Events Calendar

Mon
Tue
Wed
Thu
Fri
Sat
Sun
M
T
W
T
F
S
S
29
1
3
4
5
7
8
10
11
12
15
16
17
18
19
21
24
25
26
27
30
31
1
2
A Behavioral Health Collision At The EHR Intersection
2014-09-30    
2:00 pm - 3:30 pm
Date/Time Date(s) - 09/30/2014 2:00 pm Hear Why Many Organizations Are Changing EHRs In Order To Remain Competitive In The New Value-Based Health Care Environment [...]
Meaningful Use and The Rise of the Portals
2014-10-02    
12:00 pm - 12:45 pm
Meaningful Use and The Rise of the Portals: Best Practices in Patient Engagement Thu, Oct 2, 2014 10:30 PM - 11:15 PM IST Join Meaningful [...]
Adva Med 2014 The MedTech Conference
2014-10-06    
All Day
Adva Med 2014 The MedTech Conference October 6-8, 2014 McCormick Place Chicago, IL For more information, visit, advamed2014.com For Registration details, click here  
Public Health Measures Meaningful Use
2014-10-09    
12:00 pm - 12:45 pm
Public Health Measures Meaningful Use: Reporting on Public Health Measures Join Meaningful Use expert Jim Tate for a three part series of webinars addressing MU [...]
2014 Hospital & Healthcare I.T. Conference
2014-10-13    
All Day
Join us at our 2014 Hospital & Healthcare I.T. Conference and experience the following: Up to 125 Hospital & Healthcare I.T. executives from America’s most prestigious [...]
Connected Health Care 2014
Key Trends That will be Discussed at the Conference! Connected Healthcare 2014 is set to explore the crucial topics that are revolutionizing the connected health industry: [...]
HealthTech Conference
2014-10-14    
All Day
HealthTech Capital is a group of private investors dedicated to funding and mentoring new "HealthTech" start ups at the intersection of healthcare with the computer [...]
Health Informatics & Technology Conference (HITC-2014)
2014-10-20    
All Day
Information technology has ability to improve the quality, productivity and safety of health care mangement. However, relatively very few health care providers have adopted IT. [...]
HIMSS Amsterdam 2014
2014-10-20    
12:00 am
About HIMSS Amsterdam 2014 This year, the second annual HIMSS Amsterdam event will be taking place on 6-7 November 2014 at the Hotel Okura. The [...]
Patient Portal Functionality and EMR Integration Demonstration
2014-10-22    
2:00 pm - 3:30 pm
This purpose of this webcast is to present a demonstration to show how the Patient Portal integrates with EMR, as well as discuss how this [...]
Connected Health Symposium 2014
Symposium 2014 - Connected Health in Practice: Engaging Patients and Providers Outside of Traditional Care Settings Collaborating with industry visionaries, clinical experts, patient advocates and [...]
CHIME College of Healthcare Information Management Executives
2014-10-28 - 2014-10-31    
All Day
The Premier Event for Healthcare CIOs Hotel Accomodations JW Marriott San Antonio Hill Country 23808 Resort Parkway San Antonio, Texas 78761 Telephone: 210-276-2500 Guest Fax: [...]
The Myth of the Paperless EMR
2014-10-29    
2:00 pm - 3:00 pm
Is Paper Eluding Your Current Technologies; The Myth of the Paperless EMR Please join Intellect Resources as we present Is Paper Eluding Your Current Technologies; The Myth [...]
Events on 2014-09-30
Events on 2014-10-02
Events on 2014-10-06
Events on 2014-10-09
Events on 2014-10-13
Events on 2014-10-14
Connected Health Care 2014
14 Oct 14
San Diego
HealthTech Conference
14 Oct 14
San Mateo
Events on 2014-10-20
HIMSS Amsterdam 2014
20 Oct 14
Amsterdam
Events on 2014-10-23
Events on 2014-10-28
Events on 2014-10-29
Articles Latest News

Statistics on Data Breaches in the Healthcare Sector

EMR Industry

Trends in Healthcare Data Breach Statistics

Our analysis of healthcare data breach statistics reveals a consistent upward trend over the past 14 years. Notably, 2021 recorded the highest number of reported breaches since the Office for Civil Rights (OCR) began publishing such data.

