Reference Data — updated August 2026

HIPAA Breach Tracker

A reference look at healthcare data breaches and OCR enforcement in the United States, with a focus on Florida — context for why HIPAA compliance isn't optional.

National Picture

Healthcare breaches, at scale

7,159

Reported healthcare breaches nationally since 2009

915M+

Individuals affected across all reported breaches

$158M+

Total OCR fines issued to date

175

OCR enforcement cases, 2008–2025

$905K

Average fine per OCR enforcement case

#4

Florida's national rank for people affected by breaches

Florida Spotlight

Where South Florida stands

Florida is one of the most-affected states in the country — directly relevant to any healthcare organization operating here.

416

Reported breaches in Florida

50.5M

Individuals affected in Florida

52%

Of Florida breaches involved a hacking/IT incident

What This Means

Hacking is now the leading cause

Across the tracked data, hacking and IT incidents make up the majority of Florida's reported breaches — ahead of lost devices, improper disposal, or unauthorized access. That shift is exactly why network security, cloud security, and 24/7 monitoring matter as much as paperwork when it comes to HIPAA compliance.

  • Firewalls and network segmentation reduce exposure
  • Continuous monitoring catches incidents early
  • Staff training closes the human-error gap
  • Documented policies hold up under an OCR audit
Sources & Methodology

Where these numbers come from

SourceCoverage
HHS Office for Civil Rights (OCR) Breach PortalOngoing breach reporting database
HHS OCR official enforcement reports2018–2022
HIPAA Journal2008–2017 and 2023–2025

We update this page periodically as new data is published. If you find a figure that looks out of date, let us know.

Don't wait to become a statistic

A HIPAA Risk Assessment shows you exactly where your organization stands today.