7 Major Healthcare Cybersecurity Breaches in the U.S. (2026)

Explore seven major healthcare cybersecurity breaches in the United States, including Change Healthcare, Anthem, HCA Healthcare, Kaiser Permanente, and Ascension. See what these healthcare security breach examples reveal about stolen credentials, weak access controls, third-party risk, poor data visibility, and recovery gaps, and what healthcare organizations can learn from these major healthcare security breaches in 2026.

Healthcare cybersecurity breaches rarely begin with an advanced attack. A stolen credential, missing Multi Factor Authentication (MFA), unpatched vulnerability, exposed data store, or poorly controlled third-party connection can be enough. 

 HHS requires breaches of unsecured protected health information (PHI) affecting 500 or more individuals to be reported through its public breach portal. Data reported through April 30, 2026, listed 252 large healthcare data breaches in the United States. 

The scale of these incidents makes them difficult to ignore. It raises a question, why these healthcare security breaches happen and what they reveal about the security gaps healthcare organizations still struggle to control. 

This article examines seven major healthcare security breaches in the United States, including Change Healthcare, Anthem, HCA Healthcare, Kaiser Permanente, and Ascension. Each case highlights a different weakness in access control, data visibility, third-party risk, containment, or recovery readiness 

What Is a Healthcare Security Breach?

A healthcare security breach occurs when unauthorized individuals access, acquire, disclose, alter, or compromise protected healthcare information or the systems that store or process it. 

These incidents can affect more than electronic health records (EHRs). Patient portals, cloud applications, employee accounts, medical devices, APIs, third-party platforms, and even website tracking tools can create pathways to sensitive data. 

A single healthcare cybersecurity breach can involve compromised credentials, inadequate access controls, a third-party integration, and poor monitoring at the same time. 

The seven U.S. healthcare security breaches below show how these seemingly different weaknesses can lead to large-scale data exposure and operational disruption. 

7 Major U.S. Healthcare Data Breaches and What Went Wrong

The largest healthcare data breaches in the United States did not all start with sophisticated zero-day attacks. Some began with stolen passwords. Others involved phishing, an unpatched vulnerability, forgotten copies of patient data, or third-party tracking code that nobody treated as a security risk. 

That is what makes these incidents useful to study in 2026. They show where healthcare cybersecurity breaks down in practice. 

The seven breaches below are ranked primarily by the number of individuals affected. That gives us an objective way to compare their scale.

1. Change Healthcare

Breach fact 

Details 

Individuals affected 

Approximately 192.7 million 

Date 

February 2024 

Organization type 

Healthcare clearinghouse and technology provider 

Breach type 

Ransomware and data theft 

Initial access 

Stolen credentials used to access a Citrix remote-access portal without MFA 

Data involved 

PHI and personal information, potentially including health insurance, medical, claims, billing, financial and identity data 

What happened in the Change Healthcare breach?

On February 12, 2024, attackers used stolen credentials to access a Change Healthcare Citrix remote-access portal that did not use MFA. They then moved through the network, stole data and deployed ransomware nine days later. Change Healthcare shut down systems to contain the attack, disrupting claims, payments and pharmacy services nationwide. 

HHS now says about 192.7 million people were affected, making it the largest U.S. healthcare data breach on record. 

Why did the impact spread so widely?

The breach became so large because Change Healthcare sits inside critical claims, payment and pharmacy workflows used across the U.S. healthcare system. 

When its systems went offline, the impact spread beyond Change Healthcare itself. Providers that were never breached still struggled to process claims, receive payments and fill prescriptions. 

What security control failed?

The first failure was basic identity security: a password alone opened remote access to a critical system. MFA could have stopped stolen credentials from being enough. 

But MFA was not the only issue. Attackers also moved between systems, exposing weaknesses in access limits, network separation and monitoring. 

2. Anthem

Breach fact 

Details 

Individuals affected 

Approximately 78.8 million 

Date 

February 2015 

Organization type 

Health insurer 

Breach type 

Targeted cyberattack and large-scale data theft 

Initial access 

Spear-phishing emails sent to an Anthem subsidiary 

Data involved 

Names, Social Security numbers, medical IDs, dates of birth, addresses, email addresses and employment information 

What happened in the Anthem breach?

