HIPAA Breach Reports, Measured from the Full OCR Register

The HHS Office for Civil Rights has published 7,868 reports of health-data breaches affecting 500 or more individuals since the portal opened in 2009, covering a cumulative 1,068,108,531 individuals — figures computed from both public views of the portal (the open-investigation list and the resolved archive) as of 2026-08-20. The structural story is the takeover by hacking: 4% of reports in 2010 named a hacking or IT incident; in 2025 it was 80.9%, and in 2026 so far it is 87.4%.

The register records when each report reached OCR, not when the breach happened or was discovered, so these are statistics about reports received — not a measure of anyone's compliance with a notification deadline.

Reviewed by · Updated

The headline numbers

HIPAA's Breach Notification Rule requires covered entities to notify HHS of any breach of unsecured protected health information affecting 500 or more individuals, and HHS posts each report to a public portal as required by the HITECH Act. The portal shows at most 500 rows on screen; the figures below merge full CSV exports of both of its views — cases currently under investigation (711 reports at the snapshot date) and the resolved archive.

No published dataset tabulates the merged register in this form, which is why this page exists. The monthly series is downloadable as CSV at the link in the method note.

HIPAA large-breach reports on the OCR portal (snapshot 2026-08-20)

PopulationReportsIndividuals affected
All reports (2009–present)7,8681,068,108,531
2025 (last full year)795140,308,908
2026 through 2026-08-2043051,403,197
2025 same period, for comparison52767,238,753

Source: HHS Office for Civil Rights breach portal (reports of breaches affecting 500 or more individuals), https://ocrportal.hhs.gov/ocr/breach/breach_report.jsf, snapshot 2026-08-20. Computed by ComplianceDocs; method below. Cumulative individuals-affected counts the same person again each time a different breach affects them.

Hacking took over the register

In 2010, the register's first full year, 4% of reports named a hacking or IT incident as the breach type — the era's breaches were lost laptops, misdirected mail and stolen paper. By 2019 hacking's share had passed 60%, and it has stayed above 75% every year since 2021. 2025 set the register's record for reports in a year (795), and 140,308,908 individuals were affected in that single year.

2026 is so far running below 2025's pace — 430 reports through 2026-08-20 against 527 in the same period a year earlier — the first meaningful year-over-year decline in the register's recent history, though partial-year figures move.

HIPAA large-breach reports by submission year (OCR portal)

YearReportsHacking/IT shareIndividuals affected
2009 (portal opened Oct)180%134,773
20101994%5,932,276
20112008.5%13,162,158
20122177.8%2,853,985
201327710.5%7,018,839
201431412.4%19,073,551
201527020.7%112,466,720
201632834.8%16,711,004
201735741.7%5,313,246
201836944.7%15,256,235
201951161.4%44,969,724
202066368.9%35,321,223
202171576.4%61,206,238
202271879.1%64,053,662
202374681.5%183,065,401
202474182.6%289,857,391
202579580.9%140,308,908
2026 (partial year)43087.4%51,403,197

Year = the year the report was submitted to OCR. Breach types as published by the register; "hacking" counts rows typed Hacking/IT Incident.

Who reports, and how large the breaches are

In 2025, 75.2% of reports came from healthcare providers, and a business associate was present in 35.1% of all reports — the vendor-breach channel is a third of the register. The median 2025 breach affected 4,824 individuals, while 12.1% of reports crossed 100,000 — the register is many small incidents punctuated by a few enormous ones.

The largest single report on the register is Change Healthcare, Inc. (2024), affecting 192,700,000 individuals — reported as a hacking/it incident — followed by Anthem Inc. (2015, 78,800,000) and Conduent Business Services LLC (2025, 62,224,658). Entity names and figures are as published on the federal register.

Reports by covered-entity type, 2025 (OCR portal)

Entity typeReportsShare
Healthcare Provider59875.2%
Business Associate13617.1%
Health Plan597.4%
Healthcare Clearing House20.3%

Business-associate PRESENCE (a vendor involved in the breach, whatever the reporting entity) is a separate flag: 35.1% of all 2025 reports.

What the register does — and does not — measure

Every date on the portal is the date OCR RECEIVED the report. The register does not publish when the breach occurred or when the organization discovered it, so no statistic on this page measures how long anyone took, and none measures compliance with any deadline.

For context, the deadline that governs these reports: HIPAA's Breach Notification Rule requires individual notice “without unreasonable delay and in no case later than 60 calendar days after discovery” (45 CFR 164.404(b), text verified against the current eCFR on 2026-08-20), and breaches affecting 500 or more individuals must be reported to HHS at the same time. Whether any particular report met that clock cannot be read from this register — measuring occurrence-to-disclosure distance requires a register that publishes both dates, which is what our companion analysis of California's register does.

Also outside this register: breaches affecting fewer than 500 individuals (reported to OCR annually, not published here), and OCR's enforcement outcomes (resolution agreements and penalties), which are published separately.

Method, exclusions and the dataset

Both public views of the OCR breach portal (cases currently under investigation, and the resolved archive) were exported as CSV on the as-of date and merged, deduplicating identical rows. The portal publishes the date each report was SUBMITTED to OCR — not the breach or discovery date — so every figure here is a statistic about reports received, and no interval or deadline-compliance statistic is computable from this register. Only breaches affecting 500 or more individuals appear; smaller breaches are reported to OCR annually and are not published here.

