HealthcareBreaches.com is a free dashboard, built by Stern Security, that tracks U.S. healthcare data breaches. It combines HHS’s official breach records, which only cover incidents affecting 500 or more patient records, with Stern Security’s own investigation research into how each breach actually occurred. The 2026 update makes that research fully searchable: type “MOVEit,” for example, and the dashboard filters every chart to the 54 known healthcare breaches tied to that vendor’s file-transfer vulnerability, as of 7/1/2026.
What’s New in the 2026 Update
-
Supplemental investigation data
For the past few years, Stern Security’s analysts have investigated healthcare breaches to determine how they happened. The detailed breach description field in the data from HHS is often blank, leaving many questions about how the breach occurred. Stern Security’s research is now built directly into the dashboard, with the data source cited for every entry with supplemental data.
-
Searchable filters
Type a keyword, such as a vendor name, an attack type, or an incident, into the search bar, and every chart and statistic on the dashboard filters instantly. Search “ransomware” to isolate every known ransomware-related breach, or “MOVEit” to see all 54 breaches connected to that vulnerability.
-
Two new charts
Assets Affected by Breaches and Breach Size Distribution are now available alongside the dashboard’s existing graphs.
-
Business associate filter
Every chart can now be filtered by whether a breach involved a business associate (a HIPAA-defined third party), making it easier to isolate third-party risk trends specifically.
-
Dark/light mode
A display toggle for either viewing preference.


Why This Dashboard Exists
Healthcare breaches carry a real cost in both dollars and patient impact, but understanding how breaches happen is the first step to preventing similar ones. HHS publishes data on every healthcare breach affecting 500 or more patient records which is a critical foundation, but one that often stops short of explaining how an incident actually unfolded.
Stern Security, winner of the NC Tech Cyber Award, built HealthcareBreaches.com to close that gap. It’s free to use for anyone who wants to understand breach patterns in more depth than HHS’s raw data alone provides.
How HealthcareBreaches.com Started
Stern Security released the first version of HealthcareBreaches.com in 2022. That version pulled breach data directly from HHS.gov and turned it into graphs covering breach trends over time, the share of breaches tied to business associates, patient records lost, and how breaches were distributed across the U.S.
Alongside the dashboard, Stern Security began publishing an annual Healthcare Breach report. Producing it required more than HHS’s data alone as the HHS description field, which explains how a breach occurred, is only completed for some entries. So Stern Security analysts began investigating healthcare breaches directly, uncovering details like how many were caused by ransomware, the MOVEit vulnerability, Meta Pixel tracking issues, or phishing.
That investigation data stayed in Stern Security’s internal archives until 2026, when the team set out to add it directly to the public dashboard, which is what this update does.
You can find more of Stern Security’s ongoing research on the research blog.
How to Use This Information
Organizations and researchers can use this data to understand how breaches occur and prioritize protective measures accordingly. A spike in breaches tied to internet-facing file-sharing systems, for instance, is a concrete reason to restrict access, enforce encryption, minimize stored data, patch systems, and require multifactor authentication. Anyone conducting a risk assessment can use the dashboard to ground that work in real incident patterns rather than assumptions. Stern Security also uses this data to inform risk ratings within the Velocity platform.
Frequently Asked Questions
A free, public dashboard built by Stern Security that tracks U.S. healthcare data breaches, combining HHS’s official breach records with Stern Security’s own research into how each breach occurred.
Yes.
HHS’s official database of healthcare breaches affecting 500 or more patient records, supplemented by Stern Security’s annual investigations into breach causes.
Yes. Typing a term like “MOVEit” or “ransomware” filters every chart and statistic on the dashboard to matching breaches. As of 7/1/2026, searching “MOVEit” surfaces 54 known healthcare breaches tied to that vulnerability.
Stern Security released the first version in 2022.
The breach investigation work behind this dashboard is ongoing, and it will keep growing as new research is completed. Understanding how a breach happened is still the first step to preventing the next one.




