Skip to main content
Patient Protect circular logo mark in purple and white used for site navigationPatient Protect

Healthcare breach intelligence.

2,198 canonical breach events, reconciled across public source records and analyzed through a transparent event model. HHS OCR breach filings, state attorney general notices, regulatory actions and healthcare security signals — normalized so a filing is not mistaken for an event. No login. No subscription.

Latest dated record: Aug 27, 2026.

No account required · Opens immediately

Healthcare breach intelligence dashboard

Explore the full intelligence system.

What feeds this

How this is counted

Seven public sources. Only two of them describe a breach, and the dashboard never counts the others as one.

  • HHS OCR Breach PortalCounted in breach metrics

    The public OCR breach portal for incidents affecting 500 or more individuals. Smaller breaches carry their own HHS reporting obligations through annual submission and are not counted in this dashboard.

  • State Attorney General NoticesCounted in breach metrics

    State-level breach notifications, which often surface before federal reporting. One breach may be notified to several states; those filings reconcile into one event.

  • OCR Enforcement ActionsNot counted in breach metrics

    Resolution agreements, civil money penalties and corrective action plans. A regulatory action, not a breach report — never counted as one.

  • FTC Enforcement ActionsNot counted in breach metrics

    Proceedings against entities handling health data outside HIPAA jurisdiction. Held separately from HIPAA breach reporting.

  • CISA Vulnerability AdvisoriesNot counted in breach metrics

    Critical infrastructure advisories relevant to healthcare systems. Context about risk, not a record that a breach occurred.

  • Patient Protect NetworkNot counted in breach metrics

    Observations from healthcare security professionals across the Patient Protect network. Held as community signals.

  • Modeled Threat SignalsNot counted in breach metrics

    Derived indicators, not reported incidents. Labeled as modeled and excluded from every breach metric.

Need the HHS OCR records?

Download the dataset or query the API. One row is one source record as published — an OCR breach filing or an enforcement action, not a reconciled breach event — and every row states its record class, because most of them are enforcement actions rather than breach reports.

It is the HHS channel only. The state attorney general, FTC, CISA, network and modeled sources you see elsewhere on this dashboard are not in the file, and its counts will not reproduce the figures above — those come from the canonical model, which reconciles several sources into single events.

You have seen what happened to them.

Every event above was reported by an organization that did not expect to be in the record. The same questions that decided those outcomes — where protected health information actually flows, which vendors hold it, what a regulator would ask first — have answers at your practice today, whether or not anyone has written them down.

The Exposure Diagnostic walks the same ground the filings above describe, and tells you where yours stands. It takes a few minutes, needs no account, and ends with what to fix first.

State-level intelligence

Find your state.

Canonical breach event counts, incident mechanisms, the organizations behind them, notification deadlines and AG reporting requirements — for every US state.

Open dataset

Healthcare Breach Dataset — free, citable, CC BY 4.0.

The full breach corpus is available as a structured download for researchers, journalists, compliance teams, and AI search engines. Source records from the HHS OCR Breach Portal and OCR enforcement actions — not canonical events. Refreshed daily.

Two-layer license

Dataset (CSV/JSON) published under CC BY 4.0. Underlying breach records sourced from the HHS OCR Breach Portal.

Dashboard interface, visualizations, and scoring methodology are proprietary to Patient Protect LLC.

Cite (current/live): Patient Protect. Healthcare Data Breach Dataset. patient-protect.com/breachdash.

Cite (academic / permanent DOI): Perrin, A. (2025). Supplementary data for ‘The Economics of ePHI Exposure’ (v1.0.0) [Data set]. Zenodo. doi.org/10.5281/zenodo.15446488

Includes: record class, source type, entity name, state, individuals affected, breach submission date, enforcement action date, the upstream grouping identifier and a summary. Most rows are regulatory actions rather than breach filings, so filter on record class before counting breaches.

Regulatory foundation

Every event, anchored to the CFR.

The dashboard categorizes each event against the HIPAA Security Rule sections OCR actually cites in enforcement, so a filing surfaces the safeguard theme alongside the record. These are patterns in public filings, not a compliance assessment of any organization.

  • 45 CFR §164.306

    General requirements

    The umbrella provision — confidentiality, integrity, and availability of all ePHI.

  • 45 CFR §164.308

    Administrative safeguards

    Risk analysis, workforce access, sanction policy, information system activity review, contingency planning.

  • 45 CFR §164.310

    Physical safeguards

    Facility access, workstation use, device and media controls.

  • 45 CFR §164.312

    Technical safeguards

    Access control, audit logging, integrity controls, transmission security.

  • 45 CFR §164.404–410

    Breach notification

    Individual, media, and Secretary notification rules — the timelines every filing in this dataset is measured against.

This page is the sector. Inside the platform it becomes your office.

Everything above is public and free, and it answers a question about other practices. The same intelligence runs inside Patient Protect against a practice it knows things about, and that changes what it can say.

More sources than this page shows.
The in-platform module aggregates HHS OCR breach reports, state attorney-general notifications, OCR enforcement actions, FTC actions and CISA advisories, alongside modeled breaches and reports shared by other practices on the network. Daily, not live — OCR does not publish continuously and neither do we pretend to.
Two readings, and only one of them is about you.
Current Threat Level is the external reading for your region, and it is the same for every practice near you. Office Threat blends that with your own Security Score, so it moves when your practice does. A sector at elevated risk means something different for an office that has closed its findings than for one that has not, and that difference is the number worth watching.
The network can surface things ahead of the filings.
Regulatory filings often appear well after the event. Practices on Patient Protect can share an incident anonymously from their own event log, and those reports can surface a relevant event before it shows up in regulatory or other public reporting. The sharing toggle is off unless a practice turns it on.
Intelligence about the sector, not monitoring of your network.
Worth being exact, because this category oversells itself routinely. This reads public and network sources and blends them with what the platform knows about your compliance state. It does not watch your workstations, your network or your backups, and nothing hosted elsewhere could.

