Hospital corridor with medical equipment and fluorescent lighting
Photo via Unsplash

TL;DR: An analysis of HHS Office for Civil Rights breach filings puts the total at 301,768,951 affected individuals across 735 separate healthcare data breaches. Change Healthcare accounts for 192.7 million of those, but strip that out and you've still got 109 million people whose medical records were exposed in the remaining 734 incidents. In 2024 alone, an average of 792,226 people had their healthcare data breached every single day. Six new healthcare breaches were announced just this past week. The sector isn't getting safer. It's getting worse.

301 Million Is Not a Typo

Let's put that number in context. The U.S. population is about 335 million. That means breach filings on record with HHS cover roughly 90% of the country [1].

Now, one person can show up in multiple breaches. This is an aggregate exposure count, not unique individuals. But that's exactly the problem. If you've interacted with the U.S. healthcare system in the last decade, the odds that your medical data has been stolen aren't slim. They're near-certain.

Since October 2009, when HHS started requiring large breach reporting, 7,419 breaches involving 500 or more records have been filed. As of January 31, 2026, 978 of those are still under investigation or awaiting investigation [2]. Almost a thousand open cases. That's not a backlog. That's a system that can't keep up.

The Breaches That Broke the Scale

A handful of mega-breaches did most of the damage. Here are the biggest:

Change Healthcare: 192.7 Million

The single largest healthcare data breach in U.S. history. On February 21, 2024, ransomware group ALPHV/BlackCat hit Change Healthcare, a UnitedHealth Group subsidiary that processes roughly one in three patient records in America [3].

The entry point? A Citrix remote access portal with no multi-factor authentication. Attackers exfiltrated up to 6 terabytes of data: personal information, payment details, insurance records, medical histories. UnitedHealth paid a $22 million ransom. The initial estimate was 100 million affected. It climbed to 190 million. The final number filed with OCR: 192.7 million [3].

That's nearly double the previous record: the 2015 Anthem breach at 78.8 million.

Conduent: 25+ Million

Most people have never heard of Conduent. It's a government technology contractor that processes Medicaid, child support payments, and benefits data for dozens of states. The SafePay ransomware group spent three months inside Conduent's network, exfiltrating roughly 8 terabytes of data before anyone noticed [4].

Texas alone revised its number from 4 million to 15.4 million residents affected. Oregon held at 10.5 million. The Texas Attorney General called it one of the largest data breaches in U.S. history [4].

Here's what makes Conduent infuriating: the breach was discovered January 13, 2025. Notifications didn't begin until October 24, 2025, nine months later. HIPAA requires notification within 60 days [4]. The credit monitoring signup deadline is April 30, 2026. If you're one of the 25 million, you've got three weeks.

Navia Benefit Solutions: 2.7 Million

Navia manages healthcare flexible spending accounts and COBRA benefits. Attackers had access to their systems from December 22, 2025 to January 15, 2026: 24 days of roaming through a company that stores Social Security numbers, dates of birth, and health plan information for nearly 2.7 million people [5].

No ransomware group claimed credit. Navia didn't disclose how the attackers got in. Notification letters started going out March 18, 2026. Class action lawsuits are already filed.

CareCloud: Unknown (Millions at Risk)

On March 16, 2026, hackers accessed one of six environments where CareCloud stores electronic health records. CareCloud provides EHR storage for more than 45,000 healthcare providers covering millions of patients. The attackers had eight hours of access. CareCloud filed an SEC 8-K on March 24, acknowledging material impact, but still hasn't said how many patients were affected or what data was taken [6].

EHR breaches are worse than typical data theft. These records contain everything: your diagnoses, prescriptions, SSN, insurance details, physician notes. The kind of data that can't be changed and never expires.

OpenLoop Health: 1.6 Million (Claimed)

A telehealth platform serving 20,000+ clinicians across all 50 states. On January 7, 2026, a threat actor calling themselves "stuckin2019" claimed 1.6 million patient records. OpenLoop reported 68,160 affected in Texas state filings alone. The full scope is still being investigated [7]. Multiple class action lawsuits allege inadequate security measures and HIPAA safeguard failures.

The Numbers Are Getting Worse, Not Better

The year-over-year data tells a brutal story [2]:

  • 2024: 276.7 million records breached across 734 reported incidents: the worst year ever. An average of 792,226 people affected per day.
  • 2024 mega-breaches: 14 incidents involving more than 1 million records each, totaling 238 million records: roughly 70% of the entire U.S. population.
  • 2025: 642+ breaches affecting approximately 57 million individuals. Lower than 2024 only because there was no single breach on the scale of Change Healthcare. The number of reported incidents actually set a new record.
  • 2026 so far: New breaches announced weekly. CareCloud, OpenLoop Health, Navia, Intellihartx (500,000+ patients), and more, all in the first quarter alone.

Strip out the Change Healthcare anomaly and the trend line goes one direction: up. More breaches, more records, more often.

