Healthcare cybersecurity breaches rarely begin with an advanced attack. A stolen credential, missing Multi Factor Authentication (MFA), unpatched vulnerability, exposed data store, or poorly controlled third-party connection can be enough.
HHS requires breaches of unsecured protected health information (PHI) affecting 500 or more individuals to be reported through its public breach portal. Data reported through April 30, 2026, listed 252 large healthcare data breaches in the United States.
The scale of these incidents makes them difficult to ignore. It raises a question, why these healthcare security breaches happen and what they reveal about the security gaps healthcare organizations still struggle to control.
This article examines seven major healthcare security breaches in the United States, including Change Healthcare, Anthem, HCA Healthcare, Kaiser Permanente, and Ascension. Each case highlights a different weakness in access control, data visibility, third-party risk, containment, or recovery readiness
What Is a Healthcare Security Breach?
A healthcare security breach occurs when unauthorized individuals access, acquire, disclose, alter, or compromise protected healthcare information or the systems that store or process it.
These incidents can affect more than electronic health records (EHRs). Patient portals, cloud applications, employee accounts, medical devices, APIs, third-party platforms, and even website tracking tools can create pathways to sensitive data.
A single healthcare cybersecurity breach can involve compromised credentials, inadequate access controls, a third-party integration, and poor monitoring at the same time.
The seven U.S. healthcare security breaches below show how these seemingly different weaknesses can lead to large-scale data exposure and operational disruption.
7 Major U.S. Healthcare Data Breaches and What Went Wrong
The largest healthcare data breaches in the United States did not all start with sophisticated zero-day attacks. Some began with stolen passwords. Others involved phishing, an unpatched vulnerability, forgotten copies of patient data, or third-party tracking code that nobody treated as a security risk.
That is what makes these incidents useful to study in 2026. They show where healthcare cybersecurity breaks down in practice.
The seven breaches below are ranked primarily by the number of individuals affected. That gives us an objective way to compare their scale.
1. Change Healthcare
Breach fact
Details
Individuals affected
Approximately 192.7 million
Date
February 2024
Organization type
Healthcare clearinghouse and technology provider
Breach type
Ransomware and data theft
Initial access
Stolen credentials used to access a Citrix remote-access portal without MFA
Data involved
PHI and personal information, potentially including health insurance, medical, claims, billing, financial and identity data


What happened in the Change Healthcare breach?
On February 12, 2024, attackers used stolen credentials to access a Change Healthcare Citrix remote-access portal that did not use MFA. They then moved through the network, stole data and deployed ransomware nine days later. Change Healthcare shut down systems to contain the attack, disrupting claims, payments and pharmacy services nationwide.
HHS now says about 192.7 million people were affected, making it the largest U.S. healthcare data breach on record.
Why did the impact spread so widely?
The breach became so large because Change Healthcare sits inside critical claims, payment and pharmacy workflows used across the U.S. healthcare system.
When its systems went offline, the impact spread beyond Change Healthcare itself. Providers that were never breached still struggled to process claims, receive payments and fill prescriptions.
What security control failed?
The first failure was basic identity security: a password alone opened remote access to a critical system. MFA could have stopped stolen credentials from being enough.
But MFA was not the only issue. Attackers also moved between systems, exposing weaknesses in access limits, network separation and monitoring.
2. Anthem
Breach fact
Details
Individuals affected
Approximately 78.8 million
Date
February 2015
Organization type
Health insurer
Breach type
Targeted cyberattack and large-scale data theft
Initial access
Spear-phishing emails sent to an Anthem subsidiary
Data involved
Names, Social Security numbers, medical IDs, dates of birth, addresses, email addresses and employment information