Of 7,873 exported rows at the snapshot date, 5 duplicates across the two views were removed and 0 rows carried no parseable submission date, leaving 7,868 reports in the tabulation.

The full monthly series is available as a CSV dataset at /datasets/hipaa-breach-reports-monthly.csv and may be cited with attribution to ComplianceDocs and the HHS OCR breach portal as the underlying source. This page reports the register as published; it is not legal advice.

Charts, dataset and reuse

The charts and the underlying tabulated dataset on this page are published under CC BY 4.0: reuse them in your own article, report or deck, with attribution to ComplianceDocs — a link back to this page is the attribution form we ask for. The underlying government register is public information; the license covers this tabulation and these charts.

Bar chart: HIPAA breach reports affecting 500 or more individuals per submission year, 2010 through 2025, peaking at 795 reports in 2025
Large-breach reports submitted to the OCR portal per year. · Download SVG
Line chart: hacking and IT incidents as a share of HIPAA breach reports, rising from 4 percent in 2010 to about 81 percent in 2025
Hacking/IT incidents as a share of reports, by submission year. · Download SVG

Dataset: HIPAA large-breach reports per month (CSV; snapshot-dated, methodology above).

Cite this data

ComplianceDocs, “HIPAA large-breach reports per month, HHS OCR breach portal,” https://compliancedocshq.com/learn/hipaa-breach-statistics. Underlying register as named in the method note.

Embed a chart

Copy and paste — the snippet credits the source for you:

<a href="https://compliancedocshq.com/learn/hipaa-breach-statistics"><img src="https://compliancedocshq.com/charts/hipaa-breach-reports-by-year.svg" alt="Bar chart: HIPAA breach reports affecting 500 or more individuals per submission year, 2010 through 2025, peaking at 795 reports in 2025" width="720" style="max-width:100%;height:auto"></a>
<p>Source: <a href="https://compliancedocshq.com/learn/hipaa-breach-statistics">ComplianceDocs — HIPAA Breach Reports, Measured from the Full OCR Register</a></p>

Frequently asked questions

How many HIPAA breaches were reported in 2025?
795 breaches affecting 500 or more individuals were reported to HHS OCR in 2025 — the register's record year — affecting 140,308,908 individuals in total. 80.9% were reported as hacking or IT incidents.
How many HIPAA breaches have been reported in 2026?
430 large-breach reports through 2026-08-20, affecting 51,403,197 individuals — below the 527 reports in the same period of 2025. Partial-year figures move as new reports post.
What share of HIPAA breaches are caused by hacking?
80.9% of 2025 reports on the OCR portal were typed Hacking/IT Incident, up from 4% in 2010. So far in 2026 the share is 87.4%.
What is the largest HIPAA breach ever reported?
Change Healthcare, Inc., reported in 2024: 192,700,000 individuals, typed Hacking/IT Incident on the register. Across the register's full history, 1,068,108,531 individuals have been affected cumulatively (the same person counts again in each separate breach).
What is the HIPAA breach notification deadline?
HIPAA's Breach Notification Rule requires individual notice “without unreasonable delay and in no case later than 60 calendar days after discovery” (45 CFR 164.404(b), verified against the current eCFR on 2026-08-20). Breaches affecting 500 or more individuals are reported to HHS at the same time; smaller breaches are reported annually. This register publishes submission dates only, so it cannot show whether any report met the deadline — and this page makes no such claim.
Where does this data come from?
Every figure is computed from CSV exports of both public views of the HHS OCR breach portal (https://ocrportal.hhs.gov/ocr/breach/breach_report.jsf) — the open-investigation list and the resolved archive — snapshot 2026-08-20. The computation method and every exclusion are stated on this page, and the monthly series is downloadable as CSV.

Related guides: HIPAA

Toolkits that help

HIPAA Security & Privacy Rules

HIPAA Compliance Toolkit — Medical Practices

18 editable HIPAA policies plus the Security Risk Assessment workbook and audit evidence checklist, written for small medical practices and clinics.

HIPAA Security & Privacy Rules

HIPAA Compliance Toolkit — Dental Practices

18 editable HIPAA policies plus the Security Risk Assessment workbook and audit evidence checklist, written specifically for dental offices.

HIPAA Security & Privacy Rules

HIPAA Compliance Toolkit — Mental Health Practices

18 editable HIPAA policies written for therapists and behavioral-health practices — teletherapy security, psychotherapy-notes handling — plus the Security Risk Assessment workbook and audit evidence checklist.

Related articles

Get new templates and guides by email

An occasional email when we publish a new free template, guide, or dataset. Unsubscribe any time.

← All articles

Professional editable templates — general information only, not legal, audit, tax, or certification advice, and no professional or advisory relationship is created. No purchase makes an organization compliant or certified. Review each document with qualified counsel, your compliance professional, or your auditor before relying on it. ISO, IEC, SOC 2, AICPA, HIPAA, NIST, GDPR, the EU AI Act, IRS and FTC are referenced descriptively only; ComplianceDocs (ExpertEngine LLC) is independent and is not affiliated with, endorsed by, or certified by any standards body, regulator, or audit firm.