---
title: "Top 10 Largest Healthcare Data Breaches by Number of…"
description: "Explore the rising threat of healthcare data breaches, examining real-world examples like Newkirk Products and Banner Health, and learn what information is…"
lang: en
json-ld: |
  [
    {
      "@context": "https://schema.org",
      "@type": "Person",
      "@id": "https://christianespinosa.com/#person",
      "name": "Christian Espinosa",
      "url": "https://christianespinosa.com/",
      "image": "https://christianespinosa.com/__l5e/assets-v1/de07e44b-a8e0-4bcc-bcb0-13aec15421f1/headshot-front.jpg",
      "sameAs": [
        "https://www.facebook.com/christian.espinosa.official",
        "https://x.com/Ironracer",
        "https://www.instagram.com/christian.espinosa.official/",
        "https://www.youtube.com/@ChristianEspinosaOfficial",
        "https://www.linkedin.com/in/christianespinosa/"
      ],
      "jobTitle": "Bestselling Author, Keynote Speaker, Entrepreneur",
      "worksFor": {
        "@type": "Organization",
        "name": "Blue Goat Cyber",
        "url": "https://bluegoatcyber.com/"
      }
    },
    {
      "@context": "https://schema.org",
      "@type": "WebSite",
      "@id": "https://christianespinosa.com/#website",
      "name": "Christian Espinosa",
      "url": "https://christianespinosa.com/",
      "publisher": {
        "@id": "https://christianespinosa.com/#organization"
      },
      "inLanguage": "en-US"
    },
    {
      "@context": "https://schema.org",
      "@type": "Organization",
      "@id": "https://christianespinosa.com/#organization",
      "name": "Christian Espinosa",
      "url": "https://christianespinosa.com/",
      "logo": {
        "@type": "ImageObject",
        "url": "https://christianespinosa.com/logo.svg"
      },
      "founder": {
        "@id": "https://christianespinosa.com/#person"
      },
      "sameAs": [
        "https://www.facebook.com/christian.espinosa.official",
        "https://x.com/Ironracer",
        "https://www.instagram.com/christian.espinosa.official/",
        "https://www.youtube.com/@ChristianEspinosaOfficial",
        "https://www.linkedin.com/in/christianespinosa/"
      ]
    },
    {
      "@context": "https://schema.org",
      "@type": "Article",
      "headline": "Top 10 Largest Healthcare Data Breaches by Number of Records Stolen - Christian Espinosa",
      "description": "Explore the rising threat of healthcare data breaches, examining real-world examples like Newkirk Products and Banner Health, and learn what information is…",
      "image": "https://christianespinosa.com/__l5e/assets-v1/5660031f-71e3-4f96-ad18-bf13ac345b62/top-10-largest-healthcare-data-breaches-by-number-of-records-stolen-card.png",
      "datePublished": "2021-09-03T17:48:42+00:00",
      "dateModified": "2026-06-26T05:38:52.367Z",
      "mainEntityOfPage": {
        "@type": "WebPage",
        "@id": "https://christianespinosa.com/blog/top-10-largest-healthcare-data-breaches-by-number-of-records-stolen"
      },
      "author": {
        "@type": "Person",
        "name": "Christian Espinosa",
        "url": "https://christianespinosa.com/about"
      },
      "publisher": {
        "@type": "Organization",
        "name": "Christian Espinosa",
        "logo": {
          "@type": "ImageObject",
          "url": "https://christianespinosa.com/logo.svg"
        }
      }
    },
    {
      "@context": "https://schema.org",
      "@type": "FAQPage",
      "mainEntity": [
        {
          "@type": "Question",
          "name": "What is the core idea behind \"Top 10 Largest Healthcare Data Breaches by Number of Records Stolen - Christian Espinosa\"?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "Healthcare data breaches have increased in both scale and regularity during the last decade, with the worst affecting up to 80 million people."
          }
        },
        {
          "@type": "Question",
          "name": "Who is this post for?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "Honestly, security leaders, medical device teams, and technical operators who want the honest version, not the vendor version. If you want a listicle, this is not that. If you want the honest version of what I have actually lived and worked through, keep reading."
          }
        },
        {
          "@type": "Question",
          "name": "How do I actually apply this, not just nod along?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "Pick the single line in the post that made you flinch or look away, and change one thing in your week because of it. One choice this week beats a whole framework you never touch."
          }
        }
      ]
    }
  ]
---

