Breaches & Passwords

Medical Data Breaches Explained

By the RedactZero Team · September 9, 2026 · 9 min read

The short version

A medical data breach exposes health records held by a hospital, insurer, billing vendor, or app. Those records are the costliest category to lose because they bundle your Social Security number, date of birth, insurance ID, and diagnoses, none of which you can reset. HIPAA forces covered organizations to notify you within 60 days, but it gives you no right to sue, does not require credit monitoring, and never applied to fitness apps or period trackers at all. Freeze your credit, watch your insurance statements, and check whether your email is in a known breach.

What a medical data breach actually is

A medical data breach is any unauthorized access to, or disclosure of, protected health information held by a healthcare provider, health plan, or a vendor working for them. That includes ransomware attacks, stolen laptops, misdirected mail, and a tracking pixel quietly sending your appointment details to an ad network. The law does not care whether a hacker was involved.

Most people picture a break-in, but some of the biggest incidents are nothing of the kind. In 2025, Blue Shield of California reported that a misconfigured Google Analytics setup had shared the data of 4.7 million members with Google Ads. Nobody broke in. The data still left.

Under HIPAA, "protected health information" is anything that ties a health detail to an identifiable person: your name next to a diagnosis, a billing record, an insurance member ID, a prescription. The notice you receive must list which of those were involved, and that list is the most important paragraph in the letter.

Why health records are the most valuable thing to steal

Health records are worth more to criminals than card numbers because they cannot be cancelled. A stolen card is dead within hours of being reported. A record that bundles your Social Security number, date of birth, home address, insurance ID, and medical history stays useful for years, and it supports frauds that a card number never could.

The cost side confirms it. IBM's 2026 Cost of a Data Breach study put the average healthcare breach at $6.64 million, against a global average of $4.99 million across all industries, and healthcare has topped IBM's industry rankings for well over a decade running.

For you, the durable harm is impersonation. Someone holding your insurance ID and date of birth can obtain treatment in your name, which then lands in your medical file. Someone holding your diagnosis can write a phishing email that names your actual condition and doctor. Both are harder to spot, and harder to undo, than a fraudulent charge.

How big the problem is right now

Large healthcare breaches, meaning those affecting 500 or more people, now run at roughly two per day in the United States. The Department of Health and Human Services publishes each one on its Office for Civil Rights breach portal, and HIPAA Journal's analysis of that portal shows well over 700 large breaches reported in 2024 and roughly 800 in 2025.

Counts of affected people are more volatile, because organizations revise them upward for months. HIPAA Journal put the 2024 total at about 289 million individuals, dominated by the Change Healthcare breach. Its first count for 2025 was about 61.6 million, but that has since risen sharply as late reports were added, including one vendor breach involving more than 62 million people on its own. Through June 2026, almost 34 million individuals had been affected this year.

OrganizationTypeIndividuals affected
Conduent Business ServicesClaims and payment vendor62.2 million
AflacInsurer13.9 million
EpisourceCoding and risk-adjustment vendor6.7 million
Yale New Haven HealthHospital system5.6 million
Blue Shield of CaliforniaHealth plan4.7 million

Largest healthcare breaches reported to HHS in 2025, as compiled from the OCR breach portal by HIPAA Journal (June 2026). Several counts were revised upward after the first filing.

Notice that the two largest entries are not hospitals. Conduent and Episource are business associates, vendors that process claims and coding for insurers and state agencies. The organization that loses your records is often one you never chose.

Change Healthcare: the breach that reset the scale

The February 2024 ransomware attack on Change Healthcare, a UnitedHealth Group subsidiary that processes a large share of US medical claims, is the largest healthcare breach ever reported to HHS. UnitedHealth's estimate of affected individuals climbed from 100 million in late 2024 to 190 million in January 2025, and to 192.7 million by July 2025.

The attackers got in on February 21, 2024, through a Citrix remote-access portal that had no multifactor authentication, according to the company's own account. UnitedHealth's chief executive, Andrew Witty, told a Senate Finance Committee hearing on May 1, 2024 that the company paid a $22 million ransom. Paying did not keep the data from being exposed.

Because Change Healthcare is a clearinghouse in the middle of the system, notices went out on behalf of thousands of providers and plans. Many people received a letter from a company they had never dealt with, more than a year after the attack. That delay was permitted, which brings us to what the law actually requires.

What HIPAA requires after a breach

HIPAA's Breach Notification Rule requires a covered organization to notify affected individuals without unreasonable delay and no later than 60 calendar days after it discovers a breach of unsecured protected health information. Breaches affecting 500 or more people must be reported to HHS simultaneously, and to prominent media outlets in any state with more than 500 affected residents.

