Healthcare

Healthcare data breaches expose some of the most sensitive personal information that exists: medical records, Social Security numbers, insurance details, diagnosis and treatment history, and sometimes genetic or mental health information. These exposures can lead to medical identity theft, insurance fraud committed in a patient’s name, and the unwanted disclosure of private health conditions that can affect employment, relationships, or insurability. Hospitals, clinics, health insurers, and healthcare technology vendors are among the most frequently targeted organizations for ransomware and data theft, in part because medical records are especially valuable on illicit markets and healthcare providers often operate complex, interconnected IT systems. A single breach at a hospital system, health plan, or medical billing vendor can affect hundreds of thousands of patients at once. This page tracks confirmed data breaches at hospitals, clinics, insurers, and other healthcare organizations, including what data was exposed, which companies notified the HHS Office for Civil Rights and other regulators, and what affected patients can do next to protect their medical and financial identity.