indiana
2x
general metric
Kentucky
318,963
kentucky
2x
general metric
Oklahoma
139,151
oklahoma
2x
general metric
South Carolina
133,735
south carolina
2x
general metric
Alabama
116,236
alabama
2x
general metric
Utah
82,335
utah
2x
general metric
Arizona
40,760
arizona
2x
general metric
Arkansas
37,796
arkansas
2x
general metric
Wisconsin
10,278
wisconsin
2x
general metric
Delaware
5,800
delaware
2x
general metric
Nebraska
5,630
nebraska
2x
general metric
Nevada
2,654
nevada
2x
general metric
New Hampshire
1,221
new hampshire
2x
general metric
H1
2,026
h1
2x
general metric
Tn Healthcare Provider
2,951,318
tn healthcare provider
2x
general metric
Llc Ga Business Associate
1,261,464
llc ga business associate
2x
general metric
Causes
1,000
causes
2x
financial
$ Associate Analysis Failure
10,000
$ associate analysis failure
Contextual Telemetry
Context Block
28 METRICS
general metric
U.S. States
44
u.s. states
general metric
Illinois
5
illinois
general metric
Florida
12
florida
general metric
Virginia
702,065
virginia
general metric
Ohio
458,060
ohio
general metric
Connecticut
103,406
connecticut
general metric
Iowa
26
iowa
general metric
Oregon
27
oregon
general metric
Idaho
29
idaho
general metric
Kansas
30
kansas
general metric
Maine
45,932
maine
general metric
Louisiana
32
louisiana
general metric
District
37,963
district
general metric
Puerto Rico
37
puerto rico
general metric
West Virginia
18,392
west virginia
general metric
Alaska
40
alaska
general metric
Ia Business Associate
716,000
ia business associate
general metric
Unauthorized Disclosure Incident
705,017
unauthorized disclosure incident
general metric
Unauthorized Access Incident
303,965
unauthorized access incident
general metric
Scale
175
scale
financial
$ Plan Analysis Failure
245,000
$ plan analysis failure
general metric
Massachusetts Residents
326,426
massachusetts residents
general metric
Connecticut Residents
22,829
connecticut residents
general metric
Financial Penalties
55
financial penalties
general metric
Hacking It Incidents
343
hacking it incidents
general metric
Unauthorized Disclosure Incidents
51
unauthorized disclosure incidents
general metric
Breaches
100
breaches
financial
$ Financial Penalty
515,000
$ financial penalty
Click on any entity below to view its context in the main text!
Selective Unpublish
Selecciona las redes de las que quieres eliminar esta publicación. El sistema intentará borrar el post real de la API y limpiará la base de datos para que puedas volver a lanzarlo.
By navigating this website, you accept the use of strictly necessary technical cookies for session security and basic platform functionality. We do not use tracking or advertising cookies.
Read our Privacy Policy.