[Skip to content](#main)

[](/)

[About](/about)[Speaking](/speaking)[Cybersecurity](/cybersecurity)[Programs](/programs)[Books](/books)[Media](/media)

Writing

Search Ctrl K[Connect](/connect)

[Cybersecurity](/blog/category/cybersecurity)

# Top 10 Largest Healthcare Data Breaches by Number of Records Stolen

September 3, 2021 8 min read 1,721 words 

I've been a victim of identity theft. I know how it feels. It was after a medical emergency in Mexico, and my information was exposed before I even landed back in the States. Data breaches impact millions, if not billions, of individuals.

![](/__l5e/assets-v1/46935594-b1a4-423d-acbf-fcb08859ec4c/top-10-largest-healthcare-data-breaches-by-number-of-records-stolen-hero.webp)

The takeaways

1.  01 
    
    It was after a medical emergency in Mexico, and my information was exposed before I even landed back in the States.
    
    What to do next Run a 20-minute tabletop with your team this month using medical as the scenario.
    
2.  02 
    
    Data breaches impact millions, if not billions, of individuals.
    
    What to do next Run a 20-minute tabletop with your team this month using breaches as the scenario.
    
3.  03 
    
    The amount of data circulating has increased because of digitalization, and security breaches have risen in tandem as cybercriminals prey on our daily reliance on data.
    
    What to do next Open your current breaches plan today and identify the one gap you would not want an auditor to find.
    
4.  04 
    
    Healthcare data breaches have increased in both scale and regularity during the last decade, with the worst breaches affecting up to 80 million people.
    
    What to do next Run a 20-minute tabletop with your team this month using breaches as the scenario.
    

I've been a victim of identity theft. I know how it feels. It was after a medical emergency in Mexico, and my information was exposed before I even landed back in the States. Data breaches impact millions, if not billions, of individuals. The amount of data circulating has increased because of digitalization, and security breaches have risen in tandem as cybercriminals prey on our daily reliance on data.

Healthcare data breaches have increased in both scale and regularity during the last decade, with the worst breaches affecting up to 80 million people. These breaches frequently leak incredibly sensitive data, ranging from personally identifiable information like names, addresses, and Social Security numbers to personal health information like health insurance information, patients’ past medical history, and Medicaid ID numbers. I've compiled 10 of the largest data breaches by the number of stolen records.

## Top 10 Largest Data Breaches by Number of Stolen Records

### 10.  Newkirk Products

The first one I'm looking at involved 3.47 million stolen records. It was discovered on July 6, 2016.

Newkirk Products, a provider of healthcare ID cards, revealed [a data breach in mid-2016 involving approximately 3.47 million individuals](https://www.prnewswire.com/news-releases/newkirk-products-inc-provides-notice-of-data-breach-300309995.html). Multiple branches of Blue Cross Blue Shield, one of the major health insurance companies in the United States by enrollment, were among those affected.

The attacker was able to get unauthorized access to information by exploiting a vulnerability in the third-party software’s administrative portal on a single isolated server. Hackers acquired access to sensitive personal information such as names, birthdates, Medicaid ID numbers, group ID numbers, and premium invoice information, and in addition to primary care provider information. There was no financial information, medical records, insurance claim data, or social security numbers on the server.

To date, Newkirk has found no evidence that such information has been misused. Those affected by the data breach were sent letters that included an explanation of the occurrence, an offer of free identity protection services for two years, and advice on other ways to safeguard themselves.

### 9.  Banner Health

-   **Number of Stolen Records: 3.62 Million**
-   **Date Discovered:** late June 2016

Banner Health, a healthcare company based in Arizona, revealed in mid-2016 that [3.62 million patients’ data had been exposed due to a cyber-attack](https://www.usatoday.com/story/news/nation-now/2016/08/03/banner-health-cyberattack-breaches-records/88040778/). Banner contracted a cybersecurity expert to investigate after staff saw strange activity on its private servers. The firm identified two intrusions in which hackers acquired patient information and payment system data. Names, birth dates, addresses, Social Security numbers, credit card numbers, internal verification codes, expiration dates, as well as doctors’ names, and medical records, may have been compromised.

