US healthcare organizations reported unusually low numbers of large HIPAA breaches in late 2025, with 41 incidents affecting 500+ individuals logged for December 2025 in the HHS OCR breach portal. Reporting volumes for September–December averaged ~40.75 large breaches per month versus ~66.5 in the prior four months, and 2025 totals stood at 697 breaches (a reported ~6% decrease from 2024), though the count was expected to rise as additional incidents are added. A key factor cited for the apparent decline was a 43-day US government shutdown that furloughed most HHS staff and likely created a backlog in posting breach reports to the OCR portal, potentially suppressing late-2025 totals until processing is completed.
Separately, a VA Office of Inspector General review found a privacy and security compliance failure within the Veterans Health Administration’s national cancer testing program tied to a collaborative research effort. The OIG reported that in 2022 a VHA research director created and shared a file containing electronic health record reports and a “significant amount” of protected health information (PHI) with non-VHA investigators without institutional review board approval or de-identification, and that required audit logs for secure ePHI management were missing. The OIG noted delays in reporting and inadequate early mitigation, and issued six recommendations that the VA agreed to implement, including removing PHI from shared materials, clarifying research processes, and improving training.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
8 events from the most recent confirmed update back to the earliest known activity.
In February 2026, HIPAA-regulated entities reported 63 healthcare data breaches affecting 500 or more individuals to the HHS Office for Civil Rights breach portal, exposing or impermissibly disclosing at least 8,134,378 individuals' protected health information. The month's totals were driven by major hacking incidents at TriZetto Provider Solutions and QualDerm Partners, plus a large ApolloMD Business Services ransomware attack attributed to Qilin.
At a later stage, the VA's mitigation plan was updated to remove PHI, clarify research processes, and improve staff training. The VA also agreed to implement six recommendations from the Office of Inspector General.
In December 2025, the HHS Office for Civil Rights announced a HIPAA enforcement settlement with Concentra, Inc. over an alleged Right of Access violation. The settlement was highlighted alongside monthly healthcare breach reporting.
Among the largest healthcare breaches reported for December 2025 were a hacking incident at Fieldtex Products in New York and a ransomware attack on AllerVie Health in Texas. The AllerVie attack was claimed by the Anubis ransomware group.
In December 2025, HIPAA-regulated entities reported 41 healthcare data breaches affecting 500 or more individuals to the HHS Office for Civil Rights breach portal. The listed incidents affected 345,564 people, the lowest monthly total since December 2017.
During 2025, the New York Attorney General reported a settlement with Orthopedics NY LLP (OrthoNY) tied to alleged cybersecurity failures. The action was noted in the context of broader healthcare privacy and security enforcement developments.
After the 2022 data-sharing incident, investigators found delays in reporting the issue, failures to consult required experts, and initial mitigation steps that did not address privacy risks. Missing audit logs also meant secure management of electronic PHI could not be fully tracked.
In 2022, a Veterans Health Administration research director created and shared a file containing electronic health record reports and significant protected health information with non-VHA investigators. The sharing occurred without institutional review board approval or de-identification, contrary to HIPAA privacy and security requirements.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
3 references tracked. Mallory keeps watching after this page renders.
hipaajournal.com
Open sourcehipaajournal.com
Open sourcescworld.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.