Back to news
Cybersecurity Alert
June 2, 2026 by EmailMeNow IT Consulting

HHS Wall of Shame: Texas Healthcare Breaches in 2026

Texas healthcare organizations continue to appear in the HHS breach portal. We track 2026 incidents affecting patients and show how email security gaps contribute to the risk.

HealthcareHIPAAData BreachTexasMedicalPatient Data
Illustration of healthcare data breaches affecting Texas patients in 2026

Healthcare remains one of the most-breached sectors, and Texas organizations appear regularly in the HHS Office for Civil Rights (OCR) breach portal for incidents affecting 500 or more individuals. Texas was among the most-breached states in early 2026, and nationally, March 2026 alone saw 66 reported breaches affecting more than 8.74 million individuals.

Texas Healthcare Breaches by Month (OAG, 2026)

The dashboard below tracks Texas Attorney General breach notices in 2026 that exposed medical or health-insurance information, by month. So far that filter shows 199 reports and 23,275,718 Texans affected, current through Jul 17, 2026.

Interactive Tracker

Texas Healthcare Breaches: 2026 OAG Reports

Texans affected by 2026 breaches exposing medical or health-insurance data, by month

Data current through Jul 17, 2026
2026 YTD reports 199
Texans affected 23.3M
Largest report 12.8M
Jan
130.1K
Feb
596K
Mar
758.6K
Apr
928.5K
May
13.2M
Jun
909.9K
Jul MTD
6.7M
Show largest 2026 healthcare breach reports
Entity Published Texans affected Sector
Conduent Business Services, LLC (revised submission) May 20, 2026 12,784,367 Healthcare / Medical
DentaQuest, LLC Jul 17, 2026 3,973,000 Healthcare / Medical
Cerner Corporation Jul 7, 2026 2,658,388 Healthcare / Medical
Texas Tech University Health Sciences Center Apr 27, 2026 738,506 Healthcare / Medical
Episource, LLC Feb 11, 2026 351,562 Healthcare / Medical

Source: Texas OAG Data Security Breach Reports, filtered to 2026 notices listing medical or health-insurance information. Data current through Jul 17, 2026. Totals may change as the OAG updates the portal.

Sources

State AG breach portals

State AG reporting & notices

Texas Entities on HHS OCR (2026)

The HHS OCR portal lists 19 Texas-located covered entities with breach submissions in 2026, reporting 2,995,934 individuals affected (entity location, not Texas-resident totals). Current through July 20, 2026.

Interactive Tracker

Texas Entities on HHS OCR: 2026 Submissions

HIPAA breach reports for Texas-located covered entities with 2026 submission dates

Data current through July 20, 2026
2026 YTD reports 19
Individuals affected 3M
Largest report 2.5M
Jan
72.7K
Feb
2K
Mar
2.8M
May
29.6K
Jun MTD
65.7K
Show largest 2026 Texas HHS OCR breach reports
Entity Published Individuals affected Sector
Nacogdoches Memorial Hospital n Mar 30, 2026 2,507,073 Healthcare Provider
North Texas Behavioral Health Authority Mar 6, 2026 285,086 Healthcare Provider
Texas Health and Human Services Commission Jan 5, 2026 68,066 Health Plan
Blue Fish Pediatrics Jun 17, 2026 62,150 Healthcare Provider
Eyemart Express, LLC May 18, 2026 25,000 Healthcare Provider

Source: HHS OCR Breach Portal. Entity state is the covered entity location, not a count of Texas residents affected.

Sources

Recent Texas Healthcare Breaches (2026)

OrganizationIndividuals AffectedTypePeriod
Nacogdoches Memorial Hospital n2,507,073Healthcare ProviderMar 30, 2026
North Texas Behavioral Health Authority285,086Healthcare ProviderMar 6, 2026
Texas Health and Human Services Commission68,066Health PlanJan 5, 2026
Blue Fish Pediatrics62,150Healthcare ProviderJun 17, 2026
Eyemart Express, LLC25,000Healthcare ProviderMay 18, 2026

Figures from public breach reporting; see sources below. Counts and entries change as OCR updates the portal.

Also in the Texas OAG Breach Database

The Texas Attorney General’s breach database lists additional Texas healthcare and dental providers:

ProviderCityTexans AffectedDate Published
Texas Centers for Infectious Disease AssociatesFort Worth19,21307/01/2025
Pecan Tree Dental, PLLCGrand Prairie13,30001/30/2026
PET Imaging of Dallas NortheastGarland1,87507/17/2025
Dallas County MHMR (Metrocare Services)Dallas54204/11/2025
Winkler County Hospital DistrictKermit53306/18/2025
Legent Health (PSN Group, LLC)Plano46907/01/2025
C&C Dental Family, PLLCTyler42110/21/2025

Why Email Security Matters Here

Many healthcare breaches begin with phishing or compromised email — as in the Barrio Comprehensive Family Health Care Center incident above, which stemmed from unauthorized access to the email system. The HIPAA Security Rule requires a documented risk analysis and safeguards for ePHI in transit — areas our audit scores directly.

Check any practice’s posture at audit.emailmenow.com/?industry=healthcare-practices&state=texas.

Recommendations for Practices

  • Enforce DMARC, strict SPF, and DKIM; add MTA-STS and security headers.
  • Complete and document a HIPAA security risk analysis.
  • Train staff and oversee Business Associate vendors.