The State of Compliance
Where healthcare risk is concentrating right now.
An ongoing quarterly empirical review of U.S. healthcare breach activity — drawing on OCR, state attorney general filings, CISA advisories, and primary entity disclosures. Each issue tracks vendor concentration, disclosure quality, attack archetypes, and regulatory movement across the quarter.
Latest issue · July 2026
One AI vendor held half the verified risk in Q2.
Ten independently verified Q2 disclosures. At least 2.7 million people affected. One AI-enabled utilization-management vendor — Xsolis, Inc. — accounted for 51.7% of the verified population impact. The upstream-concentration pattern established in Q1 persisted through a new AI-vendor channel.
10
Verified disclosures
2.7M+
Affected (floor)
51.7%
From one AI vendor
7/10
At specialty practices
Series archive
Q1 2026 Healthcare Breach Review
The inaugural issue — a multi-source empirical review of 207 unique Q1 breaches affecting ~15.9M individuals. Four upstream business-associate incidents accounted for 67.6% of population impact across just 1.9% of the incident count. The multi-source compilation surfaced ~75% more breaches than the late-March OCR-only snapshot.
207
Unique breaches
15.9M
Affected
67.6%
From 4 incidents
+75%
Lift over OCR-only
Q3 2026 Healthcare Breach Review
The Q3 review will extend the multi-source compilation across the July–September 2026 quarter, track whether the AI-vendor-concentration pattern established in Q2 persists, and apply TARF empirically against the quarter's named incidents.
About the series
Empirical, quarterly, multi-source.
Each issue draws on seven authoritative channels — HHS OCR, state attorney general filings, FTC enforcement, CISA advisories, sector news reporting, primary entity disclosures, and dark-web leak-site publication. Records are deduplicated across channels before analysis. Scope filters exclude non-healthcare incidents and non-U.S. jurisdictions. Each issue publishes with version metadata, corrections policy, and open named-incident inventories where feasible.
Series metadata
- Publisher
- Secure Care Research Institute · Patient Protect LLC
- Series
- The State of Compliance
- Cadence
- Quarterly
- ISSN
- Pending
- First issue
- April 2026 (Q1 2026)
- License
- Academic citation with attribution · fair use
- Governance
- Editorial control resides with SCRI
Follow the series
Receive each new State of Compliance issue when it publishes.
No marketing. Quarterly issues, corrections, and dataset updates.
