Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
healthcare-sector-threatbreach-disclosure-notificationinsider-threat-incidentmass-credential-exposure

US Healthcare Privacy Lapses and Breach Reporting Trends

Updated 2mo agoFirst seen Feb 2, 20263 sources

US healthcare organizations reported unusually low numbers of large HIPAA breaches in late 2025, with 41 incidents affecting 500+ individuals logged for December 2025 in the HHS OCR breach portal. Reporting volumes for September–December averaged ~40.75 large breaches per month versus ~66.5 in the prior four months, and 2025 totals stood at 697 breaches (a reported ~6% decrease from 2024), though the count was expected to rise as additional incidents are added. A key factor cited for the apparent decline was a 43-day US government shutdown that furloughed most HHS staff and likely created a backlog in posting breach reports to the OCR portal, potentially suppressing late-2025 totals until processing is completed.

Separately, a VA Office of Inspector General review found a privacy and security compliance failure within the Veterans Health Administration’s national cancer testing program tied to a collaborative research effort. The OIG reported that in 2022 a VHA research director created and shared a file containing electronic health record reports and a “significant amount” of protected health information (PHI) with non-VHA investigators without institutional review board approval or de-identification, and that required audit logs for secure ePHI management were missing. The OIG noted delays in reporting and inadequate early mitigation, and issued six recommendations that the VA agreed to implement, including removing PHI from shared materials, clarifying research processes, and improving training.

Share:
US Healthcare Privacy Lapses and Breach Reporting Trends
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

8 events from the most recent confirmed update back to the earliest known activity.

8 EVENTS
Feb 1, 20265mo ago

February 2026 healthcare breaches reported to HHS OCR totaled 63 incidents

In February 2026, HIPAA-regulated entities reported 63 healthcare data breaches affecting 500 or more individuals to the HHS Office for Civil Rights breach portal, exposing or impermissibly disclosing at least 8,134,378 individuals' protected health information. The month's totals were driven by major hacking incidents at TriZetto Provider Solutions and QualDerm Partners, plus a large ApolloMD Business Services ransomware attack attributed to Qilin.

February 2026 Healthcare Data Breach Report
Jan 30, 20265mo ago

VA later adopted a mitigation plan and accepted OIG recommendations

At a later stage, the VA's mitigation plan was updated to remove PHI, clarify research processes, and improve staff training. The VA also agreed to implement six recommendations from the Office of Inspector General.

Dec 1, 20257mo ago

OCR announced HIPAA settlement with Concentra over access violation

In December 2025, the HHS Office for Civil Rights announced a HIPAA enforcement settlement with Concentra, Inc. over an alleged Right of Access violation. The settlement was highlighted alongside monthly healthcare breach reporting.

Fieldtex Products and AllerVie Health were among largest December breaches

Among the largest healthcare breaches reported for December 2025 were a hacking incident at Fieldtex Products in New York and a ransomware attack on AllerVie Health in Texas. The AllerVie attack was claimed by the Anubis ransomware group.

December 2025 healthcare breaches reported to HHS OCR totaled 41 incidents

In December 2025, HIPAA-regulated entities reported 41 healthcare data breaches affecting 500 or more individuals to the HHS Office for Civil Rights breach portal. The listed incidents affected 345,564 people, the lowest monthly total since December 2017.

Jan 1, 20251y ago

New York AG reported 2025 settlement with OrthoNY over cybersecurity issues

During 2025, the New York Attorney General reported a settlement with Orthopedics NY LLP (OrthoNY) tied to alleged cybersecurity failures. The action was noted in the context of broader healthcare privacy and security enforcement developments.

Jan 1, 20224y ago

VA testing project incident reporting and privacy response were delayed

After the 2022 data-sharing incident, investigators found delays in reporting the issue, failures to consult required experts, and initial mitigation steps that did not address privacy risks. Missing audit logs also meant secure management of electronic PHI could not be fully tracked.

VHA research director shared PHI with outside investigators without approvals

In 2022, a Veterans Health Administration research director created and shared a file containing electronic health record reports and significant protected health information with non-VHA investigators. The sharing occurred without institutional review board approval or de-identification, contrary to HIPAA privacy and security requirements.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

45 LINKEDOpen in app
Threat actors
4 linked
Malware
1 linked
Organizations
40 linked
TriZetto Provider SolutionsDoctor AllianceOCHINAccentCareVikor ScientificCarolina Foot & Ankle AssociatesMarin Cancer CareQualDerm PartnersIssaqueena Pediatric DentistryWIRX PharmacyAltaMed Health Services CorporationEyeCare PartnersEmanuel Medical CenterLakeside Pediatric & Adolescent MedicineManhattan Retirement FoundationAcademic Urology & Urogynecology of ArizonaCedar Valley ServicesAlexes Hazen MDTriad Radiology AssociatesAdvanced Homecare ManagementOscar HealthCedar Point HealthResource Corporation of AmericaJackson Hospital and ClinicIPPC Inc.Counseling Center of Wayne & Holmes CountiesCouve Healthcare ConsultingApolloMD Business ServicesFedScoopFieldtex ProductsConcentra Inc.Glendale Obstetrics & Gynecology PCAMedical Center LLPAssociated Radiologists of the Finger Lakes, P.C.AllerVie HealthGreater St. Louis Oral & Maxillofacial Surgery PCReproductive Medicine Associates of MichiganVariety CareMadison Healthcare ServicesOrthopedicsNY
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.