Breaches affecting fewer than 500 people are logged and reported to HHS in an annual batch, within 60 days of the end of the calendar year. And the 60-day clock starts at discovery, not at the intrusion. The rule also lets an organization run a risk assessment to decide whether an incident is a reportable breach at all. In practice, notification can lag the break-in by many months.

The notice itself must describe what happened, including the dates of the breach and its discovery; the types of information involved; steps you can take to protect yourself; what the organization is doing about it; and a toll-free number, email address, website, or postal address for questions.

What HIPAA does not do for you

HIPAA gives you no right to sue. There is no private right of action under the law. Your remedies are a complaint to the HHS Office for Civil Rights, a claim under state law, or joining a class action built on state negligence or consumer-protection statutes.

HIPAA also does not require the organization to pay for credit monitoring, reimburse your losses, or clean up the fraudulent claims that follow. When you are offered free monitoring after a breach, that is a voluntary gesture, a state-law requirement, or a lawsuit settlement term. It is not HIPAA.

Enforcement is thin relative to the volume. The Office for Civil Rights closed 21 enforcement actions with settlements or civil penalties in 2025, a year with roughly 800 large breaches. Most end with a letter, a portal entry, and no penalty. Complaints still matter, because they are how OCR chooses what to investigate. Our guide to where to file a privacy complaint walks through the process.

The health data HIPAA never covered

HIPAA applies only to health plans, healthcare clearinghouses, healthcare providers, and the business associates that work for them. A fitness tracker, a period-tracking app, a symptom checker, a meditation app, or a discount-prescription website is usually none of those. The health data they hold sits outside HIPAA entirely, even when it started in your doctor's records.

The FTC's guidance for app developers says this plainly: the HIPAA rules likely do not apply to health information kept in an app that is not offered by a covered entity or its business associate, even if that information originated with one. Export records from a patient portal into a third-party app and they leave HIPAA's protection.

What fills the gap is the FTC's Health Breach Notification Rule, updated in 2024 to state explicitly that it covers health apps and connected devices. It requires notice to affected people within 60 days, notice to the FTC for breaches of 500 or more, and carries civil penalties of up to $53,088 per violation. The FTC has treated unauthorized sharing with advertisers as a breach under it, but it is a notification rule, not a privacy rule: it does not restrict what an app may collect.

The enforcement record shows where the risk is. In February 2023, GoodRx agreed to a $1.5 million civil penalty, the first action under the rule, for failing to report that it had shared users' health data with Facebook, Google, and others for advertising. In May 2023, the makers of Premom, an ovulation-tracking app, agreed to a $100,000 penalty for sending users' data to marketing firms, including two based in China. In March 2023, BetterHelp was ordered to pay $7.8 million for sharing mental-health data with Facebook, Snapchat, Criteo, and Pinterest after promising to keep it private, under the FTC's general deception authority. All three describe where health data now lives: in apps, shared with advertisers, outside HIPAA.

What criminals do with medical data

Stolen medical data feeds three main frauds. Medical identity theft, where someone obtains care or prescriptions in your name. Financial identity theft, using the Social Security number and date of birth inside the record. And targeted phishing that uses your diagnosis or your doctor's name to make a scam believable.

Medical identity theft is the one specific to this data. The FTC's Consumer Sentinel Network logged 10,116 identity theft reports involving medical services in 2024, out of roughly 1.1 million identity theft reports overall. A small share, but the most damaging kind: false claims can exhaust your benefits, put someone else's conditions in your chart, and take months to correct. Many victims never notice, because the first sign is an insurance statement most people never read.

The financial side is more familiar. A Social Security number and date of birth from a health record are the ingredients of new-account fraud, and with a real name and address they can also seed a synthetic identity. Our list of the signs your identity was stolen covers the early warnings.

How to read the breach notice you received

The most useful part of a breach letter is the list of data types involved. Match each item to a risk: Social Security number means credit fraud, insurance ID means medical identity theft, diagnosis or treatment details mean targeted phishing, and contact details alone mean spam and scam calls.

Be suspicious of the letter itself. Real breach notices never ask for your Social Security number, a password, or payment details, and never need you to click a link to "verify" your identity. If a notice offers free monitoring, type the address printed in the letter rather than following an emailed link. Our guide to protecting yourself against phishing explains why breach victims get targeted a second time.

What to do after a medical data breach

Freeze your credit at all three bureaus, then pull and read your insurer's explanation-of-benefits statements for services you did not receive. Those two moves cover the most expensive outcomes. Then check your records for errors, change reused passwords, and report anything wrong.

