HomeKnowledge HubEnforcement Trackers › HHS OCR Breach Portal

Official breach register · Enforcement Trackers

The HHS Breach Portal — a public, structured record of every large US health-data breach

HHS Office for Civil RightsStatutory registerFree

US law requires HIPAA covered entities to notify the Secretary of Health and Human Services of any breach of unsecured protected health information affecting 500 or more individuals, and the Office for Civil Rights publishes those reports. The result is an open, coded dataset of health-sector breaches that has no UK equivalent.

Published by
US Department of Health and Human Services, Office for Civil Rights (OCR).
Type
Official register of reported breaches affecting 500 or more individuals; OCR investigates all such breaches.
Versions and language
Live web portal with separate HIPAA and 42 CFR Part 2 lists. English.
Jurisdiction
United States — HIPAA covered entities and business associates; Part 2 programs.
Primary audience
Security and privacy teams benchmarking breach causes; health-sector DPOs; researchers.
Topic tags
breach notification · healthcare · HIPAA · incident trends · UK GDPR Art. 33/34 comparator
Availability
Free, no registration. When we checked the list in August 2026 it offered export to spreadsheet, PDF, CSV and XML formats.

Why it matters

Breaches affecting 500 or more individuals must be reported to the Secretary without unreasonable delay and within 60 calendar days of discovery; smaller breaches are reported annually. Each posted entry records the entity, its state, the type of entity (provider, health plan, business associate), the number of individuals affected, the type of breach and the location of the information — which lets a reader see, for a whole sector, what actually goes wrong and where. The portal now also takes and lists breaches of 42 CFR Part 2 (substance-use-disorder) records.

The UK position. The ICO publishes data security incident trends as aggregated statistics and lists enforcement outcomes, but there is no UK public register of notified breaches — Article 33 notifications to the ICO are not published. So this dataset is not a comparator for UK legal duties; it is a source of evidence for likelihood arguments in a DPIA or a security business case, with the caveat that it covers one sector in one country under a definition of “breach” (45 CFR 164.402) that differs from Article 4(12).

Related: the FTC Legal Library for US privacy and data security enforcement outside the health sector.

A curated reference entry maintained by VulaPri. We summarise and link to the original; we do not reproduce or host it. Listed since 15 September 2026 · last verified 15 September 2026 — facts verified against hhs.gov (breach reporting page, content last reviewed 13 February 2026) and the ocrportal.hhs.gov front page, 11 September 2026; the list-page fields and export formats were last checked in a browser on 7 August 2026. Suggest a correction.