Why Hackers Love Hospitals

Healthcare data is the highest-value target on the black market. A stolen credit card number sells for $1-2. A stolen medical record sells for $250-$1,000 [2]. Here's why:

  • Medical records can't be canceled. You can freeze a credit card. You can't freeze your diagnosis history, prescription list, or SSN.
  • They enable multiple fraud types. Identity theft, insurance fraud, prescription fraud, tax fraud, blackmail. One record, dozens of attack vectors.
  • Healthcare systems run ancient software. Hospitals still operate on legacy systems that would make a 2010 IT admin wince. Many EHR platforms were designed for convenience, not security.
  • Downtime kills people. Ransomware gangs know hospitals can't afford to go offline. A locked EHR system means doctors can't see patient allergies, medication lists, or surgical histories. Hospitals pay ransoms because the alternative is dead patients.
  • The supply chain is massive. Your data doesn't just live at your doctor's office. It flows through billing companies (Change Healthcare), benefits administrators (Navia), government contractors (Conduent), telehealth platforms (OpenLoop), EHR providers (CareCloud), and dozens of other vendors you've never heard of. Each one is an attack surface.

The Supply Chain Problem

The biggest trend in healthcare breaches isn't direct hospital hacking. It's the vendor chain.

Change Healthcare processes claims for one-third of American patients. Conduent handles government benefits across dozens of states. CareCloud stores EHRs for 45,000+ providers. Navia manages spending accounts for thousands of employers. None of these companies treat patients. They all store patient data.

When one of them gets breached, the blast radius is enormous. You didn't choose to give your data to Conduent. Your state Medicaid office did. You probably didn't know CareCloud exists. Your doctor's billing department does.

In 2026, the HHS Office for Civil Rights highlighted that business associate data breaches have been increasing for years [2]. The trend is clear: hackers are targeting the vendors because one breach at a vendor yields millions of records across hundreds of healthcare providers.

The Enforcement Gap

HHS OCR is supposed to enforce HIPAA. In practice, enforcement is rare and penalties are small relative to the scale of negligence.

Conduent breached HIPAA's 60-day notification requirement by seven months. The consequence so far: a Texas AG investigation and some class action lawsuits. Not a single federal enforcement action. Change Healthcare paid a $22 million ransom because it was cheaper than the operational downtime. The fine for a HIPAA violation? Typically $100 to $50,000 per violation, capped at $1.5 million per year per violation category [8].

When breaching 192.7 million records costs less than the ransom payment, something is broken.

What You Can Do Right Now

  • Check if you're affected. The HHS breach portal at ocrportal.hhs.gov lists every reported breach. Search by the names of your insurance companies, hospitals, and doctors. Also check HaveIBeenPwned.com for your email.
  • Freeze your credit. If your SSN was in any healthcare breach (and it probably was), freeze your credit at all three bureaus: Equifax, Experian, TransUnion. It's free and takes 10 minutes.
  • Sign up for credit monitoring if offered. Conduent victims have until April 30, 2026. Navia and OpenLoop are also offering monitoring. Don't let these deadlines pass.
  • Watch for medical identity fraud. Review your Explanation of Benefits (EOBs) from your insurance company. If you see treatments you didn't receive or providers you didn't visit, someone is using your medical identity.
  • Request your medical records. Under HIPAA, you have a right to request your records from any covered entity. Ask your providers and insurance company for an accounting of disclosures: a log of who accessed your records and when.
  • Use unique emails for healthcare portals. Create a separate email address for medical accounts. If it shows up in a breach notification, you'll know exactly where it leaked.

The Uncomfortable Math

301 million affected people across 735 breaches. 978 investigations still open. The worst year on record was 2024 and 2026 isn't looking any better.

Healthcare organizations spent $10.93 million per breach on average in 2023, the highest cost of any industry for the 13th consecutive year [2]. And they keep getting hit because the sector chronically underinvests in cybersecurity, relies on decades-old systems, and treats patient data protection as a compliance checkbox rather than a core function.

Your medical records contain the most sensitive information about you. Your diagnoses. Your prescriptions. Your mental health history. Your reproductive health data. Your genetic testing results. All of it is being stolen at industrial scale, and the penalties for letting it happen are rounding errors on quarterly earnings reports.

The system that's supposed to protect your health data is broken. Until that changes, the only person protecting your medical information is you.

Sources

  1. CipherCue - 301 Million People in HIPAA Breach Filings: What the Data Actually Shows (2026)
  2. HIPAA Journal - Healthcare Data Breach Statistics (Updated for 2026)
  3. The HIPAA Guide - Change Healthcare Data Breach: 192.7 Million Affected
  4. Malwarebytes - The Conduent Breach: From 10 Million to 25 Million (and Counting) (February 2026)
  5. HIPAA Journal - Navia Benefit Solutions Discloses Data Breach Affecting 2.7 Million Individuals (March 2026)
  6. TechCrunch - Health Data Giant CareCloud Says Hackers Accessed Patients' Medical Records (March 31, 2026)
  7. HIPAA Journal - Telehealth Platform Provider OpenLoop Health Discloses Data Breach (2026)
  8. HIPAA Journal - HIPAA Violation Cases (Updated 2026)