Back to news
Cybersecurity Alert
July 31, 2026 by EmailMeNow IT Consulting

4 New HHS OCR Breach Submissions Dated July 31, 2026: 6,166 Individuals

HHS OCR listed 4 large HIPAA breach submissions dated July 31, 2026, affecting 6,166 individuals nationally. Monongalia County General Hospital Company led the batch with 2,173 individuals.

Source: HHS Office for Civil Rights — Breach Portal

CybersecurityData BreachHealthcareHIPAAHHS OCR
HHS OCR HIPAA breach submissions for July 31, 2026

The HHS Office for Civil Rights breach portal lists 4 large HIPAA breach submissions with a breach submission date of July 31, 2026. Combined, these filings report 6,166 individuals affected nationally (not state-resident totals).

The largest filing — Monongalia County General Hospital Company (WV) — accounts for 2,173 individuals in this batch. See our live HIPAA / HHS OCR statistics and healthcare AG tracker for broader context.

July month-to-date now totals 41 OCR submissions covering 23,438,156 individuals dated through July 31, 2026 on the under-investigation portal view.

Submissions Dated July 31, 2026

OrganizationStateEntity TypeIndividualsBreach TypeSubmitted
Monongalia County General Hospital CompanyWVHealthcare Provider2,173Hacking/IT Incident07/31/2026
Asheville Victoria NC Opco LLC d/b/a Elevate Health & RehabilitationNCHealthcare Provider1,551Hacking/IT Incident07/31/2026
Asheville Beaverdam NC Opco LLC d/b/a Bear Mountain Health and RehabilitationNCHealthcare Provider1,397Hacking/IT Incident07/31/2026
Asheville US Seventy NC Opco LLC d/b/a Swannanoa Valley Health and RehabilitationNCHealthcare Provider1,045Hacking/IT Incident07/31/2026

OCR lists breaches affecting 500 or more individuals. Submission dates reflect when the covered entity reported to OCR; investigation status and counts can change as the portal updates.

Independent Cybersecurity Audits

EmailMeNow domain audits on July 31, 2026 scored 1 filer domain in this batch. 1 of 1 show 15% Transport Security or below — a recurring gap that makes spoofed breach-notification email easier to deliver.

Pattern: Scores below the 100% ideal on identity or transport still leave room for spoofed incident-response email — even when website headers score higher.

OrganizationDomainOverallIdentityTransportWebsiteRisk
Asheville Victoria NC Opco LLC d/b/a Elevate Health & Rehabilitationasheville.com37%25%15%37%Weak

Audit links: asheville.com


Source: HHS OCR Breach Portal