Introduction to Healthcare Breach Data
The HIPAA Journal has compiled healthcare data breach statistics from October 2009, when the Department of Health and Human Services’ Office for Civil Rights first started publishing summaries of healthcare data breaches on its website. The healthcare data breach statistics below only include data breaches of 500 or more records that have been reported to the U.S. Department of Health and Human Services’ Office for Civil Rights (OCR), as details of smaller breaches are not made public by OCR.
## # A tibble: 2,049 × 9
## Name of Cover…¹ State Cover…² Indiv…³ Breac…⁴ Type …⁵ Locat…⁶ Busin…⁷ Web D…⁸
## <chr> <chr> <chr> <dbl> <chr> <chr> <chr> <chr> <chr>
## 1 Kelley Imaging… WA Busine… 627 6/13/2… Hackin… Deskto… Yes <NA>
## 2 Dino-Peds CO Health… 1357 5/30/2… Unauth… Electr… No <NA>
## 3 Care Partners … OR Health… 600 5/25/2… Hackin… Email No <NA>
## 4 Elmcroft Senio… TX Health… 10000 5/21/2… Hackin… Networ… No <NA>
## 5 UT Physicians TX Health… 2793 5/18/2… Unauth… Email No <NA>
## 6 New York City … NY Health… 2078 5/11/2… Unauth… Paper/… No <NA>
## 7 Billings Clinic MT Health… 949 4/27/2… Hackin… Email No <NA>
## 8 MAXIMUS, Inc. … VA Busine… 3029 4/17/2… Unauth… Paper/… Yes <NA>
## 9 Chesapeake Reg… VA Health… 2100 4/6/20… Theft Other … No <NA>
## 10 West Kendall B… FL Health… 1480 4/2/20… Unauth… Other No <NA>
## # … with 2,039 more rows, and abbreviated variable names
## # ¹`Name of Covered Entity`, ²`Covered Entity Type`, ³`Individuals Affected`,
## # ⁴`Breach Submission Date`, ⁵`Type of Breach`,
## # ⁶`Location of Breached Information`, ⁷`Business Associate Present`,
## # ⁸`Web Description`
Visualizations
This visualization shows exponentially how many individuals were affected in each state. We can see that Indiana has the highest among of individuals affected by far.
In this table, we can see the count of the different variations of Breach Types in each state. This data is helpful to see which Types of Data Breaches are most common in each state. We can even see the total count of types per state.
##
## AK AL AR AZ
## Hacking/IT Incident 0 5 4 6
## Hacking/IT Incident, Other 0 0 0 0
## Hacking/IT Incident, Other, Unauthorized Access/Disclosure 0 0 0 0
## Hacking/IT Incident, Theft 0 0 0 0
## Hacking/IT Incident, Theft, Unauthorized Access/Disclosure 0 0 0 0
## Hacking/IT Incident, Unauthorized Access/Disclosure 0 0 0 1
## Improper Disposal 0 1 0 1
## Improper Disposal, Loss 0 0 0 1
## Improper Disposal, Loss, Theft 0 0 0 0
## Improper Disposal, Theft 0 0 0 0
## Improper Disposal, Theft, Unauthorized Access/Disclosure 0 0 0 0
## Improper Disposal, Unauthorized Access/Disclosure 0 0 0 0
## Loss 0 0 1 4
## Loss, Other 0 0 0 0
## Loss, Other, Theft 0 0 0 0
## Loss, Theft 0 0 0 0
## Loss, Unauthorized Access/Disclosure 0 0 0 0
## Loss, Unauthorized Access/Disclosure, Unknown 0 0 0 0
## Loss, Unknown 0 0 0 0
## Other 0 2 1 2
## Other, Theft 0 0 0 0
## Other, Theft, Unauthorized Access/Disclosure 0 0 0 1
## Other, Unauthorized Access/Disclosure 0 0 0 0
## Other, Unknown 0 0 0 0
## Theft 4 11 3 16
## Theft, Unauthorized Access/Disclosure 0 0 1 1
## Unauthorized Access/Disclosure 2 6 8 8
## Unknown 0 0 0 0
##
## CA CO CT DC
## Hacking/IT Incident 18 4 2 1
## Hacking/IT Incident, Other 0 1 0 0
## Hacking/IT Incident, Other, Unauthorized Access/Disclosure 0 0 0 0
## Hacking/IT Incident, Theft 0 0 0 0