A [class-action lawsuit](https://www.latimes.com/business/la-fi-ucla-medical-data-20150717-story.html) was launched by the victims of the data breach shortly after. The judge dismissed several of the first allegations, but the parties negotiated a provisional settlement in December 2020. According to court records, victims of data breaches will be entitled to file claims for reimbursement of expenses spent because of the violation.

The maximum amount that can be compensated per breach victim is $500 for regular expenses and $10,000 for exceptional costs, including out-of-pocket expenses and missed time due to identity theft or fraud. All breach victims will also receive two years of free credit monitoring from Banner Health, which will not duplicate what was supplied at the health system’s original breach notification.

### 8.  Medical Informatics Engineering

-   **Number of Stolen Records: 3.9 million**
-   **Date Discovered:** June 10, 2015

Medical Informatics Engineering (MIE), an electronic medical records software company, reported [a data breach in mid-2015 that compromised at least 3.9 million patients](https://www.chiefhealthcareexecutive.com/view/medical-informatics-engineering-pays-100k-for-data-breach-of-35m-patients). Patients who were affected received notices in the mail informing them of their stolen PII, including their names, birthdates, mailing addresses, phone numbers, diagnoses, Social Security numbers, and other sensitive data.

According to news outlets, cyber hackers accessed the company’s network remotely by using credentials that were not consistently secure. According to an investigation, the organization did not do a thorough risk analysis to analyze the possible threats and hazards to the security, integrity, and accessibility of an individual’s electronic protected health information before the breach occurred. This is a HIPAA-required activity, and [MIE’s violation led them to pay $100,000](https://medium.com/the-aftermath-of-a-data-breach/medical-informatics-engineering-breach-the-gift-that-keeps-on-giving-9948231d2e95) as settlement.

### 7.  Advocate Health Care

-   **Number of Stolen Records: 4.03 million**
-   **Date Discovered:** August 2013

Advocate Health Care confirmed [three different data breaches](https://www.cnbc.com/2016/08/04/huge-data-breach-at-health-system-leads-to-biggest-ever-settlement.html) affecting Advocate Medical Group (AMG), a doctors’ organization with over 1,000 physicians, from July to November 2013. The initial breach happened on July 15 when AMG’s administrative headquarters in Park Ridge, Illinois, was robbed of four desktop computers carrying the records of roughly 4 million patients.

The second breach occurred between June 30 and August 15, 2013, when an unauthorized third party gained unauthorized network access to AMG’s billing service provider, potentially exposing the health records of over 2,000 AMG patients. Then, the last case of stolen PHI involved the theft of a laptop holding the health records of over 2,230 patients from an AMG employee’s car on November 1, 2013.

Advocate settled a lawsuit over the breach in August 2016 for $5.55 million.

### **6\. University of California, Los Angeles Health**

-   **Number of Stolen Records: 4.5 million**
-   **Date Discovered:** May 5, 2015

In mid-2015, the UCLA Health System revealed that hackers gained access to patient records of approximately 4.5 million individuals. Worse yet, UCLA announced that its patient data was not secured, which brought immediate and scathing criticism from security specialists.

In 2019, UCLA Health negotiated a settlement with the 4.5 million present and past patients affected by the patient data leak in a class-action lawsuit. UCLA Health consented to several resolutions as part of the agreement. All class action participants are eligible to sign up for free two-year identity protection services. The health organization also committed to compensating patients for costs paid in attempting to safeguard themselves from identity theft and expenses incurred because of identity theft or fraud. UCLA Health has also committed to revising its cybersecurity policies and practices.

### 5.  TRICARE

-   **Number of Stolen Records: 4.9 million**
-   **Date Discovered:** September 2011

Science Applications International Corporation (SAIC) reported a data breach in late 2011 that [affected about 4.9 million military clinic and hospital patients](https://www.modernhealthcare.com/article/20110929/NEWS/110929951/tricare-reports-data-breach-affecting-4-9-million-patients) participating in TRICARE, the military healthcare provider for the federal government. This transpired when records were taken from a SAIC staff’s car.

According to TRICARE authorities, the tapes contain phone numbers, addresses, Social Security numbers, and other sensitive information, including prescriptions, laboratory tests, and clinical notes. They also stated that the records did not contain any financial information, such as bank accounts or credit card numbers.

A [federal district judge dismissed most of the combined class action lawsuits](https://www.databreachtoday.com/most-claims-in-tricare-breach-dismissed-a-6834) brought against TRICARE in 2014.

