The California healthcare provider PIH Health experienced a ransomware attack in December 2024. The protected health information of 2,947,264 individuals was ultimately determined to have been compromised.
The Precision Of That Figure Is The Interesting Part
Not "nearly three million" but 2,947,264. Healthcare breach reporting produces exact counts because regulation requires them — every affected individual must be identified in order to be notified.
That is why this sector yields the most reliable affected-population data in this database, and why the healthcare files carry figures the corporate ones do not. Compare the claims-versus-verified problem this desk filed at ADT in 26-0425, where nobody was obliged to count.
And Why It Takes Months
Determining that a specific 2,947,264 people were affected means reconstructing which records were in which system during which window, then deduplicating across sources. The Conduent file at 26-0731 took fifteen months to settle its count.
It is the same tension this desk set out at 26-0403 and 26-0419: notification clocks start before the answer exists, so an initial disclosure is necessarily provisional and a final figure necessarily late.
Graded medium — the figure is well established; the intrusion route and any operational impact are not.
Compiled from public reporting, listed below. No attribution has been established. Corrections: corrections@forensicpost.com.
- Largest healthcare data breaches of 2025HIPAA Journal
- Top 20 healthcare data breaches of 2025Security Magazine