301,768,951 Individuals affected across 735 HHS OCR breach filings

This figure is the sum of individuals_affected reported in 735 HIPAA filings from the HHS Office for Civil Rights in our current dataset snapshot.

What this number is, and what it is not

That distinction matters. The number is still severe, but precision about methodology is essential when discussing public-health-scale breaches.

Change Healthcare dominates the totals

The single largest filing is Change Healthcare at 192.7 million affected individuals. Even after excluding that incident, the remainder still represents more than 109 million affected individuals across hundreds of separate filings.

This is not one isolated failure mode. It is repeated, cross-organisation exposure at national scale.

The top 10 breaches account for 82% of all exposed records

OrganisationRecords Exposed
Change Healthcare, Inc.192,700,000
Aflac Incorporated13,924,906
Kaiser Foundation Health Plan13,400,000
Episource, LLC6,725,572
Ascension Health5,466,931
Blue Shield of California4,700,000
HealthEquity, Inc.4,300,000
TriZetto Provider Solutions3,433,965
Acadian Ambulance Service2,896,985
Sav-Rx2,812,336

Hacking is the dominant cause, but insider access remains material

Of the 735 reported breaches:

One in seven incidents involving unauthorised access is significant, especially for organisations that focus only on perimeter defence.

California, Texas, and Florida lead breach volume

The geographic distribution follows population centres, but the per-capita rates tell a different story:

What this means beyond sales narratives

Several themes from public discussion are worth taking seriously:

Practical actions for healthcare organisations in the next 90 days

  1. Prioritise identity and helpdesk hardening for high-privilege workflows.
  2. Enforce vendor access segmentation and faster third-party credential rotation.
  3. Apply data minimisation to retention-heavy systems where legal requirements allow.
  4. Run scenario exercises for high-impact disclosure events and regulatory response.

Method note

Data source: HHS OCR breach portal filings included in CipherCue ingestion for records affecting 500 or more individuals. Totals shown here are filing totals and should be interpreted as reported exposure, not deduplicated persons.

We built this analysis to improve incident visibility and response timing. If your team wants the underlying filing stream in real time, request a demo.