Attackers entered Anthem’s network after a spear-phishing email compromised an employee at a subsidiary. They moved through the network, gained higher-level access and eventually reached Anthem’s enterprise data warehouse. From there, they stole information on about 78.8 million people, including Social Security numbers, health ID numbers, dates of birth and addresses. 

Why did the breach become so large?

The breach became so large because attackers moved beyond the initially compromised employee account and reached systems containing data on tens of millions of members. 

Phishing created the entry point. Weak limits on what the attackers could reach after gaining access created the scale. 

What security control failed?

The bigger failure was access control after compromise, not phishing itself. Once attackers gained a foothold, they were able to move deeper into Anthem’s environment, increase their privileges and reach highly sensitive databases.  

A phishing email should compromise one account. It should not become a route to tens of millions of records. 

3. Kaiser Permanente

Breach fact 

Details 

Individuals affected 

Approximately 13.4 million 

Date 

April 2024 

Organization type 

Health plan and healthcare provider 

Breach type 

Unauthorized disclosure through third-party tracking technologies 

Cause 

Tracking technologies installed on websites and mobile applications 

Data involved 

Names, IP addresses, sign-in indicators, website/app activity and health encyclopedia search terms 

What happened in the Kaiser Permanente breach?

Kaiser Permanente discovered that tracking technologies on its websites and mobile apps may have sent user information to Google, Microsoft Bing and X. 

The data could include names, IP addresses, login status, browsing activity and searches made in Kaiser’s health encyclopedia. About 13.4 million people were notified. 

Why did the breach become so large?

Tracking technologies operate automatically. Once installed across high-traffic websites or applications, they can run every time users visit pages. Each visit, search or interaction could potentially send data to third parties. So, the exposure accumulated quietly because data sharing was built into normal digital activity. 

What security control failed?

This was a data visibility failure. Cookies and tracking pixels may look like marketing tools, but they can also send data outside the organization. Security and privacy teams need to know exactly what each tool collects, where it sends the data and whether that changes when someone signs in. 

More broadly, tracking technologies are part of a wider third-party visibility problem. Our guide to healthcare vendor and API penetration testing explains how healthcare organizations can assess these third-party attack paths in practice.

4. HCA Healthcare

Breach fact 

Details 

Individuals affected 

Approximately 11.27 million 

Date 

July 2023 

Organization type 

Hospital and healthcare system 

Breach type 

Data theft from an external storage location 

Affected system 

External storage used to automate email formatting 

Data involved 

Names, contact details, dates of birth, service dates, locations and appointment information 

What happened in the HCA Healthcare breach?

In July 2023, HCA Healthcare discovered patient data posted on an online forum. The data did not come from its main clinical systems. Attackers stole it from an external storage location used to prepare automated emails, including appointment reminders. 

The exposed data included names, contact details, dates of birth, service dates and appointment information. About 11.27 million people were affected. 

Why did the breach become so large?

The breach became so large because a secondary storage system used for routine email communications contained patient data at scale. 

The system did not hold HCA’s main clinical records, but it still contained enough personal information to expose millions of people. 

What security control failed?

The key failure was control over secondary copies of patient data. Healthcare data rarely stays in one system. Email tools, reporting platforms, integrations and external storage can all create additional copies. Once patient data is copied elsewhere, the organization still needs to know it exists, who can access it, how long it is retained and whether activity around it is being monitored. 

5. 23andMe

Breach fact 

Details 

Individuals affected 

6.9 million 

Attack period 

Approximately May to September 2023 

Organization type 

Direct-to-consumer genetic testing company 

Breach type 

Credential stuffing and abuse of the DNA Relatives feature 

Affected system 

Reused username/password combinations exposed in previous breaches 

Data involved 

Genetic, ancestry, identity and biological-relative information 

What happened in the 23andMe data breach?

In 2023, Attackers used credential stuffing, username, and password combinations exposed in earlier breaches, to access about 14,000 accounts. They then used the DNA Relatives feature to reach information linked to 6.9 million users. 

In May 2026, California’s Attorney General alleged that weak protections against credential stuffing and a coding flaw in DNA Relatives helped expand the breach.  

