Healthcare organizations experienced a significant number of large-scale data breaches in 2025, with nearly 57 million individuals affected and at least 642 incidents reported to the Department of Health and Human Services (HHS) Office for Civil Rights. While this represents a notable decrease from the previous year, the sector continues to face substantial risks, with several high-profile breaches exposing sensitive patient information. Notable incidents include breaches at major healthcare providers and patient information portals, with some cases resulting in legal settlements and direct financial compensation to affected individuals.
Among the most impactful breaches, Consulting Radiologists Ltd. agreed to a $2.2 million settlement after a 2024 breach exposed the personal and medical data of approximately 512,000 people. Additionally, New Zealand's ManageMyHealth platform reported a breach potentially affecting over 108,000 users, highlighting the global nature of healthcare data security challenges. These incidents underscore the ongoing threat to patient privacy and the financial and reputational consequences for healthcare organizations that fail to adequately protect sensitive information.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
6 events from the most recent confirmed update back to the earliest known activity.
By January 2026, Consulting Radiologists had agreed to a $2.2 million settlement to resolve the class action over its 2024 breach. The settlement addressed claims tied to the exposure of highly confidential information of 512,000 people.
By December 31, 2025, nearly 57 million individuals were known to be affected by healthcare data breaches reported or believed to have occurred in 2025. At least 642 breaches involving 500 or more individuals were listed on the HHS OCR breach portal.
On Wednesday before the January 2, 2026 report, ManageMyHealth disclosed a breach affecting at least 108,000 users, or about 6% to 7% of its 1.8 million registered users. The New Zealand patient portal said it was notifying affected customers within 48 hours about the data accessed.
In November 2024, a class action lawsuit was filed against Consulting Radiologists alleging it failed to adequately protect patient data following the breach. The suit sought relief for the exposure of sensitive information of roughly 512,000 people.
In April 2024, the LockBit ransomware group claimed the Consulting Radiologists incident. The claim linked the earlier breach to a known ransomware operation.
In February 2024, Consulting Radiologists Ltd. experienced a breach exposing highly sensitive personal, medical, and health insurance information. The incident ultimately affected about 512,000 individuals.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
3 references tracked. Mallory keeps watching after this page renders.
hipaajournal.com
Open sourcedatabreaches.net
Open sourcedatabreaches.net
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.