FAQ

Common questions about breach intelligence.

Is this dashboard really free with no account required?

Yes. No login, no subscription, no trial period. Open it directly at patient-protect.com/breachdash. Every destination is accessible immediately.

Where does this data come from?

Seven sources: the HHS OCR Breach Portal, State Attorney General notifications from all 50 states, OCR Enforcement actions, FTC enforcement actions, CISA vulnerability advisories, Patient Protect network intelligence, and AI-modeled threat signals. Each source is identified in the dashboard by color code.

How current is the data?

Updated daily. HHS OCR and State AG data is ingested on a daily schedule. The timestamp in the dashboard header shows the exact last update time for each source.

Can I export data from the dashboard?

Yes. The Intelligence Explorer exports to CSV, and the export carries its own context — the date, the scope in force, the filters applied, and the canonical model version — so the file still explains itself months later.

How is this different from the HHS OCR breach portal?

The OCR portal lists filings. This dashboard reconciles filings into events: when the same breach is notified to HHS and to several state attorneys general, the portal shows several rows and this shows one event carrying all of them. It also brings in state attorney general notices, OCR and FTC enforcement actions, and CISA advisories, each kept in its own class so an enforcement action is never counted as a breach.

Why does breach intelligence matter for my practice?

Breach reporting is public, but it is published as filings rather than events, which makes it hard to tell how often something actually happened. Reconciling filings into events shows which incident mechanisms and entity types recur — useful context when deciding where to put limited security effort. Patient Protect’s own research on attacks against independent providers is published separately in the Research section.

What are modeled breaches?

Modeled signals are derived indicators, not reported incidents. They are held in their own record class and are excluded from every breach metric on this dashboard — they never contribute to the canonical event count or the reported-affected total. They exist as context alongside reported data, clearly labeled as modeled.

Is this included in my Patient Protect subscription?

The breach intelligence dashboard is free and open to everyone — no subscription required. Patient Protect subscribers get additional capabilities including practice-specific risk scoring, alerts on their own account, vendor and BAA records kept current, and integration with their compliance workflow.

Data Disclaimer+

The information provided through this dashboard is aggregated from publicly available sources, including but not limited to the U.S. Department of Health and Human Services (HHS) Office for Civil Rights (OCR) Breach Portal, OCR Resolution Agreements, Federal Trade Commission (FTC) health breach notifications, state Attorney General breach notification databases, the Cybersecurity and Infrastructure Security Agency (CISA) advisories, and curated news reporting. Certain records are algorithmically modeled or AI-derived from news sources and are clearly labeled as such; these “modeled” entries represent projections based on public reporting and have not been confirmed by any regulatory authority.

This data is provided “as-is” for informational and educational purposes only and does not constitute legal, compliance, medical, financial, or professional advice. Patient Protect makes no representations or warranties, express or implied, regarding the accuracy, completeness, timeliness, reliability, or suitability of the data for any particular purpose. Source records may contain errors, omissions, delays, or inaccuracies originating from the underlying publishers, and may be updated, corrected, or withdrawn at any time without notice.

Inclusion of any organization, individual, incident, or enforcement action in this dataset does not imply wrongdoing, liability, guilt, non-compliance, or any adverse determination. References to specific entities reflect publicly reported information and should not be interpreted as an endorsement, accusation, or characterization by Patient Protect.

Users are solely responsible for independently verifying any information before relying on it for decision-making, regulatory reporting, business operations, journalism, research, or legal proceedings. Patient Protect, its affiliates, officers, employees, contributors, and data providers disclaim all liability for any direct, indirect, incidental, consequential, or punitive damages arising from the use of, reliance on, or inability to use this data.

Use of this dashboard is subject to applicable laws, the terms of service of original data sources, and Patient Protect's Terms of Use. Redistribution, resale, or commercial use may require separate authorization.

If this data hits close to home

Response guides for when it happens to your practice.

HIPAA Pulse

Get the breaches that matter to your practice — delivered every other Wednesday.

HIPAA Pulse covers the regulatory, enforcement and healthcare-security developments that actually matter to an independent practice — sourced, verified and translated into what to review. Free, no spam, unsubscribe anytime.

Every other Wednesday · Free · Unsubscribe anytime

Latest verified Responses

Where the source record supports an operational takeaway, the incident gets a Response. Most do not.

View HIPAA Response

Corrections & Updates

Healthcare security data changes as investigations progress, vendors update systems, and laws and guidance evolve. If you see something outdated, incomplete, or incorrect — or have newer source material — we’d appreciate hearing from you.

Submit a correction →

Part of the HIPAA Foundation · Free tools & resources

See the full collection
TrackFree · proprietary

Track the threat landscape

The dashboard reports what happened across the sector. The platform works from what you have recorded about your own practice — vendors and their agreements, workforce and access, policies and the evidence behind them. It does not reach into your network, your devices or your other vendors' systems.

Next in the sequence

Healthcare Breach Dataset

The Breach Dashboard, HIPAA Response, Signal, and the open dataset provide different views of the same healthcare compliance and security landscape.