Why did the breach become so large?

The breach became so extensive because one compromised account could reveal information connected to many other users through the DNA Relatives feature. Attackers did not need to compromise millions of accounts individually. The product’s relationship-based design multiplied what each stolen login could expose.

What security control failed?

The breach exposed a failure in both account security and data access limits. Attackers reused stolen passwords to enter a small number of accounts. That should have been harder with stronger login protections such as MFA, breached-password detection and suspicious-login monitoring. 

But the larger failure came after login. Once inside, attackers could use the DNA Relatives feature to reach information linked to many other users. One compromised account should not unlock data belonging to thousands of connected users. 

6. Community Health Systems / CHSPSC

Breach fact 

Details 

Individuals affected 

6.1 million 

Attack period 

April to August 2014 

Organization type 

Healthcare IT/business associate supporting hospitals and physician clinics 

Breach type 

Network intrusion and data theft 

Initial access 

Compromised administrative credentials used to access the network through a VPN 

Data involved 

Names, dates of birth, phone numbers, Social Security numbers, emails and other patient information 

What happened in the Community Health Systems breach?

In April 2014, attackers stole administrative credentials and entered CHSPSC’s systems through its VPN. The FBI warned CHSPSC about the intrusion on April 18, but attacker activity continued until August 18. 

By then, the attackers had stolen protected health information belonging to 6.1 million people across 237 healthcare entities. 

Why did the breach become so large?

The breach became so large because attackers retained access for months and used compromised administrative credentials. Privileged accounts can reach far more systems and data than normal employee accounts. If attackers keep that access long enough, one stolen credential can open much of the environment. 

What security control failed?

The main problem was not only initial access. It was detection, containment and access control. Once an attacker is identified, teams must disable compromised accounts, remove unauthorized access, rotate credentials, review logs and verify that the attacker cannot return. Clearly, the system lacked it. 

7. Ascension

Breach fact 

Details 

Individuals affected 

Nearly 5.6 million 

Attack period 

May 8, 2024 

Organization type 

Multi-state hospital and health system 

Breach type 

Ransomware and data theft 

Initial access 

A malicious file was downloaded onto a company device 

Data involved 

Medical, payment, insurance, government-identification and other personal information 

What happened in the Ascension ransomware attack?

On May 8, 2024, Ascension detected a ransomware attack after an employee downloaded a malicious file they believed was legitimate. Ascension took systems offline, disrupting electronic health records, MyChart, medication and test ordering, and other clinical services. 

Staff moved to manual processes, while some facilities diverted ambulances or delayed non-emergency care. Nearly 5.6 million people were affected. 

Why did the breach become so disruptive?

The attack forced Ascension to take critical systems offline, disrupting the digital services clinicians relied on for everyday care. Because EHRs, medication orders, diagnostics and other workflows depend on connected infrastructure, containing ransomware affected far more than the initially compromised device. The result was not just data exposure. The attack disrupted healthcare delivery itself. 

What security control failed?

The bigger failure was containment after the initial compromise. One malicious download should not be able to disrupt critical hospital systems. Strong endpoint monitoring, limited privileges and network separation should restrict how far an attacker can move once a device is compromised. 

That operational reality is also shaping how healthcare organizations need to think about compliance. Our guide to HIPAA compliance expectations in 2026 looks at what that means in practice. 

Taken together, these breaches show that healthcare security problems rarely come from one missing control. They grow when organizations fail to test how those controls behave during a real compromise. 

What Major Healthcare Security Breaches Reveal About Cybersecurity in 2026

Across these healthcare security breach examples, the initial weakness was only part of the problem. The scale of the damage came from what happened next: excessive access, poorly mapped data, weak containment, critical third-party dependencies, and slow recovery.Here’s what you can learn:

Use Network Segmentation to Limit the Impact of Healthcare Cyberattacks

Network segmentation and strong access controls limit how far an attacker can move after gaining initial access. If one compromised account or endpoint can reach sensitive databases, privileged systems or critical infrastructure, the compromise can spread quickly. 

Review your network segmentation, privileged access and account permissions regularly. Identify where one compromised account or device could provide access to critical systems, then restrict those paths. 

