Healthcare remains one of the most-breached sectors, and Texas organizations appear regularly in the HHS Office for Civil Rights (OCR) breach portal for incidents affecting 500 or more individuals. Texas was among the most-breached states in early 2026, and nationally, March 2026 alone saw 66 reported breaches affecting more than 8.74 million individuals.
Texas Healthcare Breaches by Month (OAG, 2026)
The dashboard below tracks Texas Attorney General breach notices in 2026 that exposed medical or health-insurance information, by month. So far that filter shows 199 reports and 23,275,718 Texans affected, current through Jul 17, 2026.
Interactive Tracker
Texas Healthcare Breaches: 2026 OAG Reports
Texans affected by 2026 breaches exposing medical or health-insurance data, by month
Show largest 2026 healthcare breach reports
| Entity | Published | Texans affected | Sector |
|---|---|---|---|
| Conduent Business Services, LLC (revised submission) | May 20, 2026 | 12,784,367 | Healthcare / Medical |
| DentaQuest, LLC | Jul 17, 2026 | 3,973,000 | Healthcare / Medical |
| Cerner Corporation | Jul 7, 2026 | 2,658,388 | Healthcare / Medical |
| Texas Tech University Health Sciences Center | Apr 27, 2026 | 738,506 | Healthcare / Medical |
| Episource, LLC | Feb 11, 2026 | 351,562 | Healthcare / Medical |
Source: Texas OAG Data Security Breach Reports, filtered to 2026 notices listing medical or health-insurance information. Data current through Jul 17, 2026. Totals may change as the OAG updates the portal.
Sources
State AG breach portals
State AG reporting & notices
Texas Entities on HHS OCR (2026)
The HHS OCR portal lists 19 Texas-located covered entities with breach submissions in 2026, reporting 2,995,934 individuals affected (entity location, not Texas-resident totals). Current through July 20, 2026.
Interactive Tracker
Texas Entities on HHS OCR: 2026 Submissions
HIPAA breach reports for Texas-located covered entities with 2026 submission dates
Show largest 2026 Texas HHS OCR breach reports
| Entity | Published | Individuals affected | Sector |
|---|---|---|---|
| Nacogdoches Memorial Hospital n | Mar 30, 2026 | 2,507,073 | Healthcare Provider |
| North Texas Behavioral Health Authority | Mar 6, 2026 | 285,086 | Healthcare Provider |
| Texas Health and Human Services Commission | Jan 5, 2026 | 68,066 | Health Plan |
| Blue Fish Pediatrics | Jun 17, 2026 | 62,150 | Healthcare Provider |
| Eyemart Express, LLC | May 18, 2026 | 25,000 | Healthcare Provider |
Source: HHS OCR Breach Portal. Entