Back to news
Cybersecurity Alert
August 25, 2026 by EmailMeNow IT Consulting

3 New HHS OCR Breach Submissions Dated August 25, 2026: 5,154 Individuals

HHS OCR listed 3 large HIPAA breach submissions dated August 25, 2026, affecting 5,154 individuals nationally. Desert Pulmonary & Sleep Consultants, P.L.C. led the batch with 3,000 individuals.

Source: HHS Office for Civil Rights — Breach Portal

CybersecurityData BreachHealthcareHIPAAHHS OCR
HHS OCR HIPAA breach submissions for August 25, 2026

The HHS Office for Civil Rights breach portal lists 3 large HIPAA breach submissions with a breach submission date of August 25, 2026. Combined, these filings report 5,154 individuals affected nationally (not state-resident totals).

The largest filing — Desert Pulmonary & Sleep Consultants, P.L.C. (AZ) — accounts for 3,000 individuals in this batch. See our live HIPAA / HHS OCR statistics and healthcare AG tracker for broader context.

August month-to-date now totals 28 OCR submissions covering 7,185,674 individuals dated through August 25, 2026 on the under-investigation portal view.

Submissions Dated August 25, 2026

OrganizationStateEntity TypeIndividualsBreach TypeSubmitted
Desert Pulmonary & Sleep Consultants, P.L.C.AZHealthcare Provider3,000Unauthorized Access/Disclosure08/25/2026
Magnolia Medical Clinic PAFLHealthcare Provider1,601Unauthorized Access/Disclosure08/25/2026
Shoshone Medical CenterIDHealthcare Provider553Hacking/IT Incident08/25/2026

OCR lists breaches affecting 500 or more individuals. Submission dates reflect when the covered entity reported to OCR; investigation status and counts can change as the portal updates.

Independent Cybersecurity Audits

EmailMeNow domain audits on August 25, 2026 scored 3 filer domains in this batch. 3 of 3 show 15% Transport Security or below — a recurring gap that makes spoofed breach-notification email easier to deliver. Desert Pulmonary & Sleep Consultants, P.L.C. (desertpulmonary.com) leads at 55% overall; Shoshone Medical Center (shoshonehealth.com) scores 42%.

Pattern: Scores below the 100% ideal on identity or transport still leave room for spoofed incident-response email — even when website headers score higher.

OrganizationDomainOverallIdentityTransportWebsiteRisk
Desert Pulmonary & Sleep Consultants, P.L.C.desertpulmonary.com55%65%15%45%Average
Magnolia Medical Clinic PAmagnoliamedicalclinics.com44%25%15%62%Below Average
Shoshone Medical Centershoshonehealth.com42%35%15%40%Below Average

Audit links: desertpulmonary.com · magnoliamedicalclinics.com · shoshonehealth.com

Website stack note

  • Desert Pulmonary & Sleep Consultants, P.L.C. (desertpulmonary.com): WordPress behind current (running 3.7.1; latest 7.1.2); WordPress: WordPress core older than 6.4 has multiple known security fixes in later releases; upgrade promptly.
  • Magnolia Medical Clinic PA (magnoliamedicalclinics.com): WordPress behind current (running 7.0.6; latest 7.1.2)

Source: HHS OCR Breach Portal