Open data · CC BY 4.0
Healthcare Breach Dataset.
A citable, versioned dataset of U.S. healthcare data breaches, sourced from HHS Office for Civil Rights authoritative channels and enriched with Patient Protect severity scoring. Ten fields, CSV and JSON. License and attribution metadata included inside the download body so the grant travels with the file.
CC BY 4.0 · HHS OCR sourced · Updated within 24 hours of new-record ingestion
Sample rows
What the data looks like.
A three-row excerpt. The live download contains every HHS OCR filing at the 500-individual threshold plus every OCR resolution agreement and civil money penalty.
| entity_name | reported_date | state | individuals_affected | covered_entity_type | source_type | severity_score |
|---|---|---|---|---|---|---|
| Change Healthcare | 2024-02-21 | TN | 190,000,000 | Business Associate | hhs_breach | 98 |
| Kaiser Foundation Health Plan | 2024-04-12 | CA | 13,400,000 | Health Plan | hhs_breach | 84 |
| MCBS | 2026-07-18 | TX | 1,260,000 | Business Associate | hhs_breach | 72 |
Field dictionary
Ten fields, defined.
Every field emitted in the CC BY 4.0 file. Attack-vector classification and internal metadata are proprietary and are not emitted here.
- id
- string
- Stable per-row identifier.
- event_id
- string
- Groups co-filed rows for one underlying breach event. Dedupe here before summing individuals_affected.
- entity_name
- string
- Reporting entity as filed with HHS OCR.
- reported_date
- ISO date
- Date the breach was reported to HHS OCR.
- state
- 2-letter code
- U.S. state where the reporting entity is located.
- individuals_affected
- integer
- Count of individuals whose PHI was breached (HHS OCR field).
- covered_entity_type
- string
- HHS classification: Healthcare Provider, Health Plan, Healthcare Clearing House, Business Associate.
- source_type
- enum
- hhs_breach (Breach Portal filing) or ocr_enforcement (resolution agreement / CMP).
- severity_score
- integer 0–100
- Patient Protect severity enrichment. Scoring methodology is proprietary; the score itself is CC BY 4.0.
- summary
- string
- Editorial one-line summary of the incident.
License
Creative Commons Attribution 4.0.
The dataset is published under CC BY 4.0. You may reproduce, redistribute, remix, and build upon the data — commercially or otherwise — provided you attribute Patient Protect. License and attribution metadata is written inside the download body so the grant travels with the file when redistributed.
The severity_score integer emitted per row is CC BY 4.0. The methodology that produces it is proprietary.
Citation
Suggested format.
For academic use, add the retrieval date. A permanent DOI via Zenodo is planned post-launch; the citation format will be extended once the deposit is live.
Questions
Frequently asked.
- Can I cite this dataset in academic research or journalism?
- Yes. The dataset is published under Creative Commons Attribution 4.0 International (CC BY 4.0). You may reproduce, redistribute, remix, and build upon it — including for commercial use — provided you credit Patient Protect. A suggested citation format is provided on this page and inside the download body.
- Where does the data come from?
- The citable file is scoped to HHS OCR authoritative sources only: the HHS OCR Breach Portal (filings at the 500-individual threshold) and OCR resolution agreements plus civil money penalties. Non-HHS channels visible on the /breachdash dashboard UI (state AG filings, FTC settlements, CISA advisories, Patient Protect Network, AI-modeled projections) are intentionally excluded from this file — their inclusion would introduce semantic collisions in individuals_affected that a downstream researcher summing the column could not correct for.
- How often is the dataset updated?
- The dataset is served on a 24-hour incremental static regeneration cache. New HHS OCR filings and resolution agreements are ingested continuously; the downloadable file reflects state within 24 hours of new-record ingestion. Historical rows are stable — corrections are versioned in the changelog rather than silently rewritten.
- What does severity_score mean and how is it computed?
- severity_score is an integer 0–100 that ranks each breach by exposure impact. The score is CC BY 4.0 and travels with the row. The scoring methodology — the model that produces the number — is proprietary to Patient Protect and is not documented publicly. Consumers can use the score for downstream ranking without needing to reproduce the model.
- Why is there a preamble of #-prefixed rows in the CSV?
- The first five rows of the CSV are comment lines carrying license, source, attribution, and retrieval-timestamp metadata. This ensures the license grant travels with the file itself if it is redistributed. Most spreadsheet tools tolerate #-prefixed leading rows; you can also filter them explicitly during ingestion.
- Why should I dedupe by event_id before aggregating?
- A single underlying breach event can appear as multiple rows if it triggered both an HHS OCR Breach Portal filing and a later OCR enforcement action. Both rows carry the same individuals_affected count. If you sum the column without deduplicating on event_id, you will double-count the affected population for enforcement-adjacent breaches.
- Is attack-vector classification available in the download?
- No. Attack-vector classification is a proprietary render-time computation used on /breachdash and is intentionally excluded from the CC BY 4.0 file. If your research requires vector labels, contact us directly to discuss a research-use license.
- Can I use the data commercially?
- Yes. CC BY 4.0 permits commercial use, including in for-profit research, journalism, and derivative products. The only requirement is attribution: credit Patient Protect and link to patient-protect.com/breachdash or this landing page.
Part of the HIPAA Foundation · 15+ free tools
See the full collectionTrack the threat landscape
Use the dataset freely for research and journalism. The platform is what a healthcare organization runs against its own environment — configuration monitoring, BAA enforcement, incident response.
Next in the sequence
Breach DashboardA breach dashboard, HIPAA Pulse newsroom, iOS app, and a citable dataset give visibility into attacks, enforcement, and emerging risk.
Cite the dataset. Then close your own gaps.
The dataset is a research artifact. The platform is your program.
Use the dataset freely for research, journalism, and analysis. The Patient Protect platform is what a healthcare organization runs against its own environment — continuous configuration monitoring, BAA scope enforcement, workforce access controls, incident response documentation. From $39/month.
Free tools stay free — no account needed. The 14-day platform trial asks for a card for identity verification; no charge before day 14, cancel any time.