## Hacking/IT Incident, Theft, Unauthorized Access/Disclosure 1 0 0 0
## Hacking/IT Incident, Unauthorized Access/Disclosure 0 0 0 0
## Improper Disposal 2 2 0 0
## Improper Disposal, Loss 0 0 0 0
## Improper Disposal, Loss, Theft 2 0 0 0
## Improper Disposal, Theft 0 0 0 0
## Improper Disposal, Theft, Unauthorized Access/Disclosure 0 0 0 0
## Improper Disposal, Unauthorized Access/Disclosure 0 0 0 0
## Loss 13 1 2 1
## Loss, Other 1 0 0 0
## Loss, Other, Theft 0 0 0 0
## Loss, Theft 0 0 0 0
## Loss, Unauthorized Access/Disclosure 0 0 0 0
## Loss, Unauthorized Access/Disclosure, Unknown 0 0 0 0
## Loss, Unknown 0 0 0 0
## Other 12 0 0 0
## Other, Theft 1 0 0 1
## Other, Theft, Unauthorized Access/Disclosure 0 0 0 0
## Other, Unauthorized Access/Disclosure 0 1 0 0
## Other, Unknown 0 0 0 0
## Theft 108 11 13 3
## Theft, Unauthorized Access/Disclosure 2 1 0 0
## Unauthorized Access/Disclosure 47 11 8 4
## Unknown 0 0 0 0
##
## DE FL GA HI
## Hacking/IT Incident 0 15 6 1
## Hacking/IT Incident, Other 0 0 1 0
## Hacking/IT Incident, Other, Unauthorized Access/Disclosure 0 0 0 0
## Hacking/IT Incident, Theft 0 0 0 0
## Hacking/IT Incident, Theft, Unauthorized Access/Disclosure 0 1 0 0
## Hacking/IT Incident, Unauthorized Access/Disclosure 0 0 0 0
## Improper Disposal 0 3 2 0
## Improper Disposal, Loss 0 0 0 0
## Improper Disposal, Loss, Theft 0 0 0 0
## Improper Disposal, Theft 0 0 0 0
## Improper Disposal, Theft, Unauthorized Access/Disclosure 0 0 0 0
## Improper Disposal, Unauthorized Access/Disclosure 0 0 0 0
## Loss 0 10 5 1
## Loss, Other 0 0 0 0
## Loss, Other, Theft 0 0 0 0
## Loss, Theft 0 1 0 0
## Loss, Unauthorized Access/Disclosure 0 0 0 0
## Loss, Unauthorized Access/Disclosure, Unknown 0 0 0 0
## Loss, Unknown 0 0 0 0
## Other 1 5 3 0
## Other, Theft 0 0 0 0
## Other, Theft, Unauthorized Access/Disclosure 0 1 0 0
## Other, Unauthorized Access/Disclosure 0 1 0 0
## Other, Unknown 0 0 1 0
## Theft 0 42 19 0
## Theft, Unauthorized Access/Disclosure 0 6 1 0
## Unauthorized Access/Disclosure 1 37 13 2
## Unknown 0 2 0 0
##
## IA ID IL IN
## Hacking/IT Incident 0 0 15 12
## Hacking/IT Incident, Other 0 0 0 0
## Hacking/IT Incident, Other, Unauthorized Access/Disclosure 0 0 0 0
## Hacking/IT Incident, Theft 0 0 0 0
## Hacking/IT Incident, Theft, Unauthorized Access/Disclosure 0 0 0 0
## Hacking/IT Incident, Unauthorized Access/Disclosure 0 0 0 0
## Improper Disposal 1 0 2 3
## Improper Disposal, Loss 0 0 0 0
## Improper Disposal, Loss, Theft 0 0 0 0
## Improper Disposal, Theft 0 0 0 0
## Improper Disposal, Theft, Unauthorized Access/Disclosure 0 0 0 0
## Improper Disposal, Unauthorized Access/Disclosure 0 0 0 0
## Loss 2 1 6 1
## Loss, Other 0 0 0 0
## Loss, Other, Theft 0 0 0 0
## Loss, Theft 0 0 2 0
## Loss, Unauthorized Access/Disclosure 0 0 0 0
## Loss, Unauthorized Access/Disclosure, Unknown 0 0 0 0
## Loss, Unknown 1 0 0 0
## Other 1 0 7 3
## Other, Theft 0 0 0 0
## Other, Theft, Unauthorized Access/Disclosure 0 0 0 0
## Other, Unauthorized Access/Disclosure 0 0 1 0
## Other, Unknown 0 0 0 0
## Theft 1 2 33 19
## Theft, Unauthorized Access/Disclosure 0 0 0 2
## Unauthorized Access/Disclosure 4 0 20 11
## Unknown 0 0 0 0
##
## KS KY LA MA
## Hacking/IT Incident 0 4 4 9
## Hacking/IT Incident, Other 0 0 0 0
## Hacking/IT Incident, Other, Unauthorized Access/Disclosure 0 0 0 0
## Hacking/IT Incident, Theft 0 0 0 0
## Hacking/IT