HIPAA Breach Tracker
A reference look at healthcare data breaches and OCR enforcement in the United States, with a focus on Florida — context for why HIPAA compliance isn't optional.
Healthcare breaches, at scale
Reported healthcare breaches nationally since 2009
Individuals affected across all reported breaches
Total OCR fines issued to date
OCR enforcement cases, 2008–2025
Average fine per OCR enforcement case
Florida's national rank for people affected by breaches
Where South Florida stands
Florida is one of the most-affected states in the country — directly relevant to any healthcare organization operating here.
Reported breaches in Florida
Individuals affected in Florida
Of Florida breaches involved a hacking/IT incident
Hacking is now the leading cause
Across the tracked data, hacking and IT incidents make up the majority of Florida's reported breaches — ahead of lost devices, improper disposal, or unauthorized access. That shift is exactly why network security, cloud security, and 24/7 monitoring matter as much as paperwork when it comes to HIPAA compliance.
- Firewalls and network segmentation reduce exposure
- Continuous monitoring catches incidents early
- Staff training closes the human-error gap
- Documented policies hold up under an OCR audit
Where these numbers come from
| Source | Coverage |
|---|---|
| HHS Office for Civil Rights (OCR) Breach Portal | Ongoing breach reporting database |
| HHS OCR official enforcement reports | 2018–2022 |
| HIPAA Journal | 2008–2017 and 2023–2025 |
We update this page periodically as new data is published. If you find a figure that looks out of date, let us know.
Don't wait to become a statistic
A HIPAA Risk Assessment shows you exactly where your organization stands today.