- DentaQuest, the dental and vision benefits administrator, disclosed a 15-million-person data breach in July 2026 — one of the largest in healthcare history — exposing Social Security numbers, Medicaid and Medicare identifiers, diagnosis codes, and full billing records after unauthorized actors accessed its network in May 2026.
- The Healthcare Dive breach tracker now catalogs over 100 major incidents since 2023, with Conduent Business Services’ 62.2-million-person breach (October 2025) and Change Healthcare’s record 192.7-million-person ransomware attack (2024) representing the two largest single incidents ever reported to HHS — together exposing more data than exist in most countries’ entire health systems.
- Healthcare has become the premier ransomware target precisely because hospitals cannot tolerate downtime: attacks on Ascension Health (5.5M affected), Kettering Health, and Lurie Children’s Hospital forced clinical system shutdowns that directly compromised patient care, maximizing ransom payment pressure and accelerating attackers’ return on investment.
- The sector’s deepest vulnerability runs through third-party vendors: MOVEit file transfer software alone triggered cascading breaches at CMS, Delta Dental, Welltok, NationsBenefits, and dozens of others — illustrating how a single software flaw translates into healthcare-wide exposure when every organization in the ecosystem relies on the same vendor.
What Happened?
Healthcare Dive’s breach tracker — cataloging incidents reported to HHS’s Office for Civil Rights affecting 352,447 or more records — was updated through August 2026 and now spans dozens of major incidents reaching back to 2023. The most recent entry is DentaQuest’s July 2026 disclosure of a 15-million-person breach following a May 2026 network intrusion, exposing SSNs, Medicaid and Medicare numbers, provider names, and detailed clinical records. Also newly logged is Conduent Business Services’ 62.2-million-person breach from October 2025 — the second largest ever recorded — where hackers accessed networks across a three-month window and specifically exfiltrated files related to insurer Humana. Change Healthcare’s 2024 ransomware attack remains the largest breach in US healthcare history at 192.7 million affected individuals. From 2010 to 2022, healthcare data breaches already exposed 385 million patient records — and the pace has accelerated sharply since.
Why It Matters?
Healthcare data is uniquely valuable to criminals: each record contains the full stack of identity fraud inputs — Social Security numbers, birthdates, insurance IDs, and financial information — plus medical history that can be weaponized for insurance fraud or targeted extortion. Unlike financial firms, hospitals cannot shut down systems without directly harming patients, a leverage advantage ransomware operators exploit systematically. The MOVEit cascade illustrates the sector’s most dangerous structural flaw: healthcare organizations depend on a small number of shared technology vendors for core functions like file transfer, revenue cycle management, and medical transcription — meaning a single software vulnerability simultaneously compromises dozens of unrelated organizations. Business associates and third-party vendors now account for a significant share of breach volume, yet they sit outside the direct control of the health systems whose patients they expose.
What’s Next?
Regulatory pressure is intensifying: HHS’s Office for Civil Rights is expected to increase HIPAA enforcement actions and fine sizes as breach volumes grow. The 60-day notification requirement — which already allows patients to be exposed for nearly two months before learning their data was stolen — faces calls to be shortened. Class action litigation has exploded following major breaches, with Change Healthcare and Ascension facing hundreds of suits. Healthcare organizations will face growing pressure to invest in zero-trust architecture, vendor risk management, and cyber insurance, all of which carry significant cost. For investors, the breach wave creates opportunity in healthcare cybersecurity vendors — and material risk for any health system or insurer whose data practices have not kept pace with the threat environment.
Source: Healthcare Dive













