Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
breach-disclosure-notificationenforcement-actionhealthcare-sector-threatmass-credential-exposure

Regulatory Reporting Highlights Rising GDPR Enforcement and U.S. Healthcare Breach Disclosures

Updated 3mo agoFirst seen Jan 22, 20262 sources

European privacy regulators issued roughly €1.2B in GDPR fines in 2025 and received an average of 443 personal data breach notifications per day (a reported 22% increase year over year), according to DLA Piper’s GDPR Fines and Data Breach Survey as cited by DataBreaches.net. The reporting indicates sustained enforcement since GDPR’s introduction, with cumulative penalties reaching €7.1B since 2018, alongside a continued high volume of breach notifications to data protection authorities.

In the U.S. healthcare sector, HIPAA Journal reported that November 2025 showed unusually low counts of large breaches listed on the HHS OCR breach portal (32 incidents affecting 500+ individuals), but attributed the apparent decline to reporting delays during the U.S. government shutdown (Oct 1–Nov 12, 2025) and a resulting backlog. Separately, Central Maine Healthcare disclosed a breach affecting ~145,000 individuals, with unauthorized network access occurring between Mar 19 and Jun 1, 2025 and exposure of data including names and Social Security numbers plus clinical/insurance details; notifications began in late December 2025 and credit monitoring was offered.

Share:
Regulatory Reporting Highlights Rising GDPR Enforcement and U.S. Healthcare Breach Disclosures
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

7 events from the most recent confirmed update back to the earliest known activity.

7 EVENTS
Jan 22, 20265mo ago

European breach notifications rise to 443 per day

DLA Piper reported that from 28 January 2025 to the present, European data protection authorities received an average of 443 personal data breach notifications per day. This was a 22% increase year over year and the first time the daily average exceeded 400 since GDPR began.

Dec 31, 20256mo ago

European GDPR fines exceed €1.2 billion in 2025

A DLA Piper survey found that data protection authorities across Europe issued more than €1.2 billion in GDPR fines during 2025, slightly above 2024 levels. The findings indicated a renewed phase of enforcement activity after a perceived plateau.

Nov 30, 20257mo ago

Fieldtex Products and Delta Dental of Virginia disclose major breaches

Fieldtex Products reported a breach affecting 238,615 individuals, while Delta Dental of Virginia reported 126,953 affected individuals due to an email account compromise. These were the second- and third-largest healthcare breaches reported for November 2025.

VITAS Hospice Services reports largest November healthcare breach

Among November 2025 healthcare incidents, VITAS Hospice Services in Florida disclosed the largest breach, affecting 319,177 individuals through a compromised vendor account. The report identified it as the biggest healthcare breach reported for that month.

November 2025 healthcare breaches affect 1.4 million people

Large U.S. healthcare data breaches reported for November 2025 totaled 32 incidents on the HHS OCR portal, affecting 1,415,934 individuals. Hacking and IT incidents accounted for 78% of breaches and 99.1% of affected individuals, with ransomware and email compromise remaining major drivers.

Oct 1, 20259mo ago

U.S. government shutdown pauses HHS OCR portal updates

A U.S. government shutdown ran from October 1 to November 12, 2025, pausing updates to the HHS OCR breach portal and creating a reporting backlog that affected November healthcare breach statistics. The disruption also contributed to the absence of HIPAA enforcement announcements in November.

May 25, 20188y ago

GDPR takes effect across Europe

The EU General Data Protection Regulation came into force, establishing the breach notification and enforcement framework later measured by DLA Piper. The survey cited cumulative fines since this date reaching €7.1 billion.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

24 LINKEDOpen in app
Threat actors
5 linked
Organizations
19 linked
The RegisterZendeskDLA PiperGuidePoint SecurityDelta Dental of VirginiaVITAS Hospice Services, LLCFieldtex ProductsPersante Health CareNeighborhood Health CenterSteven J. Pearlman MD PCMarshfield Clinic Health SystemPersonic Management Company LLCLoving and Living Center, PCMorton Drug CompanyWest Suburban Eye Surgery Center LLCMillcreek PediatricsNS Support, LLCDavies, McFarland & CarrollHealthcare Therapy Services
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.