CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

June 2026 Healthcare Data Breach Report

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 6575

As cited

Copy frozen at (site build).

breaches incidents

June 2026 Healthcare Data Breach Report

In June 2026, 66 large healthcare data breaches were reported to the U.S. Department of Health and Human Services, affecting at least 4.5 million individuals. Network server compromises accounted for over 81 percent of incidents, with phishing and extortion attacks also prevalent; two business associates experienced the largest breaches, exposing 1.4 million and 1.26 million individuals respectively. Year-to-date figures show healthcare breaches have declined compared to 2024 and 2025, though the June monthly total represents a significant decrease from recent monthly averages.

Why it matters: Healthcare providers and business associates must audit network access controls and email security immediately, as the majority of June breaches involved network server compromise following phishing attacks or extortion demands.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

breaches incidents

June 2026 Healthcare Data Breach Report

In June 2026, 66 large healthcare data breaches were reported to HHS, affecting at least 4.5 million individuals, with network server hacking accounting for 81.8% of incidents. The largest breaches occurred at business associates Xsolis (1.4 million individuals, originating from a phishing email in January 2026) and MCBS (1.25 million individuals, involving the PEAR extortion group in September 2025). Year-to-date 2026 shows a 37.7% improvement compared to 2024, though healthcare organizations continue to experience an average of more than two large breaches daily.

Why it matters: Healthcare providers, business associates, and health plans must strengthen network security and phishing defenses to reduce the persistent breach rate, which remains elevated despite year-over-year improvements and poses ongoing exposure of patient protected health information including Social Security numbers and medical histories.

Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary