Part two of our three-part mid-year accounting. Part one covered ransomware; part three covers law enforcement.
The Numbers
Through the first half of 2026, the HHS Office for Civil Rights breach portal recorded:
- 189 large healthcare data breaches
- More than 19 million individuals affected (through June 9)
- 173 attributed to hacking / IT incidents β roughly 92%
- 14 unauthorized access or disclosure
- 1 theft, 1 loss
The composition matters more than the total. A decade ago, healthcare breach reporting was dominated by lost laptops, misdirected mail and improper disclosure β failures of process. That category is now 16 incidents out of 189. Ninety-two percent of large healthcare breaches in the first half of 2026 were somebody breaking in on purpose.
The Top Ten
As posted to the OCR portal through June 9, 2026:
| # | Organization | Individuals |
|---|---|---|
| 1 | TriZetto Provider Solutions | 3,433,965 |
| 2 | QualDerm Partners | 3,117,874 |
| 3 | Nacogdoches Memorial Hospital | 2,507,073 |
| 4 | Navia Benefit Solutions | 2,151,330 |
| 5 | NYC Health + Hospitals | 1,800,000 |
| 6 | OpenLoop Health | 716,000 |
| 7 | ApolloMD Business Services | 626,540 |
| 8 | Erie Family Health Centers | 570,000 |
| 9 | Minnesota Department of Human Services | 303,965 |
| 10 | North Texas Behavioral Health Authority | 285,086 |
The list spans revenue cycle management, benefits administration, dermatology practice groups, hospital systems, telehealth infrastructure, state human services and behavioral health authorities. What it does not do is concentrate in any one of them.
Note the top of the table. TriZetto, a Cognizant subsidiary, is a claims clearinghouse β it processes transactions between providers and payers. QualDerm is a dermatology practice management group. Navia administers flexible spending accounts and COBRA. Three of the four largest incidents in the half happened at organizations that most affected patients could not identify if asked.
The Navia count on the OCR portal, 2,151,330, sits below the 2,697,540 figure the company itself disclosed when we covered the breach in March. Divergence between a companyβs own notification count and its OCR filing is common and usually reflects different determination dates rather than a correction. It is also a reminder that these numbers are provisional.
The 19 Million Is Already Wrong
Two developments since the June 9 cutoff make the mid-year total an undercount rather than a measurement:
CareCloud went from 345,000 to 3,756,469. The intrusion happened March 10β16, squarely inside the reporting period. It reached the OCR portal in August. Every H1 tally published before this week excluded 3.7 million people whose data was taken in March.
Conduent settled at 62,224,658. That filing landed in June, and its scale β the third-largest healthcare breach in U.S. history β distorts any period total it falls inside. Conduent opened at 10.5 million in late 2025 and took eight months to arrive at the real figure.
This is the defining measurement problem of healthcare breach reporting. Large vendor breaches are reported when the victim count is determined, not when the intrusion occurs, and determination lags intrusion by three to eight months in every case above. Any half-year total is a snapshot of paperwork completed, not of harm done. The first half of 2026 will keep getting worse for at least another year.
The ITRCβs H1 figures β 471 million notices across all sectors β carry the same caveat for the same reason.
The Vendor Problem Is Now the Whole Problem
Business associates and covered entities are represented in roughly equal measure among the ten largest breaches. That equality is itself the finding: there are vastly more covered entities than business associates, and the business associates are matching them incident-for-incident at the top of the list because each one aggregates data from hundreds or thousands of providers.
Running the 2026 vendor incidents together:
- TriZetto β claims clearinghouse, 3.4 million
- CareCloud β EHR, billing and revenue cycle for tens of thousands of providers, 3.76 million
- Craneware β revenue cycle software reaching roughly 2,000 hospitals
- DentaQuest β dental benefits administration, hit by ShinyHunters
- Navia β benefits administration for roughly 10,000 employers
- Conduent β government services, 62.2 million
Six organizations. None of them see patients. Collectively they account for more exposed records than every hospital breach in the period combined.
The consolidation that produced this was rational at every step. A practice that puts records, documentation and billing on one integrated platform gets a coherent workflow and one vendor relationship instead of five. A payer that outsources benefits administration gets specialization it could not build. Each decision reduced cost and complexity locally while concentrating risk globally, and no participant in the chain was positioned to see the aggregate.
The attacker sees the aggregate. That is the entire reason the top of this table looks the way it does.
What Changes in H2
Attackers have finished learning this. The shift from hospitals to their vendors is complete, and there is no reason to reverse it: one intrusion at a clearinghouse yields what fifty hospital intrusions would.
Notification timelines are the unaddressed failure. CareCloud filed an SEC 8-K for investors eight days after determining materiality and took five months to write to patients. That ordering is legal. It is also the clearest available statement of whose interests the disclosure regime actually protects.
The counts will keep climbing after the fact. Conduent: 10.5M β 25M β 62.2M. CareCloud: 345,000 β 3.76M. Treat the first number in any large vendor breach as a floor with no known ceiling.



