Another Brutal Year for Patient Data
2025 did not break the record set by the Change Healthcare attack—that catastrophic breach affected 193 million people and remains the worst in healthcare history. But 605 healthcare breaches were still reported to HHS, affecting 44.3 million Americans.
The numbers tell a familiar story: healthcare remains one of the most targeted sectors, and the patterns of failure repeat year after year. Understanding what happened in 2025 is essential for organizations determined to avoid becoming 2026 statistics.
Take the 2-Minute Cybersecurity Assessment
The Biggest Breaches of 2025
Yale New Haven Health System: 5.56 Million Affected
Connecticut’s largest health system detected unusual activity on March 8, 2025. Hackers had breached the network and obtained sensitive data including names, contact information, demographic data, medical record numbers, and Social Security numbers. The electronic medical records system was not accessed, but the breach affected 5.56 million patients.
Episource: 5.42 Million Affected
This IT vendor providing risk adjustment and medical coding services to health plans suffered a ransomware attack in February 2025. When a vendor with access to multiple health systems gets breached, the impact cascades across their entire client base.
Blue Shield of California: 4.7 Million Affected
This breach was different—it was not a hack but a configuration error. Google Analytics had been improperly configured in a way that could have allowed Google Ads to deliver ad campaigns back to impacted members. Blue Shield severed the connection in January 2024 but notified members throughout 2025.
McLaren Health Care: 743,131 Affected
Michigan’s McLaren Health Care suffered its second ransomware attack in two years. The Inc Ransom group claimed responsibility. Attackers had access between July 17 and August 3, 2024, but the breach was not fully understood until May 2025. Being hit twice in two years illustrates that recovery without fundamental security improvements just sets up the next attack.
Covenant Health: 478,188 Affected
The Qilin ransomware group struck this Catholic healthcare organization in May 2025, claiming to have stolen 850 GB of data. Hospitals in Maine, New Hampshire, and Massachusetts experienced system shutdowns. Wait times increased and some services were only available with paper orders.
The Patterns That Keep Repeating
- Third-Party Vendor Risk
The Episource and Conduent breaches demonstrate that healthcare security extends far beyond hospital walls. When billing companies, IT vendors, and business associates get breached, patient data goes with them. Many healthcare organizations still lack visibility into their vendor ecosystem’s security practices.
- Delayed Detection
McLaren’s attackers had access for over two weeks before detection. Many breaches take months to fully investigate. The time between intrusion and detection—dwell time—remains dangerously long in healthcare.
- Repeat Targets
McLaren was hit twice in two years. Organizations that recover from ransomware without addressing fundamental security gaps become known as easy targets who will pay or suffer again.
What Experts Predict for 2026
Dave Bailey, vice president of security services at Clearwater, notes a clear shift from opportunistic attacks to highly coordinated, multi-stage operations. He predicts more disruptive attacks masquerading as traditional ransomware events, with attackers corrupting backups and damaging infrastructure to maximize pressure.
AI-enabled attacks that dramatically compress the time from initial access to impact are becoming more common. Healthcare organizations relying on manual processes will struggle to keep pace.
Take Our 2-Minute Security Assessment
centrexIT has protected San Diego healthcare organizations since 2002. If you’re not sure how your organization would fare against the attacks targeting healthcare, let’s find out together.
Take the 2-Minute Cybersecurity Assessment
Sources
- HHS Office for Civil Rights Breach Portal—605 breaches, 44.3 million affected (December 2025)
- HIPAA Journal: “Largest Healthcare Data Breaches of 2025” (January 2, 2026)
- Chief Healthcare Executive: “These are the biggest health data breaches in the first half of 2025” (December 2025)
- Bank Info Security: “2025 in Health Data Breaches and Predictions for 2026” (December 2025)
- The Record: “Nearly 480,000 impacted by Covenant Health data breach” (January 2, 2026)