Incident, Theft, Unauthorized Access/Disclosure 0 0 0 0
## Hacking/IT Incident, Unauthorized Access/Disclosure 0 0 0 0
## Improper Disposal 0 0 1 1
## Improper Disposal, Loss 0 0 0 0
## Improper Disposal, Loss, Theft 0 0 0 0
## Improper Disposal, Theft 0 0 0 0
## Improper Disposal, Theft, Unauthorized Access/Disclosure 0 0 0 0
## Improper Disposal, Unauthorized Access/Disclosure 0 1 0 0
## Loss 3 1 1 4
## Loss, Other 0 0 0 0
## Loss, Other, Theft 0 0 0 0
## Loss, Theft 0 2 1 1
## Loss, Unauthorized Access/Disclosure 0 0 0 0
## Loss, Unauthorized Access/Disclosure, Unknown 0 0 0 0
## Loss, Unknown 0 0 0 0
## Other 0 3 0 0
## Other, Theft 0 0 0 0
## Other, Theft, Unauthorized Access/Disclosure 0 0 0 0
## Other, Unauthorized Access/Disclosure 0 0 0 0
## Other, Unknown 0 0 0 0
## Theft 6 16 6 18
## Theft, Unauthorized Access/Disclosure 0 0 1 0
## Unauthorized Access/Disclosure 2 8 4 7
## Unknown 0 0 0 0
##
## MD ME MI MN
## Hacking/IT Incident 7 0 5 5
## Hacking/IT Incident, Other 0 0 0 0
## Hacking/IT Incident, Other, Unauthorized Access/Disclosure 0 0 0 0
## Hacking/IT Incident, Theft 0 0 0 0
## Hacking/IT Incident, Theft, Unauthorized Access/Disclosure 0 0 0 0
## Hacking/IT Incident, Unauthorized Access/Disclosure 1 0 1 0
## Improper Disposal 0 0 0 3
## Improper Disposal, Loss 0 0 0 0
## Improper Disposal, Loss, Theft 0 0 0 0
## Improper Disposal, Theft 0 0 0 0
## Improper Disposal, Theft, Unauthorized Access/Disclosure 0 0 0 0
## Improper Disposal, Unauthorized Access/Disclosure 0 0 0 0
## Loss 2 0 5 2
## Loss, Other 0 0 0 0
## Loss, Other, Theft 0 0 0 0
## Loss, Theft 0 0 0 0
## Loss, Unauthorized Access/Disclosure 0 0 0 3
## Loss, Unauthorized Access/Disclosure, Unknown 0 0 0 1
## Loss, Unknown 0 0 0 0
## Other 1 1 3 4
## Other, Theft 0 0 0 0
## Other, Theft, Unauthorized Access/Disclosure 0 0 0 0
## Other, Unauthorized Access/Disclosure 0 0 0 0
## Other, Unknown 0 0 0 0
## Theft 9 0 12 9
## Theft, Unauthorized Access/Disclosure 0 0 1 0
## Unauthorized Access/Disclosure 10 1 14 11
## Unknown 0 0 0 0
##
## MO MS MT NC
## Hacking/IT Incident 3 2 1 9
## Hacking/IT Incident, Other 0 0 0 0
## Hacking/IT Incident, Other, Unauthorized Access/Disclosure 0 0 0 0
## Hacking/IT Incident, Theft 0 0 0 0
## Hacking/IT Incident, Theft, Unauthorized Access/Disclosure 0 0 0 0
## Hacking/IT Incident, Unauthorized Access/Disclosure 0 0 0 0
## Improper Disposal 3 1 0 1
## Improper Disposal, Loss 0 0 0 0
## Improper Disposal, Loss, Theft 0 0 0 0
## Improper Disposal, Theft 0 0 0 0
## Improper Disposal, Theft, Unauthorized Access/Disclosure 0 0 0 1
## Improper Disposal, Unauthorized Access/Disclosure 0 0 0 0
## Loss 0 2 2 5
## Loss, Other 0 0 0 0
## Loss, Other, Theft 0 0 0 0
## Loss, Theft 0 0 0 1
## Loss, Unauthorized Access/Disclosure 0 0 0 0
## Loss, Unauthorized Access/Disclosure, Unknown 0 0 0 0
## Loss, Unknown 0 0 0 0
## Other 0 0 0 2
## Other, Theft 0 0 0 0
## Other, Theft, Unauthorized Access/Disclosure 0 0 0 0
## Other, Unauthorized Access/Disclosure 0 0 0 1
## Other, Unknown 0 0 0 0
## Theft 11 4 3 9
## Theft, Unauthorized Access/Disclosure 0 0 0 1
## Unauthorized Access/Disclosure 14 1 4 14
## Unknown 1 0 0 2
##
## ND NE NH NJ
## Hacking/IT Incident 0 1 1 1
## Hacking/IT Incident, Other 0 0 0 0
## Hacking/IT Incident, Other, Unauthorized Access/Disclosure 0 0 0 0
## Hacking/IT Incident, Theft 0 0 0 1
## Hacking/IT Incident, Theft, Unauthorized