Healthcare Insights

20 largest healthcare data breaches

Under the HIPAA Breach Notification Rule, HIPAA-covered entities and their business associates must provide notification following a breach of unsecured protected health information (PHI). The Federal Trade Commission (FTC) has similar provisions that apply to vendors of personal health records and their third-party service providers.

The Secretary of the U.S Department of Health and Human Services (HHS) maintains a list of data breaches affecting 500 or more individuals’ PHI. The Definitive Healthcare HospitalView product tracks specific healthcare data breaches that take place at U.S. hospitals and healthcare systems.

This Healthcare Insight reviews the largest healthcare data breaches in 2021 and 2022 based on the number of patient records affected. Data from the HHS breach portal was accessed January 5, 2023.

Top 2021 healthcare data breaches by affected records

RankStateCovered entity typeIndividuals affectedType of breachLocation of breached informationStatusExplore dataset
1FLBusiness Associate4,142,440Hacking/IT incidentNetwork serverResolvedExplore
2FLHealth Plan3,500,000Hacking/IT incidentNetwork serverResolvedExplore
3CABusiness Associate2,592,494Hacking/IT incidentNetwork serverUnder investigationExplore
4WIHealthcare Provider2,413,553Hacking/IT incidentNetwork serverResolvedExplore
5FLHealthcare Provider1,737,775Hacking/IT incidentNetwork serverUnder investigationExplore
6TXBusiness Associate1,656,569Hacking/IT incidentNetwork serverUnder investigationExplore
7INHealthcare Provider1,515,918Hacking/IT incidentNetwork serverUnder investigationExplore
8OHHealthcare Provider1,474,284Hacking/IT incidentNetwork serverUnder investigationExplore
9GAHealthcare Provider1,400,000Hacking/IT incidentNetwork serverUnder investigationExplore
10NVHealthcare Provider1,300,000Hacking/IT incidentNetwork serverUnder investigationExplore
11NYHealthcare Provider1,269,074Hacking/IT incidentEmailUnder investigationExplore
12NMHealthcare Provider1,228,093Hacking/IT incidentNetwork serverResolvedExplore
13NYBusiness Associate1,210,688Hacking/IT incidentNetwork serverUnder investigationExplore
14MDHealthcare Provider824,450Hacking/IT incidentEmailResolvedExplore
15NYBusiness Associate753,107Hacking/IT incidentNetwork serverResolvedExplore
16ORHealthcare Provider750,500Hacking/IT incidentNetwork serverUnder investigationExplore
17FLHealthcare Provider700,934Hacking/IT incidentNetwork serverResolvedExplore
18CAHealth Plan688,603Hacking/IT incidentNetwork serverResolvedExplore
19WAHealthcare Provider688,000Hacking/IT incidentNetwork serverUnder investigationExplore
20AZBusiness Associate685,574Hacking/IT incidentNetwork serverResolvedExplore

Fig. 1. Data is from the HHS Breach Portal. Accessed January 2023.

What were the largest healthcare data breach incidents in 2021?

Out of the 715 healthcare data breaches in 2021, the top twenty account for more than half, or 30.5 million, of the 54.1 million total individuals affected. The largest incident compromised over 4.1 million records and three breaches affected more than 2 million individuals each.

Healthcare provider organizations, including healthcare systems, hospitals, and physician groups) represent 12 of the largest data breaches in 2021, followed by business associates (6) and health plans (2). All were data hacks and all but two of the top 20 healthcare data breaches affected network servers.

Top 2022 healthcare data breaches by affected records

RankStateCovered entity typeIndividuals affectedType of breachLocation of breached informationStatusExplore dataset
1WIBusiness Associate4,112,892Hacking/IT incidentNetwork serverUnder investigationExplore
2WIHealthcare Provider3,000,000Unauthorized access/disclosureElectronic medical recordUnder investigationExplore
3PABusiness Associate2,216,365Hacking/IT incidentNetwork serverUnder investigationExplore
4MABusiness Associate2,000,000Hacking/IT incidentNetwork serverUnder investigationExplore
5COBusiness Associate1,918,941Hacking/IT incidentNetwork serverUnder investigationExplore
6TXHealthcare Provider1,608,549Hacking/IT incidentNetwork serverUnder investigationExplore
7INHealthcare Provider1,500,000Unauthorized access/disclosureNetwork serverUnder investigationExplore
8NCBusiness Associate1,362,296Unauthorized access/disclosureElectronic medical recordUnder investigationExplore
9FLHealthcare Provider1,351,431Hacking/IT incidentNetwork serverUnder investigationExplore
10TXHealthcare Provider1,290,104Hacking/IT incidentOtherUnder investigationExplore
11PRHealthcare Provider1,195,220Hacking/IT incidentNetwork serverUnder investigationExplore
12NYBusiness Associate942,138Hacking/IT incidentNetwork serverUnder investigationExplore
13MIHealthcare Provider877,584Hacking/IT incidentNetwork serverUnder investigationExplore
14CAHealth Plan854,913Hacking/IT incidentNetwork serverUnder investigationExplore
15WABusiness Associate793,283Hacking/IT incidentNetwork serverUnder investigationExplore
16AZHealthcare Provider737,448Hacking/IT incidentNetwork serverUnder investigationExplore
17AZHealth Plan637,999Hacking/IT incidentNetwork serverUnder investigationExplore
18ILBusiness Associate623,774Hacking/IT incidentNetwork serverUnder investigationExplore
19TXHealthcare Provider612,000Hacking/IT incidentNetwork serverUnder investigationExplore
20IAHealthcare Provider542,776Hacking/IT incidentElectronic medical recordUnder investigationExplore

Fig. 2. Data is from the HHS Breach Portal. Accessed January 2023.

What were the largest healthcare data breach incidents in 2022?

As of January 2023, there were 693 healthcare data breaches reported for 2022. The top 20 breaches by total individuals affected account for 55% of all records compromised – 28.2 million of 51.3 million records. The two largest incidents affected 3 million individuals or more.

Half of the largest 2022 healthcare data breaches were at provider organizations, eight were though business associates and two at health plans. Most were hacking incidents with three instances of unauthorized access. Network servers were attacked in most cases with electronic medical records breached in three incidents.

Learn more

Healthcare Insights are developed with healthcare commercial intelligence from the Definitive Healthcare platform. Want even more insights? Start a free trial now and get access to the latest healthcare commercial intelligence on hospitals, physicians, and other healthcare providers.