Based on the current data from a federal data breach portal, from January 1 to April 30, 2026, 252 large healthcare data breaches have been reported to HHS' Office for Civil Rights, according to HIPAA Journal. Fierce Healthcare is tracking data breaches across healthcare organizations in 2026. Stay up-to-date with this tracker for the latest updates, and email Cailey Gleeson at [email protected] with any news.
Unlimited Technology Systems
Incident Date: Oct. 5-10, 2025
Affected Individuals: 3.8 million
Unlimited Technology, a provider of revenue cycle management services, suffered a data breach affecting more than 3 million individuals, a U.S. Department of Health and Human Services (HHS) Office of Civil Rights database shows.
Although the scale of the data breach is unconfirmed, it is considered the largest healthcare data breach of the year date, per The HIPAA Journal.
The breach occurred from Oct. 5 to 10 and involved protected health information of more than 3.8 million individuals, according to The HIPAA Journal. Potentially accessed data includes personal contact information, Social Security numbers, insurance information and more. No threat group has claimed responsibility for the cyberattack.
Everside Health through Aesto LLC
Incident Date: Dec. 2-18, 2025
Affected Individuals: Not publicly disclosed
Everside Health, a direct primary care provider that offers employer- and union-sponsored healthcare services, was impacted by a data breach through Aesto LLC, a third party healthcare data migration vendor, according to the HHS Office of Civil Rights database.
The breach occurred around mid-December 2025, which impacted Aesto's Amazon Web Services infrastructure. In May of 2026, the vendor confirmed that protected health information, including Everside Health data, may have been accessed or acquired by an unauthorized party, according to a notice (PDF). Information that was potentially exposed includes full names, dates of birth, addresses, Social Security numbers, medical information and health records.
Aesto disclosed the breach to the attorneys general of California, Massachusetts, South Carolina and Texas beginning July 31. Affected users have been offered complimentary membership to Privacy Solutions ID. At least 80,622 South Carolina residents, 22,210 Texas Residents, and 1,562 Massachusetts residents impacted have been impacted.
CareCloud
Incident Date: March 16
Affected Individuals: At least 345,000
CareCloud, a provider of cloud-based and AI-powered EHR, RCM, PM, and clinical documentation solutions suffered a security incident in mid-March, according to The HIPAA Journal.
The network disruption impacted one of their electronic health record environments, and third-party experts confirmed that this environment was accessed by an unauthorized third party.
Although the threat actor has not been disclosed and no ransomware group has claimed responsibility, the threat actor did claim to have exfiltrated databases. CareCloud confirmed in June the compromised data types include names, addresses, Social Security numbers, financial account numbers, health insurance information and more.
Individuals have begun to receive notification letters and are being offered 24 months of complimentary identity theft protection services, per The HIPAA Journal. It is unclear how many individuals have been affected, but based on data breach summaries, it is at least 345,000 individuals.
Per their statement, “CareCloud believes it has eliminated the threat and has not identified any further unauthorized access to its AWS environment or other systems since March 16, 2026. The company has confirmed that it will continue to take steps to strengthen the security of its systems and environments to reduce the risk of similar incidents in the future.”
Youth Home
Incident Date: May 14
Affected Individuals: Not publicly disclosed
Youth Home patient data was accessed without authorization through an employee's email on May 14, according to a July 13 notice on its website.
The breach granted a third-party access to data such as first and last names, medical information, diagnosis information, medications and Social Security numbers.
Youth Home terminated access May 15, subsequently implementing measures to strengthen data security. Review by external cybersecurity teams found no evidence that the accessed information has been utilized, per the notice.
The provider is currently undergoing an enterprise-wide review of the system as well as offering one year of free credit insurance for affected individuals. They have been notified, and Youth Home maintains their commitment to security of protected information.
Lifespan Physician Group
Incident date: Dec. 15-16, 2025
Affected individuals: 311,760
Lifespan Physician Group of Massachusetts, which does business as Brown Health Medical Group, reported on July 16 a data breach impacting more than 311,000 patients, the HHS Office of Civil Rights database shows.
The breach occurred at its Hawthorn location on Dec. 15-16 through a “historic file server,” and did not impact its electronic health record (EHR) system, a substitute notice (PDF) said.
The organization determined the scope of impacted information on June 22, which includes demographic information; health insurance information; medical information; billing, claims and payment information; financial account information; Social Security numbers and more.
“We are committed to maintaining the privacy and security of personal information and take this incident very seriously,” the organization said. “We took, and will continue to take, appropriate steps to address this incident, including re-training our employees and implementing additional technical safeguards to prevent incidents of this nature from occurring in the future. We also notified law enforcement about the incident.”
The organization is providing complimentary identity restoration and fraud detection services for impacted individuals for two years, per the notice.
Madera Community Hospital
Incident date: Late May 2025
Affected individuals: 150,810
California-based Madera Community Hospital suffered a data breach in late May 2025 that impacted more than 150,000 individuals.
An unauthorized third party gained access to the organization’s computer network, according to a substitute notice (PDF). However, the notice states a subsequent investigation “did not find definitive proof that the third party acquired files with personal information or protected health information.”
Potentially impacted files include personal information, contact information, login credentials and limited medical information.
Moreover, Madera Community Hospital said in the notice the group behind the breach withdrew its extortion payment demand after learning it was a hospital. “The group told us they did not want to harm patients,” the notice said.
Vanderbilt Health
Incident date: March 23-27
Affected individuals: Not publicly disclosed
Nashville-based Vanderbilt Health identified a data breach in March stemming from an emailed phishing attempt, according to The HIPAA Journal.
Unauthorized access on the employee’s account was detected on March 27, and the individual had access to emails and other documents containing patient information—including medical record numbers, diagnoses and provider names.
The system said the breach was confined to the employee’s email. Electronic medical records, financial information and Social Security numbers were not involved, according to The HIPAA Journal. The amount of affected individuals has not been publicly disclosed.