A total of 61 healthcare data breaches involving 500 or more individuals were reported to the HHS Office for Civil Rights in May 2026, representing a 27.1% increase from April 2026, while the number of affected individuals declined by 34.8% to 879,447.
Breach Reporting Trends
Based on data from the HHS Office for Civil Rights breach portal, 61 large healthcare data breaches were reported in May 2026. Over the previous 12 months, an average of 64 large healthcare data breaches were reported each month.
From January 1, 2026, through May 31, 2026, 319 healthcare data breaches involving 500 or more individuals were reported to the HHS Office for Civil Rights. During the same period in 2025, 342 large healthcare data breaches had been reported.
The number of individuals affected by healthcare data breaches fell to 879,447 in May 2026. The monthly average declined from 28,116 affected individuals in April to 14,417 affected individuals in May.
From January 1, 2026, through May 31, 2026, at least 21,085,405 individuals were affected across 319 reported breaches. During the corresponding period from January 2025 through May 2025, 33,116,809 individuals were affected by data breaches.
Largest Healthcare Data Breaches Reported in May
Seventeen healthcare data breaches involving 10,000 or more individuals were reported in May 2026. All 17 incidents were reported as hacking incidents.
- Radiology Associates of Richmond affected 266,183 individuals.
- Orthopaedics, P.C. affected 113,330 individuals.
- ERMI LLC affected 74,074 individuals.
- Singing River Health System affected 53,888 individuals.
- Southern Illinois Ob-Gyn Associates, S.C. affected 38,700 individuals.
- Gastro Health affected 35,632 individuals.
- Eyemart Express, LLC affected 25,000 individuals.
- Connecticut Department of Social Services affected 22,500 individuals.
- Bridle Trails Family Dentistry affected 20,976 individuals.
- Community Connections affected 18,943 individuals.
- Virta Medical PC affected 14,636 individuals.
- Saurabh N. Patel, M.D – Florida Retina Center affected 13,652 individuals.
- Greenbaum Rowe Smith & Davis LLP affected 12,801 individuals.
- Wellpoint Washington, Inc. affected 12,020 individuals.
- Defense Health Agency (TriWest) affected 11,848 individuals.
- IKRON Corporation affected 11,845 individuals.
- Elara Caring affected 10,490 individuals.
The report stated that total affected individuals for May may increase as organizations complete breach investigations. HIPAA-regulated entities need to notify the HHS Office for Civil Rights and affected individuals within 60 days from discovering a data breach. If the total number of affected individuals has not yet been determined by the deadline, an estimate may be submitted. Seven entities reported breach totals of 500 or 501 individuals during May 2026.
Causes of May 2026 Healthcare Data Breaches
Hacking and information technology incidents accounted for 54 of the 61 reported breaches in May 2026.
These incidents represented 88.5% of reported breaches during the month. A total of 853,532 individuals were affected by hacking and information technology incidents, which represented 88.5% of all affected individuals reported in May.
The average number of affected individuals per hacking or information technology incident was 15,806. The median breach size was 3,619 individuals.
Seven incidents were classified as unauthorized access or disclosure incidents. Those incidents affected 25,915 individuals.
The average number of affected individuals per unauthorized access or disclosure incident was 3,702. The median breach size was 3,086 individuals.
No theft, loss, or improper disposal incidents were reported during May 2026.
Network servers were identified as the most common location of breached protected health information (PHI). Email-related incidents were also reported in substantial numbers.
States Reporting Large Healthcare Data Breaches
Large healthcare data breaches were reported in 26 states and the District of Columbia.
California reported six breaches, the highest number among states.
Florida, North Carolina, New York, New Jersey, Ohio, Texas, and Virginia each reported four breaches.
Virginia had the largest number of affected individuals, with almost 300,000 residents affected. Colorado ranked second with 128,661 affected individuals, followed by Georgia with 74,074 affected individuals and Mississippi with 53,888 affected individuals.
Breaches by HIPAA-Regulated Entity Type
Healthcare providers reported 42 breaches in May 2026. Health plans reported nine breaches. Business associates reported 10 breaches.
The report stated that breaches occurring at business associates require notification to affected covered entities. Covered entities may delegate notification responsibilities to business associates, but responsibility for ensuring notifications are issued remains with the covered entities.
The report also stated that 22 of the 61 breaches occurred at business associates when the location of the breach is analyzed rather than the reporting entity.
HIPAA Enforcement Activity
No enforcement actions were announced by the HHS Office for Civil Rights or state attorneys general during May 2026.