An official website of the United States government

Here’s how you know

Official websites use .gov
A .gov website belongs to an official government organization in the United States.

Secure .gov websites use HTTPS
A lock ( ) or https:// means you’ve safely connected to the .gov website. Share sensitive information only on official, secure websites.

ASTP Logo
Skip Navigation
  • Topics
      • Featured
        • Featured

        • Certification of Health IT

          Ensures health IT meets standards for functionality, security, and interoperability.

        • Information Blocking

          Regulations ensuring health data is shared appropriately without improper barriers.

        • Interoperability

          Enables secure and seamless exchange of electronic health information among authorized users.

        • Health Information Technology Advisory Committee (HITAC)

          Advises on policies, standards, and implementation specifications for health data and technology.

        • United States Core Data for Interoperability (USCDI)

          Offers a standardized set of health data classes and constituent data elements for nationwide, interoperable health information exchange.

        • Trusted Exchange Framework & Common Agreement (TEFCA)

          Operates as a nationwide framework for the interoperability of electronic health information.

      • Artificial Intelligence
        • Artificial Intelligence

        • Artificial Intelligence (AI) at HHS

          HHS’ list of AI use cases is publicly available to search and reference. In addition to AI use case summaries, the inventory also includes information on data, IT infrastructure, internal governance, and much more.

      • Care Continuum
        • Care Continuum

          Explore the roles of health information and technology in broad healthcare settings, supporting seamless, coordinated patient care from prevention through recovery.

        • Care Settings

        • Behavioral Health

          Health information, policies, and technology supporting integrated care for mental health and substance use disorders.

        • Emergency Medical Services

          Rapid response and communication during health emergencies through health information and technology.

        • Long-Term & Post-Acute Care

          Health information and technology facilitating coordinated care beyond acute settings.

        • Maternal & Pediatric Care

          Technology addressing unique health needs of mothers and children.

        • Pharmacy & PDMP

          Electronic tools tracking controlled substance prescriptions to improve patient safety.

        • Public Health

          Using health information and technology to prevent disease, diagnose health conditions, and promote population health.

        • Clinical Topics

        • Clinical Quality & Safety

          Optimal care through measuring results, prioritizing improvements, and implementing and monitoring results.

        • Usability & Provider Burden

          Promotes health information and technology usability to reduce clinician burden and enhance patient care.

      • Interoperability
        • Interoperability

          Promotes standardized exchange and use of electronic health data to improve patient care, coordination, and public health outcomes.

        • Health IT Interoperability

          Enables secure and seamless exchange of electronic health information among authorized users.

        • Trusted Exchange Framework & Common Agreement (TEFCA)

          Facilitates secure, nationwide electronic health information sharing to connect providers, patients, public health agencies, and payers.

        • Certification of Health IT

          Provides certification criteria for developers of health IT modules that ensures health IT products meet the standards for functionality, security, and interoperability.

        • Standards & Technology

          Advance healthcare quality and safety through standardized health IT and secure health data exchange.

        • Information Blocking

          Prevents practices that interfere with the access, exchange, or use of electronic health information, as defined by the Cures Act.

        • Interoperability Standards Platform

          Serves as a homepage for tools and resources for understanding and using health IT standards and technologies.

        • Investments

          Support interoperability improvements nationwide.

        • Health IT & Health Information Exchange Basics

          Enable secure electronic sharing and access of patient health information, supporting healthcare providers and patients across care settings.

        • Patient Access to Health Records

          Ensure patients have secure and convenient access to their health records, supported by healthcare providers and health IT developers under HIPAA.

      • Policy
          • Policy

            Outlines federal regulations and strategic initiatives guiding effective use and secure exchange of electronic health information.

            • Legislation

              Delivers improvements in the delivery and experience of health care while enhancing health outcomes by leveraging health information technology.

            • Regulations

              Supports the adoption and promotion of standards-based health information.

            • TEFCA

              Operates as a nationwide framework for the interoperability of electronic health information.

            • HHS Health IT Alignment Program

              Coordinates health data and technology initiatives across HHS to enhance interoperability and effectiveness.

            • Health Information Technology Advisory Committee (HITAC)

              Advises on policies, standards, and implementation specifications for health data and technology.

            • Privacy & Security

              Protects electronic health information security through policy.

          • Rulemaking

          • HTI Rules

            Health data interoperability regulations ensuring secure, effective technology use.

          • Information Blocking

            Policies to prevent practices interfering with the access, exchange, and use of electronic health information.

          • Certification Program Rules

            Ensures health IT meets standards for functionality, security, and interoperability.

