In the first six months of 2025, 343 data breaches were reported to the US Department of Health and Human Services, with the largest incidents accounting for close to 57 million records.
Healthcare Is The Only Sector With A Usable Public Register
Every one of those 343 is a mandatory filing with a named organisation, an affected count and a date. No other sector in this database produces anything comparable.
It is why the healthcare files here carry exact figures — 2,947,264 at PIH Health in 25-0210, 5,556,702 at Yale New Haven in 25-0308 — while corporate files carry ranges, claims and disputes. The difference is not that healthcare is better measured; it is that healthcare is compelled to measure.
Which Makes The Sector Look Worse Than It Is
Healthcare consistently tops annual breach tables. Some of that is genuine — the sector combines sensitive data with thin capacity, as this desk filed at 26-0426.
Some of it is purely an artefact of visibility. A retailer or a manufacturer suffering an equivalent compromise may face no comparable obligation to enumerate and publish. Comparing sectors using breach counts compares reporting regimes as much as security postures.
The Argument For Extending It
This desk has repeatedly hit the absence of comparable data — the availability failures nobody files at 26-0209, the unmeasured supplier incidents at 26-0426, the uncounted total at 26-0307.
The healthcare register demonstrates that a mandatory, public, per-incident register with affected counts is administratively possible. Whether it should exist elsewhere is a policy question; whether it could is settled.
This is an analysis file built on published summaries of regulatory filings, listed below. Figures are as reported by the analysts summarising the federal portal. Corrections: corrections@forensicpost.com.