Access/Disclosure 0 0 0 0
## Hacking/IT Incident, Unauthorized Access/Disclosure 0 0 0 0
## Improper Disposal 2 1 0 0
## Improper Disposal, Loss 0 0 0 0
## Improper Disposal, Loss, Theft 0 0 0 0
## Improper Disposal, Theft 0 0 0 0
## Improper Disposal, Theft, Unauthorized Access/Disclosure 0 0 0 0
## Improper Disposal, Unauthorized Access/Disclosure 0 0 0 0
## Loss 0 1 0 2
## Loss, Other 0 0 0 0
## Loss, Other, Theft 0 0 0 0
## Loss, Theft 0 0 0 0
## Loss, Unauthorized Access/Disclosure 0 0 0 0
## Loss, Unauthorized Access/Disclosure, Unknown 0 0 0 0
## Loss, Unknown 0 0 0 0
## Other 0 0 0 1
## Other, Theft 0 0 0 0
## Other, Theft, Unauthorized Access/Disclosure 0 0 0 0
## Other, Unauthorized Access/Disclosure 0 0 0 0
## Other, Unknown 0 0 0 0
## Theft 2 5 3 10
## Theft, Unauthorized Access/Disclosure 0 0 0 2
## Unauthorized Access/Disclosure 0 2 0 3
## Unknown 0 0 0 0
##
## NM NV NY OH
## Hacking/IT Incident 3 0 2 6
## Hacking/IT Incident, Other 0 0 0 0
## Hacking/IT Incident, Other, Unauthorized Access/Disclosure 0 0 0 0
## Hacking/IT Incident, Theft 0 0 0 0
## Hacking/IT Incident, Theft, Unauthorized Access/Disclosure 0 0 0 0
## Hacking/IT Incident, Unauthorized Access/Disclosure 0 1 1 0
## Improper Disposal 0 1 1 6
## Improper Disposal, Loss 0 0 0 0
## Improper Disposal, Loss, Theft 0 0 0 0
## Improper Disposal, Theft 0 0 0 0
## Improper Disposal, Theft, Unauthorized Access/Disclosure 0 0 0 0
## Improper Disposal, Unauthorized Access/Disclosure 0 0 0 0
## Loss 0 1 9 8
## Loss, Other 0 0 0 0
## Loss, Other, Theft 0 0 0 0
## Loss, Theft 0 0 0 0
## Loss, Unauthorized Access/Disclosure 0 0 0 0
## Loss, Unauthorized Access/Disclosure, Unknown 0 0 0 0
## Loss, Unknown 0 0 0 0
## Other 1 0 2 3
## Other, Theft 0 0 1 0
## Other, Theft, Unauthorized Access/Disclosure 0 0 0 0
## Other, Unauthorized Access/Disclosure 0 0 0 0
## Other, Unknown 0 0 0 0
## Theft 11 6 46 22
## Theft, Unauthorized Access/Disclosure 0 0 0 0
## Unauthorized Access/Disclosure 4 3 21 12
## Unknown 0 0 1 1
##
## OK OR PA PR
## Hacking/IT Incident 6 4 5 0
## Hacking/IT Incident, Other 0 0 0 0
## Hacking/IT Incident, Other, Unauthorized Access/Disclosure 0 1 0 0
## Hacking/IT Incident, Theft 0 0 0 0
## Hacking/IT Incident, Theft, Unauthorized Access/Disclosure 0 0 0 0
## Hacking/IT Incident, Unauthorized Access/Disclosure 0 0 1 0
## Improper Disposal 0 0 2 0
## Improper Disposal, Loss 0 0 0 0
## Improper Disposal, Loss, Theft 1 0 0 0
## Improper Disposal, Theft 0 0 0 0
## Improper Disposal, Theft, Unauthorized Access/Disclosure 0 0 0 0
## Improper Disposal, Unauthorized Access/Disclosure 0 0 0 0
## Loss 1 0 7 0
## Loss, Other 0 0 0 0
## Loss, Other, Theft 0 0 0 0
## Loss, Theft 0 0 1 0
## Loss, Unauthorized Access/Disclosure 0 0 0 0
## Loss, Unauthorized Access/Disclosure, Unknown 0 0 0 0
## Loss, Unknown 0 0 0 0
## Other 0 0 4 0
## Other, Theft 0 0 0 0
## Other, Theft, Unauthorized Access/Disclosure 0 0 0 0
## Other, Unauthorized Access/Disclosure 0 0 1 0
## Other, Unknown 0 0 0 0
## Theft 6 14 26 23
## Theft, Unauthorized Access/Disclosure 0 1 2 1
## Unauthorized Access/Disclosure 3 9 15 7
## Unknown 0 0 0 0
##
## RI SC SD TN
## Hacking/IT Incident 0 1 1 4
## Hacking/IT Incident, Other 0 0 0 0
## Hacking/IT Incident, Other, Unauthorized Access/Disclosure 0 0 0 0
## Hacking/IT Incident, Theft 0 0 0 0
## Hacking/IT Incident, Theft, Unauthorized Access/Disclosure 0 0 0 0
## Hacking/IT