HIPAA Breach Report for December 2021

by Sara Uzer

Paubox-HIPAA-Breach-Report

The Paubox HIPAA Breach Report analyzes protected health information (PHI) breaches affecting 500 or more people as reported to the Department of Health & Human Services (HHS) in November 2021.


This report will cover:


HIPAA breaches ranked by people affected

Most common breaches by type

  • Network server breaches affected the most people in November 2021. 1,084,106 individuals had their data breached.
  • Electronic medical record breaches were the second most common breach, with 152,106 people affected.
  • Email breaches affected 147,916 people, the third most common breach type.

HIPAA breaches by occurrence

Most common breach types

  • Network server was the most common attack vector in November 2021. There were 25 network server breaches.
  • Email breaches were the second most common attack vector; twelve attacks via email were reported.
  • Electronic medical record breaches were reported four times last month.

Year over year comparison

These charts compare the numbers reported in previous Paubox HIPAA Breach Reports (December 2017, December 2018, December 2019, December 2020) with this month’s report.

HIPAA breaches ranked by people affected

What we observe

  • Network server, email, and electronic medical record breaches affected most people overall in November 2017 – 2021.
  • Network server breaches affected a total of 4,593,981 people in these months.
  • Email breaches affected 1,019,057 people, and electronic medical record breaches affected 392,237.
  • There was one large AccuDoc Solutions breach in November 2018 that affected more than 1 million people.

HIPAA breaches ranked by occurrence

What we observe

  • Email, network server, and paper/films breach types were the most common attack vectors in November 2017-2021.
  • Email breaches occurred 49 total times.
  • Network server breaches occurred a total of 46 times, and paper/films types occurred 29 times.
  • The most significant number of email breaches happened in November 2020.

Takeaways

Network server breaches affected the most people in November 2021. Utah Imaging Associates, Inc. had the most significant breach that affected 583,643 people. The Urology Center of Colorado had the second-largest breach that affected 137,820 people.

The yearly comparison shows that email breaches were the most popular attack vectors for bad actors over the last five November months. Over 1 million total individuals had their data breached via 49 email breaches during this time.

Full data

Click here to view the HHS’ raw data via Google Sheets.

About the Paubox HIPAA Breach Report

The Paubox HIPAA Breach Report analyzes breaches that affected 500 or more individuals, as reported on the HHS Wall of Shame in November 2021.

SEE ALSO: HIPAA compliant email: the definitive guide