A five-provider practice we work with received a letter this month from its transcription vendor. The vendor had been breached in November, the practice's patients were among those affected, and the vendor wanted to know whether the practice would handle the patient notifications or authorize the vendor to do it. The practice manager's first question was "Are we the ones who have to report this?" The answer was yes. The second question was "How often does this actually happen?" That one has a number.

The year-end tallies of 2025 healthcare data breaches were published in the last few days, drawing on the HHS Office for Civil Rights breach portal, the public list of every breach of 500 or more individuals' protected health information. The count for 2025 stands at 710 large breaches, affecting about 61.5 million people. That is a 4.3 percent drop in the number of breaches from 2024 and a very large drop in the number of people affected, because 2024 included the Change Healthcare incident and its roughly 190 million records. Strip that out and 2025 looks like every other recent year: a breach reported to OCR roughly twice a day, most of them hacking, and the majority reported by providers.

A glossary line: under the HIPAA Breach Notification Rule, a breach affecting 500 or more individuals must be reported to OCR and to affected individuals within 60 days of discovery, and to prominent media outlets in the state. Breaches under 500 are reported to OCR annually, within 60 days of the end of the calendar year in which they were discovered, which means the small-breach reports for 2025 are due by March 1, 2026.

Key takeaways

  • 2025 closed with 710 large breaches on the OCR portal and about 61.5 million individuals affected, with a median breach size around 4,000 records, which is practice-sized.
  • Healthcare providers reported 57.5 percent of the breaches; business associates reported 35.8 percent, but their incidents affect many providers at once.
  • Hacking remains the dominant cause, and unauthorized access or disclosure incidents grew about 17 percent year over year.
  • The federal shutdown in late 2025 paused portal additions for 43 days, so the final 2025 count will rise as late reports post.
  • The controls that address most of these incidents are not expensive: multifactor authentication, phishing training, patching, offline backups and a vendor inventory.

2025 healthcare data breaches by the numbers

Measure2025Note
Large breaches reported (500+ individuals)710Down 4.3 percent from 2024; 2023 remains the record year by count
Individuals affectedAbout 61.5 millionDown sharply from 289 million in 2024, a year dominated by one clearinghouse breach
Average breach sizeAbout 86,700 individualsMedian about 4,000, which describes a typical medical practice or small clinic
Reported by healthcare providers57.5 percentPractices, hospitals, clinics, pharmacies
Reported by business associates35.8 percentVendors: billing companies, transcription, IT hosts, software
Reported by health plans6.5 percentClearinghouses reported 0.3 percent
Largest incidentsAflac (13.9 million), Yale New Haven Health (5.6 million), Episource (5.4 million)All classified as hacking

Two cautions on the numbers. The portal count for 2025 will keep rising through the spring as late reports post, and the 43-day federal shutdown in the fall delayed portal additions, so the final tally will be higher than the number published this month. Even so, the shape of the year is clear.

The median is the number we want physicians to notice. Half of the year's large breaches affected fewer than about 4,000 people. Those are not hospital systems. They are practices, small clinics, dental offices, behavioral health providers and the small vendors that serve them. The three giant incidents make the headlines; the four hundred small ones are the ones that look like you.

How the breaches happened

Hacking and IT incidents dominate, as they have every year since 2019. Within hacking, the year-end reporting notes ransomware at record levels across all sectors, with healthcare accounting for roughly 22 percent of ransomware attacks. The entry point in a practice-sized incident is nearly always one of three things: a phishing email that captured a staff member's credentials, a remote access tool or VPN without multifactor authentication, or an unpatched device exposed to the internet.

Unauthorized access and disclosure, the second category, grew about 17 percent over 2024. This is the category of misdirected faxes, wrong-patient portal messages, employees snooping in records, and paper sent to the wrong address. It is also the category most within a practice's control, and the one most often reported as a small breach rather than a large one.

Then there is the business associate problem. Business associates reported more than a third of the incidents, and a single vendor breach can pull in dozens or hundreds of practices as the covered entities responsible for notifying their own patients. The practice with the transcription vendor letter is living this: the vendor's breach is the practice's breach for notification purposes, and the practice needs the business associate agreement in hand to know who does what.

What OCR did with it

OCR's enforcement in 2025 and into 2026 has centered on the Risk Analysis Initiative, a run of settlements in which the common finding was that the entity had never performed an accurate and thorough risk analysis of its electronic protected health information, as the Security Rule has required since 2005. The settlements involve providers of every size, including small ones, and the amounts are smaller than the headline penalties of years past but come with two-year corrective action plans and monitoring.

We think the message is direct. OCR is not asking small practices to have enterprise security. It is asking them to have done the risk analysis, written down what they found, and acted on it. In every settlement we have read, the entity could not produce that document. That is the first thing OCR asks for after a breach report, and a practice that has it is in a different conversation from one that doesn't.

The controls that would have stopped most of it

Multifactor authentication on every account that can reach patient data: email, the EHR, the practice management system, remote access, the clearinghouse portal. Most phishing-based breaches end at this control, because a stolen password is not enough. Turn it on for everyone, including the physicians who object.

Phishing training that repeats. One annual slide deck does not change behavior. Short, frequent simulated phishing with immediate feedback does, and it is inexpensive. Track the click rate by quarter.

Patching and end-of-life replacement. Every device on the network that can't receive security updates is an entry point. Make a list. The practice manager should be able to say when each server, workstation, router and firewall was last patched.

Backups that ransomware can't reach. Offline or immutable backups, tested by actually restoring a file, are the difference between a bad week and a closed practice. Ask your IT vendor to demonstrate a restore, not describe one.

A vendor inventory with a business associate agreement for each one. Know every company that touches patient data, confirm the agreement is signed, and know what it says about breach notification and who pays for it. Our technology team hears from practices every month that discover a vendor, often the website or online forms provider, was holding patient data with no agreement at all.

Questions we hear

Our vendor was breached. Do we have to notify our patients, or do they?

The covered entity, meaning the practice, is responsible for notifying its patients, OCR and, if 500 or more residents of a state are affected, the media. The business associate agreement can delegate the work to the vendor, and many vendors will do it, but the obligation and the deadline remain the practice's. Read the agreement and get the delegation in writing.

We had two small incidents last year, under 500 people each. What do we owe OCR?

Breaches affecting fewer than 500 individuals discovered in 2025 must be reported to OCR through the breach portal no later than 60 days after the end of the calendar year, which is March 1, 2026. Patients still had to be notified within 60 days of discovery at the time. Report each incident separately.

Is cyber insurance a substitute for any of this?

No, and insurers increasingly require the same controls before they will write or renew a policy. Applications now ask specifically about multifactor authentication, backups and training, and a claim can be denied if the application was inaccurate. Treat the insurance application as a checklist you must actually meet.

What to do this week

  1. Confirm whether you had any breach under 500 individuals in 2025 and calendar the March 1 portal report.
  2. List every vendor that touches patient data and check that a signed business associate agreement exists for each.
  3. Turn on multifactor authentication for every account that can reach patient data, starting with email.
  4. Ask your IT vendor to perform and document a test restore from backup.
  5. Find your most recent written security risk analysis; if you can't, that is the project for this quarter.