Incident, Unauthorized Access/Disclosure 0 0 0 0
## Improper Disposal 0 4 0 3
## Improper Disposal, Loss 0 0 0 0
## Improper Disposal, Loss, Theft 0 0 0 0
## Improper Disposal, Theft 0 0 0 0
## Improper Disposal, Theft, Unauthorized Access/Disclosure 0 0 0 0
## Improper Disposal, Unauthorized Access/Disclosure 0 0 0 0
## Loss 1 1 1 6
## Loss, Other 0 0 0 0
## Loss, Other, Theft 0 0 0 0
## Loss, Theft 0 0 0 0
## Loss, Unauthorized Access/Disclosure 0 0 0 0
## Loss, Unauthorized Access/Disclosure, Unknown 0 0 0 0
## Loss, Unknown 0 0 0 0
## Other 1 1 0 2
## Other, Theft 0 0 0 0
## Other, Theft, Unauthorized Access/Disclosure 0 0 0 0
## Other, Unauthorized Access/Disclosure 0 0 0 0
## Other, Unknown 1 0 0 0
## Theft 7 8 1 17
## Theft, Unauthorized Access/Disclosure 0 0 0 0
## Unauthorized Access/Disclosure 0 7 1 10
## Unknown 0 0 0 0
##
## TX UT VA VT
## Hacking/IT Incident 28 4 1 0
## Hacking/IT Incident, Other 0 0 0 0
## Hacking/IT Incident, Other, Unauthorized Access/Disclosure 0 0 0 0
## Hacking/IT Incident, Theft 0 0 0 0
## Hacking/IT Incident, Theft, Unauthorized Access/Disclosure 0 0 0 0
## Hacking/IT Incident, Unauthorized Access/Disclosure 2 0 0 0
## Improper Disposal 6 0 2 0
## Improper Disposal, Loss 2 0 0 0
## Improper Disposal, Loss, Theft 0 0 0 0
## Improper Disposal, Theft 1 0 0 0
## Improper Disposal, Theft, Unauthorized Access/Disclosure 0 0 0 0
## Improper Disposal, Unauthorized Access/Disclosure 0 0 0 0
## Loss 9 0 3 0
## Loss, Other 0 0 1 0
## Loss, Other, Theft 0 1 0 0
## Loss, Theft 4 0 0 0
## Loss, Unauthorized Access/Disclosure 0 0 0 0
## Loss, Unauthorized Access/Disclosure, Unknown 0 0 0 0
## Loss, Unknown 0 0 0 0
## Other 3 1 1 0
## Other, Theft 0 0 0 0
## Other, Theft, Unauthorized Access/Disclosure 0 0 0 0
## Other, Unauthorized Access/Disclosure 0 0 1 0
## Other, Unknown 0 0 0 0
## Theft 64 3 14 2
## Theft, Unauthorized Access/Disclosure 0 0 2 0
## Unauthorized Access/Disclosure 34 2 2 1
## Unknown 1 0 0 0
##
## WA WI WV WY
## Hacking/IT Incident 7 4 1 2
## Hacking/IT Incident, Other 0 0 0 0
## Hacking/IT Incident, Other, Unauthorized Access/Disclosure 0 0 0 0
## Hacking/IT Incident, Theft 0 0 0 0
## Hacking/IT Incident, Theft, Unauthorized Access/Disclosure 0 0 0 0
## Hacking/IT Incident, Unauthorized Access/Disclosure 0 0 0 0
## Improper Disposal 1 0 1 0
## Improper Disposal, Loss 0 0 0 0
## Improper Disposal, Loss, Theft 0 0 0 0
## Improper Disposal, Theft 0 0 0 0
## Improper Disposal, Theft, Unauthorized Access/Disclosure 0 0 0 0
## Improper Disposal, Unauthorized Access/Disclosure 0 0 0 0
## Loss 1 2 0 1
## Loss, Other 0 0 0 0
## Loss, Other, Theft 0 0 0 0
## Loss, Theft 0 0 1 0
## Loss, Unauthorized Access/Disclosure 0 0 0 0
## Loss, Unauthorized Access/Disclosure, Unknown 0 0 0 0
## Loss, Unknown 0 0 0 0
## Other 2 1 0 0
## Other, Theft 0 0 0 0
## Other, Theft, Unauthorized Access/Disclosure 0 0 0 0
## Other, Unauthorized Access/Disclosure 1 0 0 0
## Other, Unknown 0 0 0 0
## Theft 22 8 3 1
## Theft, Unauthorized Access/Disclosure 0 0 0 0
## Unauthorized Access/Disclosure 10 0 3 3
## Unknown 1 0 0 0
In this table, we can easily classify and see the count of which types of breaches are present in each type of entity.