### 4.  Community Health Systems

-   **Number of Stolen Records: 6.1 million**
-   **Date Discovered:** June 2014

Community Health Systems (CHS), which manages 200+ hospitals across the United States, disclosed [a serious healthcare breach affecting 6.1 million patients in mid-2014](https://money.cnn.com/2014/08/18/technology/security/hospital-chs-hack/). Attackers took advantage of a software flaw to gain access to personal information such as phone numbers, physical addresses, birthdates, and Social Security numbers. The breach impacted anybody who has received care from an affiliate hospital in the last five years and anybody who had been recommended to CHS by a physician outside of CHS during that time.

CHS enlisted the help of cybersecurity professionals to investigate the breach. They discovered that the hackers were from China and that the attacks took place between April and June of 2014. The cybercriminals used high-end, complex malware to carry out their operations.

Federal authorities and cybersecurity consultants informed the hospital network that the attackers had previously committed industrial espionage and stole valuable medical device information. Instead, the intruders stole patient information this time. They were unable to obtain information about patients’ past medical history, clinical procedures, or credit card details.

The breach cost CHS and its partners [$10.4 million in compensation](https://www.hipaajournal.com/community-health-systems-pays-5-million-to-settle-multi-state-breach-investigation/).

### 3\. Excellus Bluecross Blueshield

-   **Number of Stolen Records: 10+ million**
-   **Date Discovered:** September 2015

Excellus uncovered [a cyber-attack in August 2015](https://www.usatoday.com/story/tech/2015/09/10/cyber-breach-hackers-excellus-blue-cross-blue-shield/72018150/) that exposed the personal information of around 10 million members. Following a wave of cyber-attacks in early 2015 that targeted healthcare data, Excellus had its own systems forensically reviewed. What they found ended up being the world’s third-largest healthcare data breach.

Names, phone numbers, mailing addresses, birth dates, Social Security numbers, and various account information, such as claims and payment details, were all exposed in the breach, which dated back to December 2013.

Excellus will [pay a $5.1 million fine](https://www.cyberscoop.com/excellus-data-breach-fined-hhs-ocr/) for violating HIPAA’s privacy and security standards as part of the settlement.

### 2.  Premera Blue Cross

-   **Number of Stolen Records:** **11+ million**
-   **Date Discovered:** January 29, 2015

Premera Blue Cross revealed in early 2015 that [11 million customers’ medical information had been compromised](https://www.forbes.com/sites/katevinton/2015/03/17/11-million-customers-medical-and-financial-data-may-have-been-exposed-in-premera-blue-cross-breach/?sh=59a8166575d9) due to a cyberattack. Hackers were able to put malware on Premera’s servers using a phishing email, giving them access to the data of its members. The hack disclosed bank account data, birthdates, claims information, and Social Security numbers, among other things. The company found that the first attack took place on May 5, 2014, after working with cybersecurity specialists and the FBI to examine the attack. To resolve suspected HIPAA violations in the security breach, Premera Blue Cross was made to [pay $6.85 million](https://www.healthcareitnews.com/news/premera-blue-cross-pay-685m-settle-massive-2015-breach) and submit a remedial action plan in 2020.

### 1.  Anthem Blue Cross

-   **Number of Stolen Records: 78.8 million**
-   **Date Discovered:** January 29, 2015

Anthem revealed in 2015 that 78.8 million patient information was stolen in the largest healthcare data breach in history. An anonymous hacker gained access to a database holding personal information such as names, birthdates, addresses, social security numbers, email addresses, and information about jobs and income. According to the company, the hack did not expose credit card or medical information.

Anthem agreed to pay $39.5 million in 2020 to resolve a probe by a consortium of state attorneys general. The corporation also consented to [pay $115 million](https://www.nbcnews.com/news/us-news/anthem-pay-record-115m-settle-lawsuits-over-data-breach-n776246) to settle the lawsuit, making it the largest data breach settlement ever.

_**Interested in preventing a data breach? [Contact me.](https://christianespinosa.com/cerberus-sentinel/)**_

Frequently asked

### What is the core idea behind "Top 10 Largest Healthcare Data Breaches by Number of Records Stolen - Christian Espinosa"?

### Who is this post for?

### How do I actually apply this, not just nod along?

### Work with me

I help founders and cybersecurity leaders build teams that ship, not teams that stall. If that's the problem you're trying to solve, let's talk.

