Healthcare remains one of the most-breached sectors, and Texas organizations appear regularly in the HHS Office for Civil Rights (OCR) breach portal for incidents affecting 500 or more individuals. Texas was among the most-breached states in early 2026, and nationally, March 2026 alone saw 66 reported breaches affecting more than 8.74 million individuals.
Recent Texas Healthcare Breaches (2026)
| Organization | Individuals Affected | Type | Period |
|---|---|---|---|
| Conduent Business Solutions | 25,000,000+ (multiple states, incl. Texas) | Hacking / IT incident | 2026 |
| Nacogdoches Memorial Hospital | 2,507,073 | Hacking incident | March 2026 |
| North Texas Behavioral Health Authority | 285,086 | Hacking incident | March 2026 |
| Barrio Comprehensive Family Health Care Center | 19,971 | Unauthorized access to the email system | March 2026 |
Figures from public breach reporting; see sources below. Counts and entries change as OCR updates the portal.
Also in the Texas OAG Breach Database
The Texas Attorney General’s breach database lists additional Texas healthcare and dental providers:
| Provider | City | Texans Affected | Date Published |
|---|---|---|---|
| Texas Centers for Infectious Disease Associates | Fort Worth | 19,213 | 07/01/2025 |
| Pecan Tree Dental, PLLC | Grand Prairie | 13,300 | 01/30/2026 |
| PET Imaging of Dallas Northeast | Garland | 1,875 | 07/17/2025 |
| Dallas County MHMR (Metrocare Services) | Dallas | 542 | 04/11/2025 |
| Winkler County Hospital District | Kermit | 533 | 06/18/2025 |
| Legent Health (PSN Group, LLC) | Plano | 469 | 07/01/2025 |
| C&C Dental Family, PLLC | Tyler | 421 | 10/21/2025 |
Why Email Security Matters Here
Many healthcare breaches begin with phishing or compromised email — as in the Barrio Comprehensive Family Health Care Center incident above, which stemmed from unauthorized access to the email system. The HIPAA Security Rule requires a documented risk analysis and safeguards for ePHI in transit — areas our audit scores directly.
Check any practice’s posture at audit.emailmenow.com/?industry=healthcare-practices.
Recommendations for Practices
- Enforce DMARC, strict SPF, and DKIM; add MTA-STS and security headers.
- Complete and document a HIPAA security risk analysis.
- Train staff and oversee Business Associate vendors.
Protect your patients. Contact EmailMeNow IT Consulting for HIPAA documentation and email security hardening.
Sources: Texas OAG — Data Security Breach Reports · HHS OCR Breach Portal · March 2026 Healthcare Data Breach Report — HIPAA Journal