##
## Hacking/IT Incident Hacking/IT Incident, Other
## Business Associate 30 1
## Health Plan 21 0
## Healthcare Clearing House 0 0
## Healthcare Provider 169 1
##
## Hacking/IT Incident, Other, Unauthorized Access/Disclosure
## Business Associate 0
## Health Plan 0
## Healthcare Clearing House 0
## Healthcare Provider 1
##
## Hacking/IT Incident, Theft
## Business Associate 0
## Health Plan 0
## Healthcare Clearing House 0
## Healthcare Provider 1
##
## Hacking/IT Incident, Theft, Unauthorized Access/Disclosure
## Business Associate 1
## Health Plan 0
## Healthcare Clearing House 0
## Healthcare Provider 1
##
## Hacking/IT Incident, Unauthorized Access/Disclosure
## Business Associate 2
## Health Plan 0
## Healthcare Clearing House 0
## Healthcare Provider 6
##
## Improper Disposal Improper Disposal, Loss
## Business Associate 9 1
## Health Plan 7 0
## Healthcare Clearing House 1 0
## Healthcare Provider 40 2
##
## Improper Disposal, Loss, Theft
## Business Associate 2
## Health Plan 0
## Healthcare Clearing House 0
## Healthcare Provider 1
##
## Improper Disposal, Theft
## Business Associate 1
## Health Plan 0
## Healthcare Clearing House 0
## Healthcare Provider 0
##
## Improper Disposal, Theft, Unauthorized Access/Disclosure
## Business Associate 0
## Health Plan 0
## Healthcare Clearing House 0
## Healthcare Provider 1
##
## Improper Disposal, Unauthorized Access/Disclosure
## Business Associate 0
## Health Plan 0
## Healthcare Clearing House 0
## Healthcare Provider 1
##
## Loss Loss, Other Loss, Other, Theft Loss, Theft
## Business Associate 19 1 0 2
## Health Plan 13 0 0 0
## Healthcare Clearing House 0 0 0 0
## Healthcare Provider 97 1 1 12
##
## Loss, Unauthorized Access/Disclosure
## Business Associate 3
## Health Plan 0
## Healthcare Clearing House 0
## Healthcare Provider 0
##
## Loss, Unauthorized Access/Disclosure, Unknown
## Business Associate 1
## Health Plan 0
## Healthcare Clearing House 0
## Healthcare Provider 0
##
## Loss, Unknown Other Other, Theft
## Business Associate 0 22 1
## Health Plan 0 16 0
## Healthcare Clearing House 0 0 0
## Healthcare Provider 1 36 2
##
## Other, Theft, Unauthorized Access/Disclosure
## Business Associate 0
## Health Plan 0
## Healthcare Clearing House 0
## Healthcare Provider 2
##
## Other, Unauthorized Access/Disclosure
## Business Associate 3
## Health Plan 3
## Healthcare Clearing House 0
## Healthcare Provider 1
##
## Other, Unknown Theft
## Business Associate 0 108
## Health Plan 0 43
## Healthcare Clearing House 0 2
## Healthcare Provider 2 559
##
## Theft, Unauthorized Access/Disclosure
## Business Associate 10
## Health Plan 0
## Healthcare Clearing House 0
## Healthcare Provider 15
##
## Unauthorized Access/Disclosure Unknown
## Business Associate 67 1
## Health Plan 95 2
## Healthcare Clearing House 1 0
## Healthcare Provider 261 6
In this data table, we are able to see if there was a Business Associate Present for each Location of Breached Information
##
## Desktop Computer Desktop Computer, Electronic Medical Record
## No 121 3
## Yes 12 0
##
## Desktop Computer, Electronic Medical Record, Email, Laptop, Network Server
## No 1
## Yes 0
##
## Desktop Computer, Electronic Medical Record, Email, Laptop, Network Server, Other, Other Portable Electronic Device
## No 1
## Yes 0
##
## Desktop Computer, Electronic Medical Record, Email, Laptop, Network Server, Other, Other Portable Electronic Device, Paper/Films
## No 0
## Yes 1
##
## Desktop Computer, Electronic Medical Record, Email, Laptop, Other Portable Electronic Device
## No 1
## Yes 0
##
## Desktop