Talk to sales
Start for free

The January Paubox HIPAA Breach Report analyzes protected health information (PHI) breaches affecting 500 or more people as reported to the Department of Health and Human Services (HHS) in December 2022.


This report covers:

  • HIPAA breaches ranked by people affected
  • HIPAA breaches ranked by occurrence
  • Year-over-year comparison
  • Takeaways
  • Full data


HIPAA breaches ranked by people affected



Most common breaches by type

  • Network server breaches affected the most people in December 2022. 1,752,710 individuals had their data breached.
  • Other breaches were the second most common breach, with 276,788 people affected.
  • Email breaches affected 97,217 people, the third most common breach type.


HIPAA breaches ranked by occurrence



Most common breach types

  • Network server was the most common attack vector in December 2022. There were 19 network server breaches.
  • Email breaches were the second most common attack vector. There were 11 email breaches.
  • Other breaches were the third most common attack vector, garnering 3 attacks during the month.


Year-over-year comparison

These charts compare the HIPAA data breach statistics from previous Paubox HIPAA Breach Reports (January 2020, January 2021, January 2022) with this month’s report.


HIPAA breaches ranked by people affected


What we observe

  • Network server, email, and other breaches affected the most people overall across this comparison.
  • Email breaches had the biggest impact in December 2020, with 2,032,868 people affected.


HIPAA breaches ranked by occurrence


What we observe

  • Network server, email, and paper/films breach types were the most common attack vectors in this comparison.
  • Network server breaches more than doubled in December 2020 compared to December 2019.
  • Electronic medical record breaches have seen a steady decline over this timespan, with only one occurrence in December 2021 and December 2022.


Network server breaches affected the most people in December 2022. CommonSpirit Health had the most significant breach that affected 623,774 people. Metropolitan Area EMS Authority dba MedStar Mobile Healthcare had the second-largest breach, which affected 612,000 people.

The yearly comparison shows that network server breaches were the most popular attack vectors for bad actors over the last four December months. Over five million total individuals had their data accessed via 62 network server breaches during this time.


Full data

Click here to view the HHS’ raw data via Google Sheets.


About the Paubox HIPAA Breach Report

The Paubox HIPAA Breach Report analyzes recent PHI breaches that affected 500 or more individuals, as reported on the HHS Wall of Shame in December 2022.


SEE ALSO: HIPAA Compliant Email: The Definitive Guide


Robust inbound email security is a necessity for businesses today. Keeping your email security strategy updated helps ensure the protection of your network.

Start a 14-day free trial of Paubox Email Suite today