Back to news
Cybersecurity Alert
June 14, 2026 by EmailMeNow IT Consulting

Healthcare Data Breaches Across State AG Portals: 2026 Tracker

Texas, Washington, and California AG breach data show 395 healthcare-related notices in 2026 YTD (297 TX, 34 WA, 64 CA list-only), affecting millions where resident counts are published. Cross-state tracker with dashboards and named providers.

Source: State Attorney General Breach Portals

Multi-StateHealthcareHIPAAData BreachTexasWashingtonCaliforniaState AG
Healthcare data breach tracker across Texas, Washington, and California state AG portals in 2026

Video explainer

Healthcare organizations dominate state Attorney General breach filings. Filtering 2026 notices that list medical or health-insurance information shows 165 reports in Texas affecting 16,152,032 Texans and 21 reports in Washington affecting 107,672 Washingtonians — before counting California list entries that do not publish resident totals (40 likely healthcare entities on the California AG list in 2026).

National vendors and regional clinics appear on multiple state portals. Conduent Business Services, Texas Tech University Health Sciences Center, Episource, and TriZetto Provider Solutions lead Texas; Mt. Spokane Pediatrics, OpenLoop Health, and WellPoint (Elevance Health) lead Washington.

Texas Healthcare Breaches (2026)

Interactive Tracker

Texas Healthcare Breaches: 2026 OAG Reports

Texans affected by 2026 breaches exposing medical or health-insurance data, by month

Data current through Oct 2, 2026
2026 YTD reports 297
Texans affected 26.1M
Largest report 12.8M
Jan
130.1K
Feb
596K
Mar
747.4K
Apr
921.1K
May
13.2M
Jun
882.3K
Jul
4.6M
Aug
1.2M
Sep
789.1K
Oct MTD
3M
Show largest 2026 healthcare breach reports
Entity Published Texans affected Sector
Conduent Business Services, LLC (revised submission) May 20, 2026 12,784,367 Healthcare / Medical
DentaQuest, LLC Jul 17, 2026 3,973,000 Healthcare / Medical
Cerner Corporation Oct 2, 2026 2,992,244 Healthcare / Medical
Texas Tech University Health Sciences Center Apr 27, 2026 738,506 Government / Education
Episource, LLC Feb 11, 2026 351,562 Healthcare / Medical

Source: Texas OAG Data Security Breach Reports, filtered to 2026 notices listing medical or health-insurance information. Data current through Oct 2, 2026. Totals may change as the OAG updates the portal.

Sources

Largest Texas Healthcare Notices

OrganizationTexans AffectedDate Published
Conduent Business Services, LLC (revised submission)12,784,367May 20, 2026
DentaQuest, LLC3,973,000Jul 17, 2026
Cerner Corporation2,992,244Oct 2, 2026
Texas Tech University Health Sciences Center738,506Apr 27, 2026
Episource, LLC351,562Feb 11, 2026

Newly listed in Texas (last 3 weeks)

OrganizationTexans AffectedDate Published
Lincoln Property Company Commercial LLC6,585Oct 2, 2026
Pro Holdings, LLC d/b/a ProCamps3,840Oct 2, 2026
Little River Memorial Hospital3,242Oct 2, 2026
PSI Premier Specialties Inc. d/b/a Medical Express PSI2,128Oct 2, 2026
Innovative Alternatives, Inc1,500Oct 2, 2026
i.e.Smart Systems, LLC897Oct 2, 2026
MedImpact Healthcare Systems, Inc.8,199Sep 29, 2026
PDCM Insurance1,046Sep 29, 2026

Washington Healthcare Breaches (2026)

Interactive Tracker

Washington Healthcare Breaches: 2026 AG Reports

Washingtonians affected by 2026 breaches exposing medical or health-insurance data, by month

Data current through Sep 11, 2026
2026 YTD reports 34
Washingtonians affected 388.6K
Largest report 148.3K
Jul
200.3K
Aug
166.4K
Sep
21.8K
Show largest 2026 Washington healthcare breach reports
Entity Published Washingtonians affected Sector
DentaQuest, LLC Jul 16, 2026 148,300 Healthcare / Medical
Aesto, LLC (Grant County Public Hospital District #2) Aug 4, 2026 37,253 Government / Education
Paylogix, LLC Aug 14, 2026 28,449 Healthcare / Medical
Baylor Genetics Aug 14, 2026 27,243 Healthcare / Medical
Everside Health (Aesto, LLC) Jul 31, 2026 21,308 Healthcare / Medical

Source: Washington State Attorney General - Data Breach Notifications, industry-filtered. Data current through Sep 11, 2026.