Computer, Electronic Medical Record, Email, Laptop, Other, Other Portable Electronic Device, Paper/Films
## No 1
## Yes 0
##
## Desktop Computer, Electronic Medical Record, Email, Network Server
## No 1
## Yes 0
##
## Desktop Computer, Electronic Medical Record, Email, Network Server, Paper/Films
## No 1
## Yes 0
##
## Desktop Computer, Electronic Medical Record, Laptop
## No 2
## Yes 0
##
## Desktop Computer, Electronic Medical Record, Laptop, Network Server
## No 1
## Yes 0
##
## Desktop Computer, Electronic Medical Record, Network Server
## No 1
## Yes 1
##
## Desktop Computer, Email Desktop Computer, Email, Laptop, Network Server
## No 1 6
## Yes 0 0
##
## Desktop Computer, Email, Laptop, Network Server, Other Portable Electronic Device
## No 1
## Yes 0
##
## Desktop Computer, Email, Laptop, Network Server, Other, Other Portable Electronic Device
## No 0
## Yes 1
##
## Desktop Computer, Email, Network Server Desktop Computer, Laptop
## No 1 11
## Yes 0 0
##
## Desktop Computer, Laptop, Network Server
## No 2
## Yes 0
##
## Desktop Computer, Laptop, Network Server, Other Portable Electronic Device
## No 1
## Yes 0
##
## Desktop Computer, Laptop, Other Portable Electronic Device
## No 1
## Yes 3
##
## Desktop Computer, Laptop, Other, Other Portable Electronic Device
## No 1
## Yes 0
##
## Desktop Computer, Laptop, Paper/Films Desktop Computer, Network Server
## No 0 12
## Yes 1 1
##
## Desktop Computer, Network Server, Other, Other Portable Electronic Device
## No 1
## Yes 0
##
## Desktop Computer, Network Server, Paper/Films Desktop Computer, Other
## No 1 2
## Yes 0 0
##
## Desktop Computer, Other Portable Electronic Device
## No 4
## Yes 0
##
## Desktop Computer, Other Portable Electronic Device, Paper/Films
## No 1
## Yes 0
##
## Desktop Computer, Other, Other Portable Electronic Device
## No 1
## Yes 0
##
## Desktop Computer, Other, Other Portable Electronic Device, Paper/Films
## No 1
## Yes 0
##
## Desktop Computer, Paper/Films Electronic Medical Record
## No 6 60
## Yes 2 4
##
## Electronic Medical Record, Email, Laptop, Paper/Films
## No 1
## Yes 0
##
## Electronic Medical Record, Laptop
## No 1
## Yes 0
##
## Electronic Medical Record, Laptop, Network Server, Other, Other Portable Electronic Device
## No 1
## Yes 0
##
## Electronic Medical Record, Network Server
## No 6
## Yes 2
##
## Electronic Medical Record, Other
## No 4
## Yes 1
##
## Electronic Medical Record, Other, Other Portable Electronic Device
## No 0
## Yes 2
##
## Electronic Medical Record, Paper/Films Email Email, Laptop
## No 7 128 0
## Yes 0 14 1
##
## Email, Laptop, Network Server
## No 2
## Yes 0
##
## Email, Laptop, Other Portable Electronic Device
## No 1
## Yes 0
##
## Email, Laptop, Paper/Films Email, Network Server
## No 1 3
## Yes 0 1
##
## Email, Network Server, Other Portable Electronic Device Email, Other
## No 1 2
## Yes 0 0
##
## Email, Other Portable Electronic Device Laptop Laptop, Network Server
## No 2 232 3
## Yes 3 42 0
##
## Laptop, Other Laptop, Other Portable Electronic Device
## No 2 14
## Yes 0 2
##
## Laptop, Other Portable Electronic Device, Paper/Films Laptop, Paper/Films
## No 2 7
## Yes 0 1
##
## Network Server Network Server, Other Network Server, Paper/Films Other
## No 136 3 1 114
## Yes 77 1 1 51
##
## Other Portable Electronic Device
## No 85
## Yes 16
##
## Other Portable Electronic Device, Paper/Films
## No 2
## Yes 0
##
## Other, Other Portable Electronic Device Other, Paper/Films Paper/Films
## No 31 8 308
## Yes 15 0 97
This output shows the count of unique variations of different types of breaches. We can see which breaches happen most often together and which breaches are typically stand alone breaches.