What happened in the Anthem breach?
Attackers entered Anthem’s network after a spear-phishing email compromised an employee at a subsidiary. They moved through the network, gained higher-level access and eventually reached Anthem’s enterprise data warehouse. From there, they stole information on about 78.8 million people, including Social Security numbers, health ID numbers, dates of birth and addresses.
Why did the breach become so large?
The breach became so large because attackers moved beyond the initially compromised employee account and reached systems containing data on tens of millions of members.
Phishing created the entry point. Weak limits on what the attackers could reach after gaining access created the scale.
What security control failed?
The bigger failure was access control after compromise, not phishing itself. Once attackers gained a foothold, they were able to move deeper into Anthem’s environment, increase their privileges and reach highly sensitive databases.
A phishing email should compromise one account. It should not become a route to tens of millions of records.
3. Kaiser Permanente
Breach fact
Details
Individuals affected
Approximately 13.4 million
Date
April 2024
Organization type
Health plan and healthcare provider
Breach type
Unauthorized disclosure through third-party tracking technologies
Cause
Tracking technologies installed on websites and mobile applications
Data involved
Names, IP addresses, sign-in indicators, website/app activity and health encyclopedia search terms


What happened in the Kaiser Permanente breach?
Kaiser Permanente discovered that tracking technologies on its websites and mobile apps may have sent user information to Google, Microsoft Bing and X.
The data could include names, IP addresses, login status, browsing activity and searches made in Kaiser’s health encyclopedia. About 13.4 million people were notified.
Why did the breach become so large?
Tracking technologies operate automatically. Once installed across high-traffic websites or applications, they can run every time users visit pages. Each visit, search or interaction could potentially send data to third parties. So, the exposure accumulated quietly because data sharing was built into normal digital activity.
What security control failed?
This was a data visibility failure. Cookies and tracking pixels may look like marketing tools, but they can also send data outside the organization. Security and privacy teams need to know exactly what each tool collects, where it sends the data and whether that changes when someone signs in.
More broadly, tracking technologies are part of a wider third-party visibility problem. Our guide to healthcare vendor and API penetration testing explains how healthcare organizations can assess these third-party attack paths in practice.
4. HCA Healthcare
Breach fact
Details
Individuals affected
Approximately 11.27 million
Date
July 2023
Organization type
Hospital and healthcare system
Breach type
Data theft from an external storage location
Affected system
External storage used to automate email formatting
Data involved
Names, contact details, dates of birth, service dates, locations and appointment information


What happened in the HCA Healthcare breach?
In July 2023, HCA Healthcare discovered patient data posted on an online forum. The data did not come from its main clinical systems. Attackers stole it from an external storage location used to prepare automated emails, including appointment reminders.
The exposed data included names, contact details, dates of birth, service dates and appointment information. About 11.27 million people were affected.
Why did the breach become so large?
The breach became so large because a secondary storage system used for routine email communications contained patient data at scale.
The system did not hold HCA’s main clinical records, but it still contained enough personal information to expose millions of people.
What security control failed?
The key failure was control over secondary copies of patient data. Healthcare data rarely stays in one system. Email tools, reporting platforms, integrations and external storage can all create additional copies. Once patient data is copied elsewhere, the organization still needs to know it exists, who can access it, how long it is retained and whether activity around it is being monitored.
5. 23andMe
Breach fact
Details
Individuals affected
6.9 million
Attack period
Approximately May to September 2023
Organization type
Direct-to-consumer genetic testing company
Breach type
Credential stuffing and abuse of the DNA Relatives feature
Affected system
Reused username/password combinations exposed in previous breaches
Data involved
Genetic, ancestry, identity and biological-relative information


