The HHS Breach Portal — a public, structured record of every large US health-data breach
US law requires HIPAA covered entities to notify the Secretary of Health and Human Services of any breach of unsecured protected health information affecting 500 or more individuals, and the Office for Civil Rights publishes those reports. The result is an open, coded dataset of health-sector breaches that has no UK equivalent.
- Published by
- US Department of Health and Human Services, Office for Civil Rights (OCR).
- Type
- Official register of reported breaches affecting 500 or more individuals; OCR investigates all such breaches.
- Versions and language
- Live web portal with separate HIPAA and 42 CFR Part 2 lists. English.
- Jurisdiction
- United States — HIPAA covered entities and business associates; Part 2 programs.
- Primary audience
- Security and privacy teams benchmarking breach causes; health-sector DPOs; researchers.
- Topic tags
- breach notification · healthcare · HIPAA · incident trends · UK GDPR Art. 33/34 comparator
- Availability
- Free, no registration. When we checked the list in August 2026 it offered export to spreadsheet, PDF, CSV and XML formats.
Why it matters
Breaches affecting 500 or more individuals must be reported to the Secretary without unreasonable delay and within 60 calendar days of discovery; smaller breaches are reported annually. Each posted entry records the entity, its state, the type of entity (provider, health plan, business associate), the number of individuals affected, the type of breach and the location of the information — which lets a reader see, for a whole sector, what actually goes wrong and where. The portal now also takes and lists breaches of 42 CFR Part 2 (substance-use-disorder) records.
The UK position. The ICO publishes data security incident trends as aggregated statistics and lists enforcement outcomes, but there is no UK public register of notified breaches — Article 33 notifications to the ICO are not published. So this dataset is not a comparator for UK legal duties; it is a source of evidence for likelihood arguments in a DPIA or a security business case, with the caveat that it covers one sector in one country under a definition of “breach” (45 CFR 164.402) that differs from Article 4(12).
Related: the FTC Legal Library for US privacy and data security enforcement outside the health sector.
