

2015 was particularly bad due to three massive data breaches at health plans: Anthem Inc, Premera Blue Cross, and Excellus. 2015 was the worst year in history for breached healthcare records with more than 112 million records exposed or impermissibly disclosed. There has been a general upward trend in the number of records exposed each year, with a massive increase in 2015.

In 2022, an average of 1.94 healthcare data breaches of 500 or more records were reported each day. Fast forward 5 years and the rate has more than doubled. In 2018, healthcare data breaches of 500 or more records were being reported at a rate of around 1 per day.

That equates to more than 1.2x the population of the United States. Those breaches have resulted in the exposure or impermissible disclosure of 382,262,109 healthcare records. One trend that has continued in 2022 is an increase in the number of cyberattacks and data breaches at business associates, which suffered more data breaches in 2022 than any other type of HIPAA-regulated entity.īetween 20, 5,150 healthcare data breaches of 500 or more records have been reported to the HHS’ Office for Civil Rights. Hacking incidents increased significantly since 2015, as has the scale of data breaches, as shown in the charts below showing average and median data breach sizes.

Our healthcare data breach statistics show the main causes of healthcare data breaches are now hacking/IT incidents, with unauthorized access/disclosure incidents also commonplace. The move to digital record keeping, more accurate tracking of electronic devices, and more widespread adoption of data encryption have been key in reducing these data breaches. The loss/theft of healthcare records and electronic protected health information dominated the breach reports between 20. There have been notable changes over the years in the main causes of breaches. Bookmark this page and check back regularly to get the latest healthcare data breach statistics and healthcare data breach trends. There was a slight decrease in reported data breaches in 2022 – only the second time that there has been a year-over-year decrease in reported healthcare data breaches, although it is naturally too early to tell if this is a blip or the start of a trend that will see healthcare data breaches decline. Our healthcare data breach statistics clearly show there has been an upward trend in data breaches over the past 14 years, with 2021 seeing more data breaches reported than any other year since records first started being published by OCR. The data on which these healthcare data breach statistics have been calculated were obtained from the HHS’ Office for Civil Rights on March 20, 2023. The report will be updated monthly in 2023 to include the latest figures on data breaches and HIPAA enforcement actions. 5,150 data breaches were reported to OCR between October 21, 2009, and December 31, 2022, 882 of which were showing as still under investigation at the end of 2022. The breaches include closed cases and breaches that are still being investigated by OCR for potential HIPAA violations. Department of Health and Human Services’ Office for Civil Rights (OCR), as details of smaller breaches are not made public by OCR. The HIPAA Journal has compiled healthcare data breach statistics from October 2009, when the Department of Health and Human Services’ Office for Civil Rights first started publishing summaries of healthcare data breaches on its website. The healthcare data breach statistics below only include data breaches of 500 or more records that have been reported to the U.S.
