Excerpt from HIPAA Journal, Published on September 4, 2026
Healthcare data breaches continue at high levels in 2026, with HIPAA Journal reporting that 395 large breaches affecting 500 or more individuals had been reported to the U.S. Department of Health and Human Services Office for Civil Rights (OCR) through June 30.
The figures are based on OCR data and include breaches that remain under investigation or are awaiting investigation. HIPAA Journal noted that 66 large healthcare data breaches were reported in June alone, exposing or potentially exposing the protected health information of at least 4.5 million individuals.
Large breaches continue to be driven primarily by hacking and other IT incidents. HIPAA Journal reported that these categories accounted for more than 80% of large healthcare data breaches, based on the available data.
The scale of individual incidents also remains significant. The updated statistics list 2026 breaches at DentaQuest affecting 15 million individuals, Aesto affecting more than 9.5 million, and Lumexa Imaging affecting more than 5.8 million. The figures can change as investigations identify additional affected records.
The trend highlights the importance of security controls around protected health information, particularly where healthcare organizations rely on business associates and other third parties. Organizations should maintain effective monitoring, access controls, incident response, and vendor oversight as part of their broader security programs.
For additional information, visit HIPAA Journal.




