
The 10 largest health data breaches of the first half of 2024
Many health systems and healthcare companies have suffered cyberattacks, or they’ve been affected by a breach of a vendor in the first six months of the year. Millions of Americans have been affected.
More than 31 million Americans have been affected by the 10 largest breaches of health data in the first half of the year.
And that comes with a big caveat.
It’s still unclear how many people may have been impacted by two high-profile cyberattacks: the ransomware attacks of
Plus, that’s only looking at the impact of the biggest breaches. Millions more have been affected by other attacks or the unauthorized disclosure of private information. There have been 341 breaches reported to the Department of Health and Human Services in the first half of the year, according to the department’s
The Change Healthcare attack caused
Change Healthcare discovered the attack in February, and lawmakers have pressed UnitedHealth for clarity on how many people have been affected. The Department of Veterans Affairs has warned that
Ascension has also been working to recover from its attack on May 8, and said in mid-June that it has restored its electronic health records across the system. The attack affected patient care, as
Wes Wright, chief healthcare officer of Ordr, Inc., a cybersecurity firm, says healthcare organizations are vulnerable because so many records are digital.
But he says recent high-profile attacks underscore some basic problems with many healthcare organizations in their approach to cybersecurity, including segmenting systems so a breach in one area doesn’t take down an entire health system.
“It's all about fundamentals,” Wright tells Chief Healthcare Executive®. “I mean, where we're getting beaten is in the blocking and the tackling.”
The Health Department’s Office of Civil Rights requires organizations to report any breach of health data involving more than 500 individuals. As of July 1, Change Healthcare and Ascension haven’t reported their estimate of the individuals attacked.
Still, several organizations have reported breaches that affected more than 1 million individuals. In 2023, the number of large breaches reported to the government affected
The full impact of this year’s attacks won’t be known for some time, but clearly cybersecurity remains a stubborn problem for hospitals, health systems and other providers.
Here’s a look at the 10 largest data breaches that have been reported to the health department’s database in the first half of 2024. Most involve cyberattacks, but a couple involve the inadvertent disclosure of private health information.
It’s also worth noting some breaches involve vendors working with hospitals and other providers,
- Read more:
Health department must change ‘woefully inadequate’ approach to cybersecurity, senator says
1. Kaiser Permanente
The California-based health system says
Kaiser Permanente says online technologies may have sent personal information to other parties, including Google, Bing, and X. The personal data may have been sent when patients and members accessed websites or mobile applications.
Kaiser Permanente’s health plan has about 12.5 million members, and the organization also operates 40 hospitals in several states.
The system said in late April that there’s no evidence that there has been any misuse of patient information, but notified individuals “out of an abundance of caution.”
“We apologize that this incident occurred,” Kaiser Permanente said in a statement.
2. Concentra Health Services
The Texas-based company, a division of Select Medical, says it has been impacted by a breach that affected nearly 4 million people, the health department said. Concentra said the breach occurred due to a third party, Perry Johnson & Associates, Inc.
“This event occurred solely at PJ&A and was not the result of any activities or inactions on Concentra’s part,” Concentra said in a
Concentra offers occupational medicine, urgent care, physical therapy and other services at more than 540 medical centers. The company also serves employers and operates more than 140 onsite facilities.
PJ&A, which provides medical transcription services to healthcare organizations,
3. Sav-Rx
A&A Services, doing business as Sav-Rx, was hit with a cyberattack and estimates that 2.8 million individuals have been affected, according to the health department.
In a
The company is offering free credit monitoring and identity theft protection to customers for two years.
Sav-Rx said it conducted a thorough investigation and says they aren’t aware of third parties using the data. The company said it concluded its investigation April 30.
4. WebTPA
WebTPA Employer Services, LLC, which handles administrative services for benefits plans and insurance companies, experienced a data breach affecting more than 2.5 million people, according to the health department.
The company said in a
The company, which is based in Texas, said it’s providing two years of identity monitoring services to customers. The information accessed included names, Social Security numbers, and insurance information, among others, the company said.
5. INTEGRIS Health
The Oklahoma health system suffered a cyberattack affecting nearly 2.4 million people, the health department says.
INTEGRIS said in a
The health system also said some individuals were by a group claiming responsibility for the breach, but urged individuals not to respond or engage with the group.
6. Medical Management Resource Group
The organization suffered a breach affecting more than 2.3 million people, the health department says.
The company, based in Arizona, does business as American Vision Partners and was the victim of a hacking incident that was discovered on Jan. 16, 2024, according to the
The exposed information varies for different individuals, but could have included Social Security numbers, dates of birth, banking information and passport information. American Vision Partners is an eye care management organization.
7. Geisinger
The Pennsylvania health system suffered a data breach that has affected more than 1.2 million individuals, according to the health department.
“On Nov. 29, 2023, Geisinger discovered and immediately notified Nuance that a former Nuance employee had accessed certain Geisinger patient information two days after the employee had been terminated,” Geisinger said in a
Geisinger disclosed the breach on June 24, and the health system said Nuance waited to inform those affected at the behest of authorities.
“Because it could have impeded their investigation, law enforcement investigators asked Nuance to delay notifying patients of this incident until now,” Geisinger said. “The former Nuance employee has been arrested and is facing federal charges.”
Geisinger is advising patients to review statements from their health plan and reach out to their insurance company if they are billed for services they didn’t receive.
8. Eastern Radiologists, Inc.
The North Carolina organization suffered a cybersecurity incident affecting more than 880,000 people, according to the health department.
Eastern Radiologists began notifying patients in early March about the breach and said an unauthorized party managed to access or copy some private information from patients, according to
The company provides services for 17 hospitals and 7 outpatient facilities.
9. Superior Air-Ground Ambulance Service, Inc.
The Illinois-based company experienced a cyberattack that affected more than 850,000 people, the health department says.
In a
Superior said it has reviewed procedures and taken steps to improve its security. The company provides EMS services in five states.
10. UNITE HERE
The New York labor union suffered a cyberattack that affected more than 790,000 individuals, according to the health department.
In a
UNITE HERE is offering credit monitoring and identity theft protection and says it is working “to lower the chances of something like this happening again.”
In addition, UNITE HERE offered versions of its public notice in more than a dozen languages, including Spanish, Arabic, Chinese and Russian. The union represents 300,000 people in a host of industries.

















































