Based on the current data from a federal data breach portal, from January 1 to April 30, 2026, 252 large healthcare data breaches have been reported to HHS’ Office for Civil Rights, according to HIPAA Journal. Fierce Healthcare is tracking data breaches across healthcare organizations in 2026. Stay up-to-date with this tracker for the latest updates, and email Cailey Gleeson at [email protected] with any news.
Lifespan Physician Group
Incident date: Dec. 15-16, 2025
Affected individuals: 311,760
Lifespan Physician Group of Massachusetts, which does business as Brown Health Medical Group, reported on July 16 a data breach impacting more than 311,000 patients, a U.S. Department of Health and Human Services (HHS) Office of Civil Rights database shows.
The breach occurred at its Hawthorn location on Dec. 15-16 through a “historic file server,” and did not impact its electronic health record (EHR) system, a substitute notice (PDF) said.
The organization determined the scope of impacted information on June 22, which includes demographic information; health insurance information; medical information; billing, claims and payment information; financial account information; Social Security numbers and more.
“We are committed to maintaining the privacy and security of personal information and take this incident very seriously,” the organization said. “We took, and will continue to take, appropriate steps to address this incident, including re-training our employees and implementing additional technical safeguards to prevent incidents of this nature from occurring in the future. We also notified law enforcement about the incident.”
The organization is providing complimentary identity restoration and fraud detection services for impacted individuals for two years, per the notice.
Madera Community Hospital
Incident date: Late May 2025
Affected individuals: 150,810
California-based Madera Community Hospital suffered a data breach in late May 2025 that impacted more than 150,000 individuals.
An unauthorized third party gained access to the organization’s computer network, according to a substitute notice (PDF). However, the notice states a subsequent investigation “did not find definitive proof that the third party acquired files with personal information or protected health information.”
Potentially impacted files include personal information, contact information, login credentials and limited medical information.
Moreover, Madera Community Hospital said in the notice the group behind the breach withdrew its extortion payment demand after learning it was a hospital. “The group told us they did not want to harm patients,” the notice said.
Vanderbilt Health
Incident date: March 23-27
Affected individuals: Not publicly disclosed
Nashville-based Vanderbilt Health identified a data breach in March stemming from an emailed phishing attempt, according to The HIPAA Journal.
Unauthorized access on the employee’s account was detected on March 27, and the individual had access to emails and other documents containing patient information—including medical record numbers, diagnoses and provider names.
The system said the breach was confined to the employee’s email. Electronic medical records, financial information and Social Security numbers were not involved, according to The HIPAA Journal. The amount of affected individuals has not been publicly disclosed.