Sources

Largest Washington Healthcare Notices

OrganizationWashingtonians AffectedDate Published
DentaQuest, LLC148,300Jul 16, 2026
Aesto, LLC (Grant County Public Hospital District #2)37,253Aug 4, 2026
Paylogix, LLC28,449Aug 14, 2026
Baylor Genetics27,243Aug 14, 2026
Everside Health (Aesto, LLC)21,308Jul 31, 2026

Newly listed in Washington (last 3 weeks)

OrganizationWashingtonians AffectedDate Published
zHealth, Inc.1,332Sep 11, 2026
Cornerstone Staffing Solutions, Inc.681Sep 11, 2026
Quatrro Business Support Services, Inc.10,008Sep 9, 2026
Hibbett Retail, Inc.510Sep 8, 2026
LHC Group, Inc.6,602Sep 4, 2026
Mogren, Glessner & Ahrens, P.S.1,379Sep 3, 2026
The Lighthouse for the Blind, Inc.520Sep 3, 2026

HHS OCR Large Breaches (2026 Submissions)

Federal HHS OCR submissions dated in 2026 currently list 404 large breaches on the live under-investigation portal, affecting 67,614,220 individuals nationally (not state-resident totals). Current through October 5, 2026.

Interactive Tracker

HHS OCR Large Healthcare Breaches: 2026 Submissions

HIPAA breach reports with a 2026 submission date, by month

Data current through October 5, 2026
2026 YTD reports 404
Individuals affected 67.6M
Largest report 15M
Jan
2.5M
Feb
7.1M
Mar
8.7M
Apr
1.2M
May
1.2M
Jun
4.4M
Jul
33.4M
Aug
8.2M
Sep MTD
917.8K
Show largest 2026 HHS OCR breach reports
Entity Published Individuals affected Sector
DentaQuest, LLC Jul 16, 2026 15,000,000 Health Plan
Aesto, LLC Jul 31, 2026 9,540,683 Business Associate
AdaptHealth, LLC Aug 14, 2026 4,115,802 Healthcare Provider
Unlimited Technology Systems, LLC Jul 21, 2026 3,803,750 Business Associate
CareCloud, Inc. Jul 24, 2026 3,756,469 Business Associate

Source: HHS OCR Breach Portal (under-investigation view). Figures are national individuals-affected counts for covered entities; entity state does not equal state-resident totals.

Sources

California AG List (No Affected Counts)

California publishes incident names without resident totals.

List-Only Tracker

California Healthcare Breaches: 2026 AG List

Likely healthcare entities on the California AG data breach list, by month — California does not publish residents-affected counts

