Industries
13
min read

Healthcare Records and HIPAA Breach Statistics 2026: 40 Verified Numbers

40 sourced numbers on healthcare data breaches: how many happened in 2025, where PHI actually gets compromised (paper vs servers vs email), what OCR fined and why, what a breach costs, and California's 7-year retention rule. Compiled from the HHS OCR breach portal, IBM, and the California code.
Paper medical charts in a California practice before scanning
Written by
John
Published on
September 13, 2026

Healthcare Records and HIPAA Breach Statistics 2026: 40 verified numbers on healthcare data breaches, where protected health information gets compromised, what OCR is enforcing, what a breach costs, and how long California providers must keep records. Every figure is traced to the HHS Office for Civil Rights breach portal, IBM, the California code, or the analyst that published it, dated, and linked. Last updated September 2026.

We scan medical records for California practices, so we get asked the same question in every intake meeting: is paper safer than digital? The honest answer is in the data below. Paper is now a small share of breaches, but it is the one category that still comes down to a lost box, a dumpster, or a filing cabinet in a flooded basement. Digital records get breached by hackers. Paper records get breached by carelessness. Both are HIPAA violations.

This page is built the way we wish every statistics page were built: primary sources only, each number attributed and dated. We refresh it when OCR data updates.

Key Takeaways

  • 710 large healthcare data breaches (500+ individuals) were reported to HHS in 2025, down 4.3% from 742 in 2024 (HHS OCR data via HIPAA Journal).
  • At least 61,556,256 individuals had PHI exposed in 2025, a 78.7% drop from the 2024 record of 289,162,330 (HIPAA Journal).
  • Two large healthcare breaches are reported every day, twice the 2018 rate (HIPAA Journal).
  • Paper and film were the location of PHI in 5.6% of 2025 breaches; network servers were 61.5% and email 24.9% (HIPAA Journal).
  • Only one improper-disposal breach was reported in 2025, but it affected more than 35,000 people (HIPAA Journal).
  • California had the most large healthcare breaches of any state in 2025: 69 (HIPAA Journal).
  • The average healthcare breach costs $7.42 million in the U.S., the highest of any industry for the 14th straight year (IBM, 2025).
  • Healthcare breaches take 279 days to identify and contain, more than five weeks longer than the global average (IBM, 2025).
  • OCR closed 21 enforcement actions in 2025, its second-highest total ever, collecting $8,330,066 in penalties (HIPAA Journal).
  • 76% of 2025 OCR penalties included a risk-analysis failure (HIPAA Journal).
  • California providers must keep adult medical records at least 7 years after discharge (California Health and Safety Code 123145).
  • HIPAA requires compliance documentation to be kept 6 years (45 CFR 164.316 and 164.530).

How many healthcare data breaches happened in 2025?

  • 710 healthcare data breaches affecting 500 or more individuals were reported to the HHS Office for Civil Rights in 2025, down 4.3% from 2024. The annual total has plateaued in the 700 to 750 range since the large increases of 2018 to 2021. Source: HIPAA Journal, 2025 Healthcare Data Breach Report, February 2026, compiled from the OCR breach portal.
  • The 2024 total was first reported as 725 and later rose to 742 as late filings were added. A 43-day federal shutdown in late 2025 paused portal updates, so the 2025 count is likely to rise. Source: HIPAA Journal, February 2026.
  • At least 61,556,256 individuals had PHI exposed or impermissibly disclosed in 2025, a 78.7% decrease from 2024, when 289,162,330 individuals were affected, including 192,700,000 from the Change Healthcare ransomware attack. Source: HIPAA Journal, February 2026.
  • There were 9 mega breaches (1 million+ individuals) in 2025, down from 18 in 2024. Source: HIPAA Journal.
  • The average 2025 breach affected 86,699 individuals (median 4,011), down from an average of 389,707 (median 6,702) in 2024. Source: HIPAA Journal.
  • The largest 2025 breach was Aflac, with 13,924,906 U.S. individuals affected. Three of the top 20 were in California: Episource (5,418,866), Blue Shield of California (4,700,000, via website tracking tools), and Serviceaide (483,126, an unsecured database). Source: HIPAA Journal.
  • Breach size distribution in 2025: 1 breach over 10 million, 8 between 1 and 10 million, 6 between 500,000 and 1 million, 64 between 100,000 and 500,000, 176 between 10,000 and 100,000, 309 between 1,000 and 10,000, and 146 between 500 and 999. Source: HIPAA Journal.
  • More than 935 million individuals have had PHI exposed since OCR began publishing breaches in October 2009, roughly 2.6 times the U.S. population, per an analysis of the OCR portal. The cumulative total was under 500 million through 2022 and nearly doubled in two years. Source: OCR breach portal data as compiled by FaxSIPit, May 2026.

