Breach intelligence tracker
Every HIPAA breach reported to HHS OCR, every State AG notification we can parse, every OCR enforcement action, and the FTC and CISA filings adjacent to healthcare. Maintained by Patient Protect Research and free to use with attribution.
Recent breaches
Back to newsroom →| Organization | State | Records | Vector | Source | Reported |
|---|---|---|---|---|---|
| Virta Medical PC | CA | — | Breach | State AG | Jun 12 |
| Clinical Registry Solutions | CA | — | Breach | State AG | Jun 11 |
| Gay & Lesbian Community Services Center of Orange County Inc | WA | 1,249 | Breach | State AG | Jun 5 |
| JASON R EGBERT OD PC | WA | 1,225 | Hacking/IT Incident | HHS OCR | Jun 10 |
| WellPoint (Independent Clinics of Washington, Elevance Health) | WA | 12,017 | Breach | State AG | Jun 2 |
| Indiana Family and Social Services Administration (FSSA) | IN | — | IT Incident | State AG | Jun 1 |
| Unnamed Entity | IN | 1 | Unknown | State AG | Jun 1 |
| Indiana Attorney General | IN | — | Hacking | State AG | Jun 1 |
| United Medical Doctors | CA | 501 | Hacking/IT Incident | HHS OCR | Jun 17 |
| Networking Technology, Inc. (RXNT) | WA | 4,480 | Breach | State AG | May 29 |
| IMA Diligence Services, LLC | WA | 1,977 | Breach | State AG | May 29 |
| MCNA Dental | IN | 8,900,000 | Hacking | State AG | May 26 |
| Wellmark Health Insurance | IA | 6,666 | Unauthorized Access/Disclosure | HHS OCR | Jun 5 |
| Spokane Digestive Disease Center, P.S. | WA | 2,093 | Breach | State AG | May 26 |
| ERMI LLC | CA | — | Breach | State AG | May 26 |
| Virta Medical PC | CO | 14,636 | Hacking/IT Incident | HHS OCR | Jun 16 |
| Equinix Incorporated Group Health and Welfare Benefit Plan | CA | 677 | Hacking/IT Incident | HHS OCR | Jun 4 |
| Acadia Healthcare Company, Inc | TN | 1,807 | Hacking/IT Incident | HHS OCR | Jun 10 |
| Oakwood Lutheran Senior Ministries, Inc. | WI | 1,080 | Hacking/IT Incident | HHS OCR | Jun 17 |
| Southern Illinois Ob-Gyn Associates, S.C. | IL | 38,700 | Hacking/IT Incident | HHS OCR | Jun 3 |
| AUTOAPS LLC | CA | 1,591 | Hacking/IT Incident | HHS OCR | Jun 10 |
| Gastro Health | FL | 1,628 | Hacking/IT Incident | HHS OCR | Jun 16 |
| Nottingham Village | PA | 5,240 | Hacking/IT Incident | HHS OCR | Jun 16 |
| DentaQuest | MA | 3,086 | Unauthorized Access/Disclosure | HHS OCR | Jun 9 |
| Radiology Associates of Richmond | VA | 266,183 | Hacking/IT Incident | HHS OCR | Jun 9 |
Recent OCR enforcement
Resolution agreements, civil money penalties, corrective action plans| Organization | State | Records | Vector | Source | Reported |
|---|---|---|---|---|---|
| Texas Medical Practice | TX | 1 | Enforcement | OCR Enforcement | Dec 6 |
| New York Medical Practice | NY | 1 | Enforcement | OCR Enforcement | Nov 8 |
| California Medical Practice | CA | 1 | Enforcement | OCR Enforcement | Oct 18 |
| Lovelace Health System | NM | 1,900,000 | Enforcement | OCR Enforcement | Sep 20 |
| Allegheny Health Network | PA | 10,000 | Enforcement | OCR Enforcement | Aug 9 |
| Eye Care Leaders | NC | 3,000,000 | Enforcement | OCR Enforcement | Aug 1 |
| Perry Memorial Hospital | IL | 1 | Enforcement | OCR Enforcement | Jun 14 |
| Anthem, Inc. | IN | 78,800,000 | Enforcement | OCR Enforcement | Jun 1 |
Using this data in your reporting
Methodology
The HIPAA Pulse breach tracker pulls from five public-record data streams that together form a near-complete picture of healthcare cybersecurity incidents. Each row in the tracker originates in a regulator filing, an enforcement action, or a government advisory — never an unverified claim.
Sources
- HHS OCR Breach Portal Primary
- The U.S. Department of Health and Human Services, Office for Civil Rights maintains the official Breach Notification Portal. Under HIPAA, covered entities must report breaches affecting 500 or more individuals. This is the most authoritative federal source for healthcare breach data.
- State Attorney General notifications Primary
- State AGs receive breach notifications under state-level data breach laws. Many states require notification for breaches smaller than the federal 500-person threshold, making AG data a critical supplement that often surfaces weeks before the federal portal updates.
- OCR enforcement actions Regulatory
- Resolution Agreements (negotiated settlements), Civil Money Penalties, and Corrective Action Plans imposed on covered entities for HIPAA violations. Enforcement data identifies which breaches led to regulatory consequences and the financial penalties that followed.
- FTC Health Breach Notification Rule Regulatory
- The Federal Trade Commission enforces the HBNR for entities that handle health data outside HIPAA’s jurisdiction — consumer health apps, wearable device makers, and non-HIPAA-covered services. FTC data captures healthcare-adjacent breaches the OCR portal does not.
- CISA medical-device advisories Cyber
- The Cybersecurity and Infrastructure Security Agency publishes advisories for vulnerabilities in medical devices and healthcare IT systems. Advisories include CVE identifiers, CVSS scores, affected products, and patch availability. They are leading indicators — flagged here as advisories, not breaches, until confirmed exploitation appears in HHS or AG filings.
What we exclude from the public tracker
The platform behind this tracker also ingests two streams we do not publish here: modeled breach projections (statistically inferred from leading indicators) and internal Patient Protect Network reports (community-reported incidents from the Patient Protect platform). These belong in compliance tooling, not in a public publication. The HIPAA Pulse tracker is restricted to incidents with public-record provenance: a regulator filing, an enforcement record, or a government advisory.
Severity, scoring, and reporting lag
Each incident carries a severity score (0–100) computed from individuals affected (35%), attack vector risk (25%), entity criticality (15%), enforcement history (10%), and source confidence (15%). Source confidence is highest for HHS OCR (95%) and FTC (90%); lower for unconfirmed sources. The dashed boundary between “moderate” and “high” severity in the table reflects the platform’s standard 60-point cutoff used in the Patient Protect breach dashboard.
Reporting lag — the gap between breach discovery and regulator notification — varies widely. HIPAA requires notification within 60 days, but many filings arrive later. The tracker shows the regulator-reported date, not the discovery date; lag analysis lives in the full breach dashboard.
Source links
HHS OCR Breach Portal → · FTC Health Breach Notification Rule → · CISA healthcare advisories → · Patient Protect breach dashboard →