Aflac confirmed that protected health information belonging to at least 13,924,906 individuals was exposed or stolen, making it the largest confirmed healthcare data breach reported in 2025. Reporting links the incident to the social-engineering campaign recorded across this corpus.
The Largest Health Breach Of The Year Was Not At A Health Provider
The corpus filed at 25-0801 that the biggest healthcare exposure of the year happened at a company with no patients, and treated it as a pattern rather than an observation.
This is the same finding with a bigger number and a named company. Yale New Haven, a large regional health system, reported 5,556,702 at 25-0308. An insurance company reported nearly fourteen million.
A provider holds the patients it treated. A supplemental insurer holds the claim records of everyone it covered across every employer group — which is a wider population, assembled for adjudication rather than for care.
And It Sits In The Wrong Regulatory Frame
The healthcare register at 25-0630 exists because US health organisations are compelled to file. That obligation follows the data class, which is why this incident appears in healthcare breach tables at all.
What does not follow the data class is the security supervision — the argument at 25-0601, where an insurer’s regulator examines solvency and conduct rather than the third-party platforms its sales estate runs on.
The reporting duty tracks the sensitivity of the record. The security expectation tracks the sector of the company. For an insurer holding health data those two point in different directions.
Supplemental Insurance Data Is Unusually Revealing
Aflac’s products pay on diagnosis of specific conditions. A claim record therefore states not that somebody sought care but that they were diagnosed with something the policy names — cancer, a critical illness, an accident with defined injuries.
That is a more directly interpretable health disclosure than most clinical records, and the permanence argument at 25-1010 applies in full. There is no equivalent of a credit freeze for a leaked diagnosis.
Compiled from public reporting and company disclosure, listed below. The figure is the company’s confirmed count as reported and is described as a minimum. Attribution follows published research assessments. Corrections: corrections@forensicpost.com.