Where does protected health information actually get breached?

This is the section that matters for anyone deciding whether to keep records on paper or convert them.

  • 61.5% of 2025 breaches involved PHI on network servers, 24.9% involved compromised email accounts, 5.6% involved physical PHI (paper and film), and 4.6% involved electronic medical record systems. Source: HIPAA Journal, February 2026.
  • Hacking and IT incidents affected an average of 105,623 individuals per breach (median 5,434), versus 9,909 (median 1,662) for unauthorized access or disclosure and 4,402 (median 1,690) for loss and theft. Source: HIPAA Journal.
  • Unauthorized access and disclosure incidents rose 17.4% in 2025, while hacking, loss/theft, and improper disposal each fell slightly. These include insider data theft and inadvertent exposure by employees. Source: HIPAA Journal.
  • Only one improper-disposal breach was reported by a HIPAA-regulated entity in 2025, affecting more than 35,000 individuals. Improper disposal typically involves paper records that were not shredded or were abandoned. Source: HIPAA Journal.
  • Loss and theft incidents, once a leading cause of healthcare breaches, are now rare, which HIPAA Journal attributes to cloud storage and cheaper encryption. Source: HIPAA Journal.
  • Hacking and other IT incidents accounted for more than 80% of large healthcare breaches in 2025. Source: OCR data as analyzed by Packet33, July 2026.
  • Ransomware attacks hit a record 1,174 confirmed incidents across all industries in 2025, and healthcare was the worst-affected sector at 22% of attacks. 96% of ransomware attacks involve data theft, and only 20% of victims paid in Q4 2025, so roughly 77% of attacks end with data leaked. Source: Black Fog and Coveware, as cited by HIPAA Journal.

Who gets breached, and where?

  • By reporting entity, the OCR portal lists 523 breaches at healthcare providers, 56 at health plans, 2 at clearinghouses, and 128 at business associates for 2025. By the entity where the breach actually occurred, 57.5% happened at providers, 35.8% at business associates, 6.5% at health plans, and 0.3% at clearinghouses. Source: HIPAA Journal.
  • California had the most large healthcare breaches of any state in 2025 with 69, followed by Florida and Texas (47 each), New York (44), and Ohio (37). Source: HIPAA Journal.
  • California was second in individuals affected, at 11,849,467, behind Georgia (16,050,351, driven by Aflac). Source: HIPAA Journal.
  • Breaches were reported in 49 states, D.C., and Puerto Rico in 2025. Vermont was the only state with none. Source: HIPAA Journal.

What does a healthcare data breach cost?

  • The average cost of a healthcare data breach in the U.S. was $7.42 million in 2025, down $2.35 million from $9.77 million in 2024, but still the highest of any industry for the 14th consecutive year. Source: IBM Cost of a Data Breach Report 2025, as reported by HIPAA Journal, July 2025.
  • Healthcare breaches took 279 days on average to identify and contain, more than five weeks longer than the global average of 241 days. Source: IBM Cost of a Data Breach Report 2025 (full report PDF).
  • The average U.S. breach across all industries hit a record $10.22 million in 2025, up 9%, driven by regulatory fines and detection costs, while the global average fell 9% to $4.44 million. Source: IBM, 2025.
  • Financial services was second at $5.56 million per breach. Source: IBM, 2025.
  • Almost half of breached organizations said they would raise prices as a result, and about one-third planned increases of 15% or more. Source: IBM via HIPAA Journal, 2025.
  • Healthcare accounted for only 2% of the 600 organizations IBM studied, a caveat worth keeping in mind when quoting the $7.42 million figure. Source: TechTarget, July 2025.