      • Research & Analysis
        • Research & Analysis

          Interactive datasets related to health IT data analysis, providing insights into adoption and use.

        • Dashboards

          Gives data-driven insight on how dashboards are driving health IT adoption and how they have helped users to meet federal healthcare incentives or programs.

        • Data Briefs

          Provides health IT adoption and use statistics derived from surveys and administrative data and in-depth analysis of health IT policies and programs.

        • Datasets

          Grants access to raw datasets from ASTP related to health IT adoption, health IT capabilities and other topics.

        • Quick Stats

          Streamlines data into visualizations of key data and summarizes the latest statistics, facts and figures about health IT.

        • About Health IT Research & Analysis

          Provides information about how health IT data are collected, analyzed, and published.

  • Resources & Tools
      • Featured
        • Featured Resources & Tools

          Highlights key tools and guidance supporting effective health IT implementation, interoperability, patient engagement, and compliance with federal standards.

        • Interoperability Standards

          ASTP’s initiatives in health data standards enable secure electronic health data exchange.

        • TEFCA Resources

          Data sheets, videos, and documents to guide users of the TEFCA framework and exchange.

        • Implementation Resources

          Technical resources and tools supporting healthcare providers, clinicians, and developers of health IT products.

        • Health IT Playbook

          Strategies, recommendations, and best practices for implementing and using health data and technology.

        • Security Risk Assessment Tool

          Desktop application supporting providers conducting HIPAA security risk assessments.

        • Patient Engagement Playbook

          Practical reference tool for clinicians, staff, and other innovators around the world to improve patient engagement.

        • Certified Health IT Product List (CHPL)

          A comprehensive and authoritative listing of successfully tested and certified health IT modules.

        • Conformance Test Tools & Edge Testing Tool

          Resources for developers implementing standards to enable health information interoperability.

        • Health IT Feedback Form

          Users can submit feedback regarding health data and technology usability, interoperability, and compliance issues.

      • Resources
        • Resources

          Collection of practical materials, videos, educational tools, and user guides designed to support successful implementation and adoption of health IT systems.

        • Get It, Check It, Use It Guide

          A guide for patients and caregivers who want to access, review, and use their health records.

        • Video Resources

          A repository of informational videos created by ASTP.

        • Health IT Curriculum Resources for Educators

          Instructional materials to help healthcare workers stay current in the changing healthcare environment and deliver care more effectively.

        • Fact Sheets

          A repository of fact sheets created by ASTP.

      • Tools & Technology
          • Implementation

          • Certified Health IT Product List

            A comprehensive and authoritative listing of successfully tested and certified health IT modules.

          • Electronic Clinical Quality Improvement Resource Center

            Provides common standards and shared technologies to monitor and analyze the quality of health care and patient outcomes.

          • Security Risk Assessment Tool

            Desktop application supporting providers conducting HIPAA security risk assessments.

          • Tools

          • Edge Testing Tool

            A centralized collection of testing tools and resources supporting health IT developers and users fully evaluating specific technical standards.

          • Conformance Test Tools

            ONC-approved conformance resources supporting developers implementing standards to enable health information interoperability.

          • Get It, Check It, Use It Guide

            A guide for patients and caregivers who want to access, review, and use their health records.

          • Quick Links

          • Certification & Testing
          • USCDI
          • USCDI+
          • Interoperability Standards Platform (ISP)
          • FHIR
          • ASTP Standards Bulletins
          • Patient ID & Matching Adopted Standards for HHS
  • News & Events
      • Media Center
      • ASTP Blog
      • News
      • Events
      • Featured Blogs & News

      • HTI-5 Proposed Rule

        HTI-5 Proposed Rule

        HTI-5 Proposed Rule The Assistant Secretary for Technology Policy/Office of the National Coordinator for Health Information Technology (ASTP/ONC) published the…

        TEFCA’s growing, are you in? Take a look at who’s participating in TEFCA Exchange

        TEFCA’s growing, are you in? Take a look at who’s participating in TEFCA Exchange

        We are pleased to announce that the beta version of an interactive, searchable map for TEFCAâ„¢ participation is now available. The map released today is another example of our commitment to transparency.

        USCDI v6 and Standards Bulletin 25-2

        USCDI v6 and Standards Bulletin 25-2

        The United States Core Data for Interoperability Version 6 (USCDI v6) is now available! USCDI v6 includes an updated list of data classes and elements that seek to advance health data in a way that will benefit users of health IT. We also released the latest Standards Bulletin, which describes ASTP’s continued expansion of USCDI.

