1 min read

HIPAA Breach Report for October 2025

HIPAA Breach Report for October 2025

The HIPAA Breach Report for October 2025 analyzes protected health information (PHI) breaches affecting 500 or more people as reported to the Department of Health and Human Services (HHS) in September 2025.

 

This report covers:

 

HIPAA breaches ranked by people affected

Paubox HIPAA Breach Report October 2025 - HIPAA breaches ranked by people affected

 

Most common breaches by type

  • Network server breaches affected the most people. 1,359,914 individuals had their data breached.
  • Email breaches were the second most common breach, with 190,935 people affected.
  • Electronic medical record breaches affected 16,281 people, the third most impactful breach type.

HIPAA breaches ranked by occurrence

Paubox HIPAA Breach Report October 2025 - HIPAA breaches ranked by occurrence

 

Most common breach types

  • Network server was the most common attack vector. There were 22 network server breaches.
  • Email breaches were the second most common attack vector. There were 9  breaches.
  • Paper/films and Electronic medical record breaches were the third most common attack vector, with 2 attacks each.

 

Year-over-year comparison

These charts compare the HIPAA data breach statistics from previous Paubox HIPAA Breach Reports (October 2021, October 2022, October 2023, and October 2024) with this month’s report.

 

HIPAA breaches ranked by people affected

Paubox HIPAA Breach Report October 2025 - HIPAA breaches ranked by people affected - year-over-year comparison

 

What we observe

  • Network server breaches affected the most people overall in September 2025.

  • The number of people affected by network server breaches is significantly lower that of the previous 2 Septembers.

  • The number of individuals impacted by Email breaches in September 2025 was only slightly down compared to previous years.

 

HIPAA breaches ranked by occurrence

Paubox HIPAA Breach Report October 2025 - HIPAA breaches ranked by occurrence - year-over-year comparison

What we observe

  • Network server breaches were, as usual, the most frequent attack vector. 

  • Email, as a the vector, was consistent with previous years' instances.

Takeaways

Network server breaches affected the most people in August 2025. Goshen Medical Center had the most significant breach, which affected 456,385 people. Medical Associates of Brevard, LLC had the second-largest breach, affecting 246,711 people.

Overall, over 1.5 million individuals had their data accessed via 36 breaches reported in August 2025.

Full data

Click here to view the HHS’ raw data via Google Sheets.

About the Paubox HIPAA Breach Report

The Paubox HIPAA Breach Report analyzes recent PHI breaches that affected 500 or more individuals, as reported on the HHS Wall of Shame in September 2025.

SEE ALSO: HIPAA Compliant Email: The Definitive Guide

Robust inbound email security is a necessity for businesses today. Keeping your email security strategy updated helps ensure the protection of your network.

Subscribe to Paubox Weekly

Every Friday we'll bring you the most important news from Paubox. Our aim is to make you smarter, faster.