Skip to main content
Patient Protect circular logo mark in purple and white used for site navigationPatient Protect

Open data · CC BY 4.0

Healthcare Breach Dataset.

A citable, versioned dataset of U.S. healthcare data breaches, sourced from HHS Office for Civil Rights authoritative channels and enriched with Patient Protect severity scoring. Ten fields, CSV and JSON. License and attribution metadata included inside the download body so the grant travels with the file.

CC BY 4.0 · HHS OCR sourced · Updated within 24 hours of new-record ingestion

Sample rows

What the data looks like.

A three-row excerpt. The live download contains every HHS OCR filing at the 500-individual threshold plus every OCR resolution agreement and civil money penalty.

entity_namereported_datestateindividuals_affectedcovered_entity_typesource_typeseverity_score
Change Healthcare2024-02-21TN190,000,000Business Associatehhs_breach98
Kaiser Foundation Health Plan2024-04-12CA13,400,000Health Planhhs_breach84
MCBS2026-07-18TX1,260,000Business Associatehhs_breach72

Field dictionary

Ten fields, defined.

Every field emitted in the CC BY 4.0 file. Attack-vector classification and internal metadata are proprietary and are not emitted here.

id
string
Stable per-row identifier.
event_id
string
Groups co-filed rows for one underlying breach event. Dedupe here before summing individuals_affected.
entity_name
string
Reporting entity as filed with HHS OCR.
reported_date
ISO date
Date the breach was reported to HHS OCR.
state
2-letter code
U.S. state where the reporting entity is located.
individuals_affected
integer
Count of individuals whose PHI was breached (HHS OCR field).
covered_entity_type
string
HHS classification: Healthcare Provider, Health Plan, Healthcare Clearing House, Business Associate.
source_type
enum
hhs_breach (Breach Portal filing) or ocr_enforcement (resolution agreement / CMP).
severity_score
integer 0–100
Patient Protect severity enrichment. Scoring methodology is proprietary; the score itself is CC BY 4.0.
summary
string
Editorial one-line summary of the incident.

License

Creative Commons Attribution 4.0.

The dataset is published under CC BY 4.0. You may reproduce, redistribute, remix, and build upon the data — commercially or otherwise — provided you attribute Patient Protect. License and attribution metadata is written inside the download body so the grant travels with the file when redistributed.

The severity_score integer emitted per row is CC BY 4.0. The methodology that produces it is proprietary.

Citation

Suggested format.

Patient Protect. (2026). Healthcare Breach Dataset. CC BY 4.0. Retrieved from https://patient-protect.com/breach-dataset

For academic use, add the retrieval date. A permanent DOI via Zenodo is planned post-launch; the citation format will be extended once the deposit is live.

Questions

Frequently asked.

Can I cite this dataset in academic research or journalism?
Yes. The dataset is published under Creative Commons Attribution 4.0 International (CC BY 4.0). You may reproduce, redistribute, remix, and build upon it — including for commercial use — provided you credit Patient Protect. A suggested citation format is provided on this page and inside the download body.
Where does the data come from?
The citable file is scoped to HHS OCR authoritative sources only: the HHS OCR Breach Portal (filings at the 500-individual threshold) and OCR resolution agreements plus civil money penalties. Non-HHS channels visible on the /breachdash dashboard UI (state AG filings, FTC settlements, CISA advisories, Patient Protect Network, AI-modeled projections) are intentionally excluded from this file — their inclusion would introduce semantic collisions in individuals_affected that a downstream researcher summing the column could not correct for.
How often is the dataset updated?
The dataset is served on a 24-hour incremental static regeneration cache. New HHS OCR filings and resolution agreements are ingested continuously; the downloadable file reflects state within 24 hours of new-record ingestion. Historical rows are stable — corrections are versioned in the changelog rather than silently rewritten.
What does severity_score mean and how is it computed?
severity_score is an integer 0–100 that ranks each breach by exposure impact. The score is CC BY 4.0 and travels with the row. The scoring methodology — the model that produces the number — is proprietary to Patient Protect and is not documented publicly. Consumers can use the score for downstream ranking without needing to reproduce the model.
Why is there a preamble of #-prefixed rows in the CSV?
The first five rows of the CSV are comment lines carrying license, source, attribution, and retrieval-timestamp metadata. This ensures the license grant travels with the file itself if it is redistributed. Most spreadsheet tools tolerate #-prefixed leading rows; you can also filter them explicitly during ingestion.
Why should I dedupe by event_id before aggregating?
A single underlying breach event can appear as multiple rows if it triggered both an HHS OCR Breach Portal filing and a later OCR enforcement action. Both rows carry the same individuals_affected count. If you sum the column without deduplicating on event_id, you will double-count the affected population for enforcement-adjacent breaches.
Is attack-vector classification available in the download?
No. Attack-vector classification is a proprietary render-time computation used on /breachdash and is intentionally excluded from the CC BY 4.0 file. If your research requires vector labels, contact us directly to discuss a research-use license.
Can I use the data commercially?
Yes. CC BY 4.0 permits commercial use, including in for-profit research, journalism, and derivative products. The only requirement is attribution: credit Patient Protect and link to patient-protect.com/breachdash or this landing page.

Part of the HIPAA Foundation · 15+ free tools

See the full collection
TrackCC BY 4.0

Track the threat landscape

Use the dataset freely for research and journalism. The platform is what a healthcare organization runs against its own environment — configuration monitoring, BAA enforcement, incident response.

Next in the sequence

Breach Dashboard

A breach dashboard, HIPAA Pulse newsroom, iOS app, and a citable dataset give visibility into attacks, enforcement, and emerging risk.

Cite the dataset. Then close your own gaps.

The dataset is a research artifact. The platform is your program.

Use the dataset freely for research, journalism, and analysis. The Patient Protect platform is what a healthcare organization runs against its own environment — continuous configuration monitoring, BAA scope enforcement, workforce access controls, incident response documentation. From $39/month.

Free tools stay free — no account needed. The 14-day platform trial asks for a card for identity verification; no charge before day 14, cancel any time.