  • About
      • Overview
        • About ASTP

          Mission, role, and responsibilities of ASTP.

        • Leadership

          Profiles of ASTP’s senior leadership team.

        • History

          Timeline of ASTP’s evolution and key milestones.

        • Budget & Performance

          Financial reports and performance accountability.

        • Investments

          Strategic investments in programs, policies, and technology.

        • Reports to Congress

          Annual health data and technology progress updates to Congress.

      • Careers
        • Careers at ASTP

          View opportunities with ASTP.

        • Working at ASTP

          Overview of workplace culture and employee experience.

      • Contact
        • Contact Us

          Reach ASTP with general inquiries.

        • Health IT Feedback Form

          Users can submit feedback regarding health data and technology usability, interoperability, and compliance issues.

        • Report Issue with Certified Health IT

          Complaint process to resolve any issues of potential noncompliance with certification requirements.

        • Information Blocking Claim

          Form to report alleged information blocking practices.

        • Speaker Request

          Form to request ASTP experts for speaking engagements.

      • Funding Opportunities
        • Funding Announcements

          ASTP’s contractors and grantees play a valuable role in helping promote better health care for Americans by fostering interoperable health data and technology.

        • Grants Management & Process

          Learn about opportunities for funding through grants and cooperative agreements.

Popular searches: certifications information blocking interoperability

Health IT Research & Analysis

    • Data Types
    • Categories
    • Sort By
Quick Stats iconQuick Stats

Breaches of Unsecured Protected Health Information

Last Updated

June 2021

Link to Page Icon Link to Page
  • Overview
  • Notes
Source

U.S. Department of Health and Human Services (HHS) Office for Civil Rights. Breaches Affecting 500 or More Individuals: https://ocrportal.hhs.gov/ocr/breach/breach_report.jsf. February 1, 2016.

Citation

Office of the National Coordinator for Health Information Technology. ‘Breaches of Unsecured Protected Health Information,’ Health IT Quick-Stat #53. https://www.healthit.gov/data/quickstats/breaches-unsecured-protected-health-information. February 2016.

Based upon data collected by the HHS Office for Civil Rights, as of February 1, 2016, protected health information breaches affected over 113 million individuals in 2015. In 2015, hacking incidents comprised nearly 99% of all individuals affected by breaches, and the number of reported hacking incidents, 57, comprised over 20% of all reported breaches. From 2011 to 2014, 97 hacking incidents affected less than 4 million individuals – less than 10% of all reported breaches and affected individuals during this time.

However, despite the rise in breaches related to hacking incidents, reported breaches related to other incidents and the number of individuals affected by these breaches are down in 2015. Through February 1, 2016, theft, loss, improper disposal, and unauthorized access or disclosure of protected health information comprise 208 of all reported breaches (N=265), down from 216 (N=285) in 2014 and 211 (N=262) in 2013. These four types of breach incidents affected 1.4 million individuals in 2015, compared to 10.7 million in 2014 and 6.7 million in 2013.

In 2015, four of the fifty-one hacking incidents involved an electronic medical record (EMR). One hacking incident affected 3.9 million individuals’ health information – nearly all the individuals affected by an EMR hacking incident in 2015.

Note: ^a non-hacking/IT incident includes all other types of reported health information breaches: theft, loss, improper disposal, unauthorized access/disclosure, other, or unknown (not reported or data missing). See notes below for types of IT and devices involved in these incidents.

Number of Individuals Affected by a Protected Health Information Breach: 2010-2015

Count of affected individuals by the type and source of information breach

 201020112012201320142015
Type of Information Breach
Hacking/IT incident568,358297,269900,684236,8971,786,630111,812,172
(Of this total, 78M individuals (70%) were affected by a singular hacking/IT incident, and 5 of the 51 hacking/IT incidents affected 97% of all individuals)
Improper disposal34,58763,94821,329526,53893,61282,421
Loss924,9096,019,57895,815142,411243,37647,214
Theft3,691,4604,720,129927,9095,397,9897,058,678740,598
Unauthorized access/disclosure130,106118,444338,767383,7593,019,284572,919
Other breach158,59313,981503,900254,305413,878—
Source of Information Breach
Desktop computer246,6432,042,18681,3854,348,1292,378,304316,226
Electronic medical record803,6001,720,064
(Of this total, 1.7M individuals (99%) were affected by a singular incident)
136,75140,196121,8453,948,985
(Of this total, 3.9M individuals (99%) were affected by a singular incident)
E-mail8,0503,111294,30858,847519,625583,977
Laptop1,507,914405,873575,5291,023,1811,273,612391,830
Network server665,123613,963921,335320,1277,253,441107,252,466
(All but 26,000 individuals were affected by a hacking/IT incident)
Paper/Film204,966103,711198,409575,076590,352229,743
Portable Electronic Device29,7141,516124,978154,877141,110209,558
Other source2,058,1668,259,368455,709422,381343,537322,539
Note: Each count above is the total number of individuals affected by a breach of the specific information source and the breach type. Individual reports of a breach may involve one or more information sources, i.e. laptop, e-mail, etc, and one or more breach types, i.e. theft, loss, etc. In those cases, there may be double-counting of the number of affected individuals or reported breaches in a specific year.
Source: U.S. Department of Health and Human Services (HHS) Office for Civil Rights. Breaches Affecting 500 or More Individuals. February 1, 2016.