##
## Hacking/IT Incident
## 220
## Hacking/IT Incident, Other
## 2
## Hacking/IT Incident, Other, Unauthorized Access/Disclosure
## 1
## Hacking/IT Incident, Theft
## 1
## Hacking/IT Incident, Theft, Unauthorized Access/Disclosure
## 2
## Hacking/IT Incident, Unauthorized Access/Disclosure
## 8
## Improper Disposal
## 57
## Improper Disposal, Loss
## 3
## Improper Disposal, Loss, Theft
## 3
## Improper Disposal, Theft
## 1
## Improper Disposal, Theft, Unauthorized Access/Disclosure
## 1
## Improper Disposal, Unauthorized Access/Disclosure
## 1
## Loss
## 129
## Loss, Other
## 2
## Loss, Other, Theft
## 1
## Loss, Theft
## 14
## Loss, Unauthorized Access/Disclosure
## 3
## Loss, Unauthorized Access/Disclosure, Unknown
## 1
## Loss, Unknown
## 1
## Other
## 74
## Other, Theft
## 3
## Other, Theft, Unauthorized Access/Disclosure
## 2
## Other, Unauthorized Access/Disclosure
## 7
## Other, Unknown
## 2
## Theft
## 712
## Theft, Unauthorized Access/Disclosure
## 25
## Unauthorized Access/Disclosure
## 424
## Unknown
## 9
Number of Healthcare Data Breaches by Year
List of the Top 25 Largest Healthcare Data Breaches
Total Healthcare Records (individuals affected) Exposed by State for the Top 10 States
Number of Healthcare Hacking Incidents by Month
Number of Breaches by Covered Entity Type
On what day of the week (Sunday, Monday, etc.) are breaches most often reported?
There are much fewer reports happening on the weekends when businesses
are not operating. Friday (6) has the most reports by far. This could be
because individuals know that businesses may not stay up to date with
their work over the weekend.
In which year (or years) were there at least 50 breaches from a ‘Business Associate’ covered entity type and at least 150 breaches from a healthcare provider covered entity type?
In 2013 and 2014, there were at least 50 breaches from a “Business Associate” and at least 150 breaches from a healthcare provider covered entity type.
How has the type of breach (hacking, improper disposal, loss, etc.) changed for each year? For example, the visual should help assess whether hacking / IT Incidents or Theft were more prevalent in 2014 and whether this trend was maintained in 2015?
Which entities had email breaches with more than 90,000 individuals affected?
From this bar graph, we can understand that South Carolina Department of
Health and Human Services had 228435 individuals affected through email
breach and Washington State Health Care Authority had 91187 individuals
affected through email. I was shocked to see only 2 entities with the
location of email breach having affected more than 90,000 individuals.
Today, hacking email systems seems to be very common.
For each Covered Entity type, how many of them occur because of Theft, Loss,or the combination of Theft and Loss?
What is the average individuals affected by breach per year?
This graph shows us exponentially, on average, how many individuals were affected each year. 2015 seems to be the year with the highest amount of individuals affected. 2018 produces the lowest average amount of individuals affected by year.