[Start a conversation](/contact)

Share this essay

[X ](https://twitter.com/intent/tweet?url=https%3A%2F%2Fchristianespinosa.com%2Fblog%2Ftop-10-largest-healthcare-data-breaches-by-number-of-records-stolen&text=Top%2010%20Largest%20Healthcare%20Data%20Breaches%20by%20Number%20of%20Records%20Stolen) [LinkedIn](https://www.linkedin.com/sharing/share-offsite/?url=https%3A%2F%2Fchristianespinosa.com%2Fblog%2Ftop-10-largest-healthcare-data-breaches-by-number-of-records-stolen) [Facebook](https://www.facebook.com/sharer/sharer.php?u=https%3A%2F%2Fchristianespinosa.com%2Fblog%2Ftop-10-largest-healthcare-data-breaches-by-number-of-records-stolen) [Email](mailto:?subject=Top%2010%20Largest%20Healthcare%20Data%20Breaches%20by%20Number%20of%20Records%20Stolen&body=https%3A%2F%2Fchristianespinosa.com%2Fblog%2Ftop-10-largest-healthcare-data-breaches-by-number-of-records-stolen)Copy link 

![Christian Espinosa, headshot](/__l5e/assets-v1/de07e44b-a8e0-4bcc-bcb0-13aec15421f1/headshot-front.jpg)

About the author

[Christian Espinosa](/about) · Founder & CEO, Blue Goat Cyber

Christian is the founder and CEO of Blue Goat Cyber, a medical device cybersecurity firm. He's an Air Force Academy graduate, 24x Ironman, climber of two of the Seven Summits, and the author of The Smartest Person in the Room and The In-Between: Life in the Micro.

Keep reading

-   [
    
    ### Ransomware – Should You Pay? - Christian Espinosa
    
    Same thread: cybersecurity.
    
    Read essay → ](/blog/ransomware-should-you-pay)
-   [
    
    ### 3 Steps to Hide Data in an Image Using Steganography - Christian Espinosa
    
    Same thread: cybersecurity.
    
    Read essay → ](/blog/3-steps-to-hide-data-in-an-image-using-steganography)
-   [
    
    ### 3 Reasons Why Current Cybersecurity Measures Aren’t Working and How to Fix Them - Christian Espinosa
    
    Same thread: cybersecurity.
    
    Read essay → ](/blog/3-reasons-why-current-cybersecurity-measures-arent-working-and-how-to-fix-them)

[← Previous essay 

Explanation of Cybersecurity Hashing and Collisions - Christian Espinosa

](/blog/explanation-of-cybersecurity-hashing-and-collisions)[Next essay → 

Questions to Ask a vCISO - Christian Espinosa

](/blog/questions-to-ask-a-vciso)

Related, Cybersecurity

### Need medical-device or offensive security expertise?

Blue Goat Cyber, Christian's firm, runs FDA-aligned premarket submissions, penetration testing, and SBOM/SOUP analysis for medtech and high-stakes industries.

[Explore Blue Goat Cyber](/cybersecurity)

Christian Espinosa

Bestselling author, keynote speaker, and Founding CEO of [Blue Goat Cyber](https://bluegoatcyber.com/). Helping technical leaders develop the soft skills that turn brilliance into impact.

[](https://www.linkedin.com/in/christianespinosa/)[](https://x.com/Ironracer)[](https://www.instagram.com/christian.espinosa.official/)[](https://www.youtube.com/@ChristianEspinosaOfficial)[](https://www.facebook.com/christian.espinosa.official)

Explore

-   [About](/about)
-   [Timeline](/timeline)
-   [Speaking](/speaking)
-   [Cybersecurity](/cybersecurity)
-   [Programs](/programs)

Read

-   [Books](/books)
-   [Guides](/guides)
-   [Blog](/blog)
-   [Media](/media)
-   [Podcast Interviews](/podcasts)
-   [Success Stories](/success-stories)

Connect

-   [Contact Christian](/connect)
-   [LinkedIn ↗](https://www.linkedin.com/in/christianespinosa/)
-   [Blue Goat Cyber ↗](https://bluegoatcyber.com/)
-   [Resources](/resources)

© 2026 Christian Espinosa. All rights reserved.

[Privacy](/privacy-policy)[Terms](/terms-of-use)