Number of Reported Protected Health Information Breaches: 2010-2015

Count of reported breaches by the type and source of information breach

 201020112012201320142015
Type of Information Breach
Hacking/IT incident101616233257
(4 of these incidents involved an electronic medical record)
Improper disposal107713116
Loss181719242822
Theft12711811712411380
Unauthorized access/disclosure726256372100
Other breach2221824280
Source of Information Breach
Desktop computer283523392929
Electronic medical record366141416
E-mail5210203637
Laptop503851674238
Network server171620304641
(34 of these breaches involved a hacking/IT incident)
Paper/Film464547536267
Portable Electronic Device6219202215
Other source425026243422
Note: Each count above is the total number of reported breach incidents of the specific information source and the breach type. Individual reports of a breach may involve one or more information sources, i.e. laptop, e-mail, etc, and one or more breach types, i.e. theft, loss, etc. In those cases, there may be double-counting of the number of reported incidents or reported breaches in a specific year.
Source: U.S. Department of Health and Human Services (HHS) Office for Civil Rights. Breaches Affecting 500 or More Individuals. February 1, 2016.
  1. The HIPAA Breach Notification Rule, http://www.hhs.gov/ocr/privacy/hipaa/understanding/coveredentities/breachnotificationifr.html, requires health care providers, health plans, and other HIPAA covered entities to notify affected individuals when their health information is breached, as well as the HHS Secretary and the media where a breach affects more than 500 individuals. As required by section 13402(e)(4) of the HITECH Act, the Secretary of HHS must post a list of breaches of unsecured protected health information affecting 500 or more individuals.
  2. A breach may involve any of the following types of incidents: theft, loss, hacking/IT incident, improper disposal, unauthorized access/disclosure, other, or unknown (not reported or data missing).
  3. Breach incidents may involve any of the following information, information technology, or devices: paper/films, network server, laptop, desktop computer, e-mail, electronic medical record, other portable electronic device, or other.
Submit Feedback

Submit HealthIT.gov Feedback

Step 1 of 3

33%
Name(Required)
Please provide your email address for follow-up.
What kind of issue are you experiencing?(Required)
Select the type of issue you encountered. Select all that apply.
Where did you experience this issue?(Required)
Select the type of issue you encountered. Select all that apply.
Example: Google Chrome on PC or Safari on iPhone.

Page Information

What page did you find this issue? e.g. Interoperability, ASTP Blog
e.g. https://beta.healthit.gov/interoperability
Please provide a detailed description of the issue you experienced.
Drop files here or
Max. file size: 3 MB, Max. files: 3.
    If you have any screenshots or files related to the issue, please upload them here.

    Subscribe for Email Updates

    This field is for validation purposes and should be left unchanged.

    EXPLORE

    • Certification of Health IT
    • Information Blocking
    • Interoperability
    • Health Information Technology Advisory Committee (HITAC)
    • Patient Access to Health Records
    • TEFCA
    • Policy
    • Resources

    DATA

    • HealthData.gov
    • Health IT Research & Analysis

    NEWS & EVENTS

    • Media Center
    • ASTP Blog
    • News
    • Events

    ABOUT

    • About ASTP/ONC
    • Careers
    • Contact
    • Funding Opportunities
    ASTP Logo HHS
    Linkedin
    X
    YouTube
    • Privacy Policy
    • Website Disclaimers
    • Viewers & Players
    • GobiernoUSA.gov
    • HHS Vulnerability Disclosure Policy
    • Archived Content

    External Link Notice

    Welcome to HealthIT.gov!

    Thank you for visiting the HealthIT.gov website! We welcome your feedback using the "Submit Feedback" button at the bottom of the page to help us improve your experience!