The trend continued in 2022, with 720 breaches involving 500 or more records reported to the OCR. The situation worsened in 2023, which set two new records: the highest number of reported breaches and the largest number of affected records in a single year. That year, 725 data breaches were reported, resulting in the exposure or unauthorized disclosure of over 133 million patient records.

The healthcare data breach statistics presented below include only incidents involving 500 or more records, as reported to the Office for Civil Rights (OCR). Although HIPAA mandates the reporting of all data breaches regardless of size, OCR does not publicly disclose details of smaller breaches. The data reflected in the following statistics and graphs encompasses both closed cases and ongoing investigations into potential HIPAA violations.

Between October 21, 2009—when the Office for Civil Rights (OCR) began publishing summaries of healthcare data breaches on its “Wall of Shame”—and December 31, 2023, a total of 5,887 large-scale breaches (involving 500 or more records) were reported. As of January 22, 2023, 857 of these breaches remained under investigation. For comparison, one year earlier, that number stood at 882, indicating minimal progress in reducing the investigative backlog—an issue largely attributed to OCR’s persistent underfunding.

Over the years, the primary causes of data breaches have shifted significantly. From 2009 to 2015, most incidents stemmed from the loss or theft of physical healthcare records and electronic protected health information (ePHI). However, the transition to digital recordkeeping, improved device tracking, and wider adoption of encryption technologies have helped reduce such cases. Similarly, incidents involving improper disposal and unauthorized access or disclosure have shown a downward trend.

Despite these improvements, data breaches have continued to rise due to a sharp increase in hacking and ransomware attacks. According to OCR, between January 1, 2018, and September 30, 2023, hacking-related breaches surged by 239%, and ransomware incidents rose by 278%. In 2019, hacking accounted for 49% of all reported breaches; by 2023, that figure had climbed to 79.7%.

Not only are breaches becoming more frequent—they’re also growing in severity. In 2021, 45.9 million healthcare records were compromised. That number rose to 51.9 million in 2022. But 2023 shattered all previous records, with a staggering 168 million records exposed, stolen, or improperly disclosed. This total included 26 breaches involving over 1 million records and four breaches exceeding 8 million records each. The largest single breach affected 11.27 million individuals, making it the second-largest healthcare breach ever recorded.

Preliminary data suggests a slight decrease in the number of breaches in 2024, though it is too early to draw definitive conclusions, as OCR has yet to finalize all breach reports for the year. While the number of incidents may have declined, the number of compromised records has surged once again—reaching over 276 million. This includes the largest healthcare data breach to date: the ransomware attack on Change Healthcare, which impacted an estimated 190 million individuals.

OCR updates its breach data at least once a month, typically adding the previous month’s figures around the 21st. Be sure to check regularly for the latest trends and updates for the current year.

Healthcare Data Breaches by Year

From 2009 through 2024, a total of 6,759 healthcare data breaches involving 500 or more records were reported to the Office for Civil Rights (OCR). These incidents have resulted in the exposure or unauthorized disclosure of protected health information (PHI) affecting 846,962,011 individuals—more than 2.6 times the population of the United States.

In 2018, healthcare data breaches of this scale were reported at an average rate of about one per day. By 2023, that rate had more than doubled, with an average of 1.99 breaches reported daily. Each day, an average of 364,571 healthcare records were compromised.

While the number of breaches reported in 2024 remained relatively consistent with the previous year, the impact grew significantly. In 2024 alone, the PHI of 276,775,457 individuals was exposed or stolen—averaging an astonishing 758,288 compromised records per day.