PrivacySignal
Breach

May 2026 Healthcare Data Breach Report

HIPAA Journal · · US Federal · Data Breaches

According to data from the HHS Office for Civil Rights breach portal, 61 healthcare data breaches were reported in May 2026, as tracked in the HIPAA Journal's monthly analysis. The report reflects ongoing disclosure activity logged by the federal agency responsible for HIPAA enforcement.

Why this matters: Sixty-one breaches in a single month means tens of thousands of people likely had their most sensitive records exposed — diagnoses, prescriptions, mental health histories, insurance details. Healthcare data does not expire. It can be used years later to discriminate, defraud, or embarrass. The HHS breach portal exists so there is at least some public record of who got hit and when. But disclosure is not the same as accountability. Most people whose records are exposed never hear about it in time to do anything useful.

Who should care: Cybersecurity · Privacy officers · Administrators · Healthcare professionals · Compliance

This summary is AI-assisted and may contain errors. It is an original briefing to help you gauge significance quickly — not a reproduction of the source. Always read the linked original before relying on it. See our methodology.

Analysis

All analysis →

Weekly Editorial Analysis from Experts and Editors

Related stories

Breach
DataBreaches.net · · International

Winona County paid more than $128K following January ransomware attack

WXOW in Minnesota reports: Winona County paid more than $128,000 following a January ransomware attack, according to a county news release. The county said it negotiated and paid $128,539.57 with assistance from its insurance carrier after ransomware was detected on its computer network Jan. 22, 2026. Officials said the decision was made after consultation with... Source

Who should care: Cybersecurity · Privacy officers · Administrators

#breach#security Read original →
Breach
DataBreaches.net · · International

UK: HIV charity has ‘sensitive’ health data stolen

George House Trust, a UK HIV charity, has notified service users that sensitive personal health data may have been stolen following a breach of Beacon CRM, a platform used by more than 1,000 charities and non-profits.

Who should care: Cybersecurity · Privacy officers · Administrators · Healthcare professionals · Compliance

#breach#healthcare Read original →
Breach
BleepingComputer · · International

Over 8,300 Gitea servers vulnerable to code execution attacks

Over 8,300 Internet-exposed Gitea instances are still unpatched against a critical security flaw exploited in ongoing remote code execution attacks, according to cybersecurity watchdog Shadowserver. [...]

Who should care: Cybersecurity · Privacy officers · Administrators

#breach#security Read original →
Breach
HIPAA Journal · · US Federal

American Vision Partners Settles Data Breach Litigation for $1.75M

American Vision Partners, an eye care management company operating as Medical Management Resource Group LLC, has agreed to pay $1.75 million to settle a class action lawsuit tied to a data breach. The settlement resolves litigation brought by affected individuals whose information was exposed.

Who should care: Cybersecurity · Privacy officers · Administrators · Healthcare professionals · Compliance

#breach#healthcare Read original →
Breach
BleepingComputer · · International

Nearly 700 rogue AI agents coordinated in the Hugging Face attack

A July attack on Hugging Face involved nearly 700 AI agents, reportedly powered by OpenAI's internal IM1 model, coordinating the intrusion through an unauthorized message board. The newly surfaced details reveal an unusual level of machine-to-machine coordination in what appears to be a significant breach of a major AI platform.

Who should care: Cybersecurity · Privacy officers · Administrators · General readers · AI governance · Policy

#breach#ai Read original →