What is OCR enforcing?

  • OCR resolved 21 investigations with settlements or civil monetary penalties in 2025, the second-highest total on record, collecting $8,330,066. Penalties were lower than prior years because most cases targeted a single provision. Source: HIPAA Journal, February 2026.
  • 16 of the 21 enforcement actions (76%) included a risk-analysis failure. Breach notification failures were second (5), followed by impermissible disclosure (4), activity monitoring (3), right of access (3), and risk management (3). Source: HIPAA Journal.
  • The largest 2025 penalties were Solara Medical Supplies ($3,000,000), Warby Parker ($1,500,000), BayCare Health System ($800,000), and PIH Health ($600,000). The smallest was Vision Upright MRI at $5,000. Source: HIPAA Journal.
  • Three 2025 enforcement actions were for Right of Access failures, including Oregon Health & Science University ($200,000) and Concentra ($112,500). OCR has confirmed Right of Access and risk analysis remain 2026 priorities, with risk management added. Source: HIPAA Journal.
  • The HIPAA Breach Notification Rule requires notice to OCR, individuals, and the media within 60 days of discovery. More than one-fifth of 2025 enforcement actions included a notification failure. Source: HIPAA Journal.
  • In most cases, documentation requested under HIPAA (including a patient's access request) must be produced within 30 days. Failure to respond in time is the most common reason for complaints to OCR. Source: HIPAA Journal.

How long must medical records be kept in California?

HIPAA does not set a retention period for medical records themselves; it defers to state law. California's rules are longer than most.

  • Licensed California providers must preserve patient records for a minimum of 7 years following discharge. Source: California Health and Safety Code section 123145.
  • Records of minors must be kept until at least one year after the patient turns 18, and never less than 7 years. Source: Recording Law, California Medical Records Retention Laws, verified March 2026.
  • Providers that cease operations must still preserve records for the full 7-year period. Source: Health and Safety Code 123145, via Recording Law.
  • Medi-Cal providers must keep records 10 years. Source: Slothwise, California retention summary, April 2026.
  • California licensed facilities must retain exposed X-ray film for 7 years. Source: 22 CCR sections 72543 and 73543, via Slothwise.
  • HIPAA requires privacy and security compliance documentation (policies, training records, business associate agreements, risk analyses) to be kept 6 years from creation or last effective date. Source: 45 CFR 164.530(j) and 164.316(b)(2)(i), via Gamma Compliance.
  • Medicare hospitals must retain medical records at least 5 years (42 CFR 482.24), and OSHA employee exposure records must be kept 30 years (29 CFR 1910.1020). Where California's rule is longer, California controls. Source: Tavrn, Medical Record Retention Laws by State, 2026.

What this means for a California practice sitting on paper charts

The breach data says paper is a small share of incidents, and that is true. But the 5.6% of breaches that involve paper are the ones that never had to happen. There is no patch for a chart left in a hallway.

The bigger issue is the 30-day clock. Right of Access is an OCR enforcement priority for 2026, and a request for a seven-year-old chart in an offsite storage box is where practices miss the deadline. A scanned, indexed archive answers that request in minutes.

The third point is that digitizing does not remove risk, it moves it. 61.5% of breaches are on network servers. When you convert records, the scanning vendor needs to sign a Business Associate Agreement, keep chain of custody, and hand the files to a system that is secured. We covered how that works in our HIPAA-compliant medical records scanning guide and the operational benefits of digitizing medical records. For the broader picture on paper decline and digitization, see our document scanning and digitization statistics page.

How to cite this page

Turn Source Imaging, "Healthcare Records and HIPAA Breach Statistics 2026," turnsourceimaging.com, updated September 2026. Please cite the original publisher alongside this page. If a figure has been revised at its source, email us and we will update it.

Sources

Converting paper charts in Los Angeles, Orange County, San Diego, or the Inland Empire? Get a quote from Turn Source Imaging. We sign a BAA, document chain of custody, and scan a free sample batch first.

Get In Touch!
No spam. Just the latest releases and tips, interesting articles, in your inbox every week.
Read about our privacy policy.
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.