Data current through Oct 1, 2026
2026 YTD reports 64
Entities listed 64
Jan
17 reports
Feb
5 reports
Mar
7 reports
Apr
6 reports
May
3 reports
Jun
3 reports
Jul
7 reports
Aug
8 reports
Sep
7 reports
Oct MTD
1 reports
Show all 2026 California healthcare list entries
Entity Published
Marana Health Center Oct 1, 2026
San Bernardino County on behalf of Arrowhead Regional Medical Center Sep 28, 2026
MedImpact Healthcare Systems, Inc. Sep 25, 2026
Modoc Medical Center Sep 22, 2026
Ridgeway Pharmacy Ltd Sep 21, 2026
Paradigm Healthcare Services Sep 14, 2026
Catalyst Physician Group Sep 11, 2026
Elixir Medical Corporation Sep 4, 2026
Virta Health Corp. and Virta Medical, PC Aug 31, 2026
Murfreesboro Medical Clinic Aug 26, 2026
Livara Health Medical Group - dba SpineZone Aug 25, 2026
Kern Psychiatric Health and Wellness Center, Inc Aug 21, 2026
Northern Inyo Healthcare District d/b/a Northern Inyo Hospital Aug 20, 2026
Silver Summit Medical Corporation Aug 19, 2026
Terry J. Dubrow, MD, A Medical Corporation Aug 13, 2026
Boston Healthcare for the Homeless Program Aug 7, 2026
Stanislaus County Health Services Agency Jul 31, 2026
Clinical Registry Solutions Jul 29, 2026
BAYADA Home Health Care, Inc. Jul 17, 2026
Madera Community Hospital Jul 14, 2026
Alta Orthopaedics Medical Group, Inc. Jul 8, 2026
L.A. Care Health Plan Jul 2, 2026
TriWest Healthcare Alliance Jul 2, 2026
Virta Medical PC Jun 12, 2026
Clinical Registry Solutions Jun 11, 2026
Ultrahuman Healthcare Private Limited Jun 5, 2026
Southern California University of Health Sciences May 19, 2026
Family Health Centers of San Diego May 12, 2026
Sanger Skilled Care, LLC dba Cornerstone Care Center May 7, 2026
L.A. Care Health Plan Apr 27, 2026
Conduent Business Services, LLC Apr 27, 2026
Texas Tech University Health Sciences Center Apr 24, 2026
City Health, a medical corporation Apr 14, 2026
Pediatric Products, LLC Apr 14, 2026
CardioFit Medical Group, Inc. Apr 9, 2026
Nephrology Associates Medical Group Mar 26, 2026
Conduent Business Services, LLC Mar 24, 2026
Stockton Cardiology Medical Group Mar 20, 2026
Northwest Medical Homes, LLC Mar 5, 2026
Tieu Dental Corporation Mar 5, 2026
Palo Verde Hospital Mar 2, 2026
Valley Radiology Consultants Medical Group Mar 2, 2026
Couve Healthcare Consulting, LLC DBA Evergreen Healthcare Group Feb 24, 2026
North East Medical Services Feb 18, 2026
AltaMed Health Services Corporation Feb 12, 2026
TriZetto Provider Solutions Feb 11, 2026
Episource, LLC Feb 9, 2026
Conduent Business Services, LLC Jan 30, 2026
Native American Health Center Jan 28, 2026
Brown & Toland Physicians Jan 26, 2026
Petaluma Health Center Jan 20, 2026
Winters Healthcare Jan 20, 2026
Indian Health Center of Santa Clara Valley Jan 16, 2026
La Clinica de La Raza, Inc. Jan 15, 2026
LifeLong Medical Care Jan 14, 2026
Asian and Pacific Islander Wellness Center, Inc. dba San Francisco Community Health Center Jan 9, 2026
Harmony Health Medical Clinic and Family Resource Center Jan 8, 2026
Open Door Community Health Centers Jan 8, 2026
Mission Neighborhood Health Center Jan 7, 2026
CE-Edinger Medical Group BA - TriZetto TPS Jan 7, 2026
Native American Health Center Jan 6, 2026
Imperial Beach Community Clinic (“IB Clinic”) Jan 6, 2026
Santa Rosa Community Health Centers Jan 5, 2026
Conduent Business Services, LLC Jan 2, 2026

Source: California Attorney General - Data Breach List, filtered to likely healthcare providers, clinics, payers, and medical vendors. California does not publish residents-affected counts.

Sources

State AG breach portals

See our California AG breach tracker for full incident monitoring.

Why Email Security Matters

Many healthcare breaches begin with phishing or compromised email accounts. The HIPAA Security Rule requires documented safeguards for ePHI in transit — areas our audit scores directly.

Check any practice’s posture at audit.emailmenow.com/?industry=healthcare-practices.

Recommendations

  • Enforce DMARC, strict SPF, and DKIM; add MTA-STS where feasible.
  • Complete and document a HIPAA security risk analysis.
  • Train staff and oversee Business Associate vendors.