Combine Your MFA with Least Privilege to Limit Account Access

MFA can stop stolen credentials from becoming a valid login, but it cannot limit what an account can access after login. If an account has excessive privileges, an attacker may still reach sensitive data or critical systems. 

Pair MFA with least privilege. Review privileged access, user roles and account permissions regularly so each user can access only what their role requires.  

Map Your Patient Data Beyond EHR Systems to Protect PHI

Patient data does not stay only inside EHRs or primary clinical databases. It can also move EHR into cloud storage, email platforms, analytics tools, APIs, websites and third-party systems as a part of normal healthcare operations. 

To protect PHI, you need visibility into those systems too. Map where your patient data is stored, processed and shared and apply appropriate security controls to those secondary systems and data copies as well. 

Assess Your Third-Party Risk for Operational Disruption, Not Just PHI Access

Third-party risk is not limited to vendors that handle PHI. Even vendors without direct access to patient data can create operational risk if your healthcare services depend on them. For vendors that do handle PHI, a Business Associate Agreement (BAA) defines their HIPAA responsibilities.  

But a BAA does not address the operational impact if a critical vendor becomes unavailable. If a critical provider goes offline, you may lose access to claims processing, payments, patient communications or other essential services. 

Map which vendors your critical operations depend on, what systems they support and how easily you could replace them if their services become unavailable. 

Test Your Cybersecurity Recovery Plans to Maintain Continuity of Patient Care

A cyberattack can disrupt patient care when it takes EHRs, medication systems or other critical services offline. Backups protect data, but they do not guarantee that you can restore systems or continue essential workflows during an outage. 

Set restoration priorities, test backup recovery and make sure your staff can continue critical workflows while systems remain unavailable. 

Not sure how far one compromised account could reach in your healthcare environment? KLEAP can assess access paths, exposed systems, third-party connections and recovery gaps through a healthcare security risk assessment and manual penetration testing.  

Book a slot with us: 

What Should Healthcare Organizations Do Differently in 2026?

For healthcare organizations, the takeaway is not to add more controls for the sake of it. It is to understand where the biggest exposure exists and test whether existing controls can actually limit the impact of a compromise. 

That means looking at where sensitive data moves, how far compromised accounts or devices can reach, which third-party dependencies create operational risk, and whether recovery plans work when critical systems go offline. 

These are the same areas KLEAP focuses on when assessing healthcare environments. 

KLEAP starts with a healthcare security risk analysis to identify the systems, data flows, access paths and third-party dependencies that create the largest exposure. 

From there, manual penetration testing validates whether those risks can actually be exploited across applications, APIs, networks, cloud environments and identity systems. 

KLEAP also helps healthcare and health tech teams review vendor risk, align controls with HIPAA and NIST requirements, and prioritize remediation based on actual exposure rather than theoretical severity. 

If you want a dedicated expert to help identify, test and close the gaps that could turn one compromise into a major breach, talk to your concierge. 

Frequently Asked Question

Healthcare organizations should prioritize MFA, limited privileges, segmentation, asset and data inventories, patching, backups, vendor reviews, monitoring, and security testing. A control written in a policy is not enough. It needs to work in practice. Risk assessments and penetration testing help you verify that. 

Florida has one of the largest number of healthcare providers in the US and consistently ranks among the top states for healthcare data breaches reported to OCR. High provider density plus high patient volume equals a large attack surface.

Medical devices may run outdated software, lack modern authentication, or be difficult to patch. If poorly isolated, they can increase the attack surface and make recovery harder after a breach. Accurate inventories and network segmentation are critical. 

No. Many healthcare data breaches begin in email, VPNs, cloud platforms, vendor systems, or employee devices. However, EHR security breaches can be especially damaging because EHRs contain large amounts of clinical and identity data. 

No. Encryption reduces the risk of stolen files being read, but it cannot stop every breach. Attackers may use legitimate accounts, abuse administrator privileges, or steal data while it is already accessible inside an application. 

No. MFA reduces password-based attacks, but it does not control what a user can access after login. Healthcare organizations also need limited privileges, network segmentation, monitoring, patching, and tested incident response. 

Share

Table of Contents