Skip to main content
Patient Protect circular logo mark in purple and white used for site navigationPatient Protect
Quarterly SeriesVol. 1 · ISSN pending

The State of Compliance

Where healthcare risk is concentrating right now.

An ongoing quarterly empirical review of U.S. healthcare breach activity — drawing on OCR, state attorney general filings, CISA advisories, and primary entity disclosures. Each issue tracks vendor concentration, disclosure quality, attack archetypes, and regulatory movement across the quarter.

Latest issue · July 2026

New issueVol. 1 · Issue 2 (Brief) · Q2 2026 · v1.1

One AI vendor held half the verified risk in Q2.

Ten independently verified Q2 disclosures. At least 2.7 million people affected. One AI-enabled utilization-management vendor — Xsolis, Inc. — accounted for 51.7% of the verified population impact. The upstream-concentration pattern established in Q1 persisted through a new AI-vendor channel.

10

Verified disclosures

2.7M+

Affected (floor)

51.7%

From one AI vendor

7/10

At specialty practices

Series archive

Previous issueVol. 1 · Issue 1 · Q1 2026 · v1.3 · April 2026

Q1 2026 Healthcare Breach Review

The inaugural issue — a multi-source empirical review of 207 unique Q1 breaches affecting ~15.9M individuals. Four upstream business-associate incidents accounted for 67.6% of population impact across just 1.9% of the incident count. The multi-source compilation surfaced ~75% more breaches than the late-March OCR-only snapshot.

207

Unique breaches

15.9M

Affected

67.6%

From 4 incidents

+75%

Lift over OCR-only

Publishes October 2026Vol. 1 · Issue 3 · Q3 2026

Q3 2026 Healthcare Breach Review

The Q3 review will extend the multi-source compilation across the July–September 2026 quarter, track whether the AI-vendor-concentration pattern established in Q2 persists, and apply TARF empirically against the quarter's named incidents.

About the series

Empirical, quarterly, multi-source.

Each issue draws on seven authoritative channels — HHS OCR, state attorney general filings, FTC enforcement, CISA advisories, sector news reporting, primary entity disclosures, and dark-web leak-site publication. Records are deduplicated across channels before analysis. Scope filters exclude non-healthcare incidents and non-U.S. jurisdictions. Each issue publishes with version metadata, corrections policy, and open named-incident inventories where feasible.

Series metadata

Publisher
Secure Care Research Institute · Patient Protect LLC
Series
The State of Compliance
Cadence
Quarterly
ISSN
Pending
First issue
April 2026 (Q1 2026)
License
Academic citation with attribution · fair use
Governance
Editorial control resides with SCRI

Follow the series

Receive each new State of Compliance issue when it publishes.

No marketing. Quarterly issues, corrections, and dataset updates.