Desk live·
ForensicPost
Breaches/Analysis/File 25-0630

US Healthcare Reported 343 Breaches Covering 57 Million Records in Six Months

US healthcare organisations reported 343 breaches to federal regulators in the first half of 2025, covering nearly 57 million records. The reporting regime is why we can say that at all.

Constructed geometry · not a chart of case data
JurisdictionUSAthe affected organisation’s jurisdiction, not the actor’s suspected origin
TargetUS healthcare sector
ActorMultiple
D. Kennedy11 min readConfidence: high2 sources reviewed

In the first six months of 2025, 343 data breaches were reported to the US Department of Health and Human Services, with the largest incidents accounting for close to 57 million records.

Healthcare Is The Only Sector With A Usable Public Register

Every one of those 343 is a mandatory filing with a named organisation, an affected count and a date. No other sector in this database produces anything comparable.

It is why the healthcare files here carry exact figures — 2,947,264 at PIH Health in 25-0210, 5,556,702 at Yale New Haven in 25-0308 — while corporate files carry ranges, claims and disputes. The difference is not that healthcare is better measured; it is that healthcare is compelled to measure.

Which Makes The Sector Look Worse Than It Is

Healthcare consistently tops annual breach tables. Some of that is genuine — the sector combines sensitive data with thin capacity, as this desk filed at 26-0426.

Some of it is purely an artefact of visibility. A retailer or a manufacturer suffering an equivalent compromise may face no comparable obligation to enumerate and publish. Comparing sectors using breach counts compares reporting regimes as much as security postures.

The Argument For Extending It

This desk has repeatedly hit the absence of comparable data — the availability failures nobody files at 26-0209, the unmeasured supplier incidents at 26-0426, the uncounted total at 26-0307.

The healthcare register demonstrates that a mandatory, public, per-incident register with affected counts is administratively possible. Whether it should exist elsewhere is a policy question; whether it could is settled.

How we reported this

This is an analysis file built on published summaries of regulatory filings, listed below. Figures are as reported by the analysts summarising the federal portal. Corrections: corrections@forensicpost.com.

Sources
  1. Nearly 57 million records exposed: what the biggest health care breaches of 2025 revealACA International
  2. Healthcare data breach 2025 statisticsCobalt
D. Kennedy
Identity and access reporter. Former DFIR consultant. Signal on request.
// the chain of custody — tuesdays

Get the next file first.

One incident a week, taken apart properly. Logs, timelines, and what the filing left out.

PGP-signed edition · no tracking pixels · one-click unsubscribe
© 2026 ForensicPost Media · the desk · newsletter · searchGlossary