What happened in the 23andMe data breach?
In 2023, Attackers used credential stuffing, username, and password combinations exposed in earlier breaches, to access about 14,000 accounts. They then used the DNA Relatives feature to reach information linked to 6.9 million users.
In May 2026, California’s Attorney General alleged that weak protections against credential stuffing and a coding flaw in DNA Relatives helped expand the breach.
Why did the breach become so large?
The breach became so extensive because one compromised account could reveal information connected to many other users through the DNA Relatives feature. Attackers did not need to compromise millions of accounts individually. The product’s relationship-based design multiplied what each stolen login could expose.
What security control failed?
The breach exposed a failure in both account security and data access limits. Attackers reused stolen passwords to enter a small number of accounts. That should have been harder with stronger login protections such as MFA, breached-password detection and suspicious-login monitoring.
But the larger failure came after login. Once inside, attackers could use the DNA Relatives feature to reach information linked to many other users. One compromised account should not unlock data belonging to thousands of connected users.
6. Community Health Systems / CHSPSC
Breach fact
Details
Individuals affected
6.1 million
Attack period
April to August 2014
Organization type
Healthcare IT/business associate supporting hospitals and physician clinics
Breach type
Network intrusion and data theft
Initial access
Compromised administrative credentials used to access the network through a VPN
Data involved
Names, dates of birth, phone numbers, Social Security numbers, emails and other patient information


What happened in the Community Health Systems breach?
In April 2014, attackers stole administrative credentials and entered CHSPSC’s systems through its VPN. The FBI warned CHSPSC about the intrusion on April 18, but attacker activity continued until August 18.
By then, the attackers had stolen protected health information belonging to 6.1 million people across 237 healthcare entities.
Why did the breach become so large?
The breach became so large because attackers retained access for months and used compromised administrative credentials. Privileged accounts can reach far more systems and data than normal employee accounts. If attackers keep that access long enough, one stolen credential can open much of the environment.
What security control failed?
The main problem was not only initial access. It was detection, containment and access control. Once an attacker is identified, teams must disable compromised accounts, remove unauthorized access, rotate credentials, review logs and verify that the attacker cannot return. Clearly, the system lacked it.
7. Ascension
Breach fact
Details
Individuals affected
Nearly 5.6 million
Attack period
May 8, 2024
Organization type
Multi-state hospital and health system
Breach type
Ransomware and data theft
Initial access
A malicious file was downloaded onto a company device
Data involved
Medical, payment, insurance, government-identification and other personal information


What happened in the Ascension ransomware attack?
On May 8, 2024, Ascension detected a ransomware attack after an employee downloaded a malicious file they believed was legitimate. Ascension took systems offline, disrupting electronic health records, MyChart, medication and test ordering, and other clinical services.
Staff moved to manual processes, while some facilities diverted ambulances or delayed non-emergency care. Nearly 5.6 million people were affected.
Why did the breach become so disruptive?
The attack forced Ascension to take critical systems offline, disrupting the digital services clinicians relied on for everyday care. Because EHRs, medication orders, diagnostics and other workflows depend on connected infrastructure, containing ransomware affected far more than the initially compromised device. The result was not just data exposure. The attack disrupted healthcare delivery itself.
What security control failed?
The bigger failure was containment after the initial compromise. One malicious download should not be able to disrupt critical hospital systems. Strong endpoint monitoring, limited privileges and network separation should restrict how far an attacker can move once a device is compromised.
That operational reality is also shaping how healthcare organizations need to think about compliance. Our guide to HIPAA compliance expectations in 2026 looks at what that means in practice.
Taken together, these breaches show that healthcare security problems rarely come from one missing control. They grow when organizations fail to test how those controls behave during a real compromise.
What Major Healthcare Security Breaches Reveal About Cybersecurity in 2026
Use Network Segmentation to Limit the Impact of Healthcare Cyberattacks
Network segmentation and strong access controls limit how far an attacker can move after gaining initial access. If one compromised account or endpoint can reach sensitive databases, privileged systems or critical infrastructure, the compromise can spread quickly.
Review your network segmentation, privileged access and account permissions regularly. Identify where one compromised account or device could provide access to critical systems, then restrict those paths.
Combine Your MFA with Least Privilege to Limit Account Access
MFA can stop stolen credentials from becoming a valid login, but it cannot limit what an account can access after login. If an account has excessive privileges, an attacker may still reach sensitive data or critical systems.
Pair MFA with least privilege. Review privileged access, user roles and account permissions regularly so each user can access only what their role requires.
Map Your Patient Data Beyond EHR Systems to Protect PHI
Patient data does not stay only inside EHRs or primary clinical databases. It can also move EHR into cloud storage, email platforms, analytics tools, APIs, websites and third-party systems as a part of normal healthcare operations.
To protect PHI, you need visibility into those systems too. Map where your patient data is stored, processed and shared and apply appropriate security controls to those secondary systems and data copies as well.
Assess Your Third-Party Risk for Operational Disruption, Not Just PHI Access
Third-party risk is not limited to vendors that handle PHI. Even vendors without direct access to patient data can create operational risk if your healthcare services depend on them. For vendors that do handle PHI, a Business Associate Agreement (BAA) defines their HIPAA responsibilities.
But a BAA does not address the operational impact if a critical vendor becomes unavailable. If a critical provider goes offline, you may lose access to claims processing, payments, patient communications or other essential services.
Map which vendors your critical operations depend on, what systems they support and how easily you could replace them if their services become unavailable.
Test Your Cybersecurity Recovery Plans to Maintain Continuity of Patient Care
A cyberattack can disrupt patient care when it takes EHRs, medication systems or other critical services offline. Backups protect data, but they do not guarantee that you can restore systems or continue essential workflows during an outage.
Set restoration priorities, test backup recovery and make sure your staff can continue critical workflows while systems remain unavailable.
Not sure how far one compromised account could reach in your healthcare environment? KLEAP can assess access paths, exposed systems, third-party connections and recovery gaps through a healthcare security risk assessment and manual penetration testing.
Book a slot with us:
What Should Healthcare Organizations Do Differently in 2026?
For healthcare organizations, the takeaway is not to add more controls for the sake of it. It is to understand where the biggest exposure exists and test whether existing controls can actually limit the impact of a compromise.
That means looking at where sensitive data moves, how far compromised accounts or devices can reach, which third-party dependencies create operational risk, and whether recovery plans work when critical systems go offline.
These are the same areas KLEAP focuses on when assessing healthcare environments.
KLEAP starts with a healthcare security risk analysis to identify the systems, data flows, access paths and third-party dependencies that create the largest exposure.
From there, manual penetration testing validates whether those risks can actually be exploited across applications, APIs, networks, cloud environments and identity systems.
KLEAP also helps healthcare and health tech teams review vendor risk, align controls with HIPAA and NIST requirements, and prioritize remediation based on actual exposure rather than theoretical severity.
If you want a dedicated expert to help identify, test and close the gaps that could turn one compromise into a major breach, talk to your concierge.
Frequently Asked Question
What is the difference between a healthcare cyberattack and a healthcare data breach?
Healthcare organizations should prioritize MFA, limited privileges, segmentation, asset and data inventories, patching, backups, vendor reviews, monitoring, and security testing. A control written in a policy is not enough. It needs to work in practice. Risk assessments and penetration testing help you verify that.
What controls can reduce healthcare data breaches?
Florida has one of the largest number of healthcare providers in the US and consistently ranks among the top states for healthcare data breaches reported to OCR. High provider density plus high patient volume equals a large attack surface.
Why are medical devices a healthcare cybersecurity risk?
Medical devices may run outdated software, lack modern authentication, or be difficult to patch. If poorly isolated, they can increase the attack surface and make recovery harder after a breach. Accurate inventories and network segmentation are critical.
Are EHR security breaches the main cause of healthcare data breaches?
No. Many healthcare data breaches begin in email, VPNs, cloud platforms, vendor systems, or employee devices. However, EHR security breaches can be especially damaging because EHRs contain large amounts of clinical and identity data.
Does encryption prevent healthcare data breaches?
No. Encryption reduces the risk of stolen files being read, but it cannot stop every breach. Attackers may use legitimate accounts, abuse administrator privileges, or steal data while it is already accessible inside an application.
Is Multi Factor Authentication (MFA) enough to prevent a security breach in healthcare?
No. MFA reduces password-based attacks, but it does not control what a user can access after login. Healthcare organizations also need limited privileges, network segmentation, monitoring, patching, and tested incident response.