  1. Freeze your credit with Equifax, Experian, and TransUnion. It is free and blocks new accounts opened with your Social Security number. Our credit freeze guide has the steps for each bureau.
  2. Review your explanation-of-benefits statements and your patient portal for visits, prescriptions, or equipment you never received. Report anything unfamiliar to your insurer's fraud line, in writing.
  3. Request a copy of your medical record from the affected provider and ask for corrections if someone else's care has been added. HIPAA gives you the right to have a covered entity amend a record about you.
  4. Report medical identity theft at IdentityTheft.gov, which generates a recovery plan and the letters you will need.
  5. File a complaint with the HHS Office for Civil Rights if the organization was slow to notify you or left required details out of the letter.
  6. Check whether your email address has appeared in other breaches and change any password you reused. RedactZero's free scan checks an email against Have I Been Pwned and stores nothing you enter. Our explainer on how Have I Been Pwned works covers what a result means.

Then keep watching. Fraud built on medical data tends to arrive months later, when the letter is long forgotten. Our general checklist for what to do after a data breach covers the rest, and the breaches and passwords hub collects every related guide in one place.

Find out what is already exposed

Run a free exposure scan to see whether your email is in a known breach, plus the data brokers likely to list you - no account, nothing stored.

Run a free exposure scan

Frequently asked questions

Does HIPAA require a company to tell me if my medical data was breached?

Yes, if the organization is a HIPAA covered entity (a provider, health plan, or clearinghouse) or a vendor working for one. The Breach Notification Rule requires individual notice without unreasonable delay and no later than 60 calendar days after the breach is discovered. Apps and websites outside HIPAA fall under the FTC's separate Health Breach Notification Rule instead.

How long does a healthcare organization have to notify me of a breach?

No later than 60 calendar days after it discovers the breach, and sooner if it reasonably can. The clock starts at discovery, not at the intrusion, so a breach that went unnoticed for months can legally reach you much later than that.

Can I sue a hospital or insurer under HIPAA?

No. HIPAA has no private right of action, so individuals cannot sue for a HIPAA violation. You can file a complaint with the HHS Office for Civil Rights, and you may have claims under state negligence or consumer-protection law, which is what most breach class actions are built on.

Are fitness apps and period trackers covered by HIPAA?

Usually not. HIPAA covers providers, health plans, clearinghouses, and their business associates. A consumer app that is not offered by one of those is outside HIPAA even if the data came from your doctor. Those apps are covered by the FTC's Health Breach Notification Rule, which requires notice of a breach but does not stop the sharing itself.

What is medical identity theft?

Someone using your name, insurance ID, or Social Security number to obtain treatment, prescriptions, or equipment, or to bill your insurer for care you never received. It can exhaust your benefits and put another person's conditions into your medical record. The FTC logged 10,116 identity theft reports involving medical services in 2024.

Should I freeze my credit after a medical data breach?

Yes, if the notice says your Social Security number or date of birth was involved. A freeze at Equifax, Experian, and TransUnion is free and blocks new accounts opened in your name. It does not stop medical identity theft, so also review your insurer's explanation-of-benefits statements.

How do I know if my data was in the Change Healthcare breach?

Change Healthcare mailed notices on behalf of the providers and plans it served, so the letter may have come from a company you never dealt with. If you had US health insurance in early 2024, assume exposure is possible: the final count was 192.7 million people. HHS keeps a Change Healthcare FAQ page, and you can contact the provider that treated you to ask whether it used Change for claims.

Where do I file a complaint about a medical data breach?

For a HIPAA-covered organization, file with the HHS Office for Civil Rights. For a health app or website outside HIPAA, file with the FTC. If you find fraudulent claims or accounts, report them at IdentityTheft.gov, which generates a recovery plan and the letters you will need.

Sources: HHS Office for Civil Rights breach portal figures as compiled by HIPAA Journal (2024 and 2025 annual reports, June 2026 monthly report, largest breaches of 2025); HIPAA Breach Notification Rule, 45 CFR 164.400-414, and the amendment right at 45 CFR 164.526; Congressional Research Service report R43991 on HIPAA's scope and private right of action; FTC (Health Breach Notification Rule and compliance guide, Mobile Health Apps Interactive Tool, GoodRx, BetterHelp and Premom press releases, Consumer Sentinel Network Data Book 2024); IBM Cost of a Data Breach Report 2026; UnitedHealth Group testimony to the Senate Finance Committee on May 1, 2024, as reported by NBC News and The Record; Change Healthcare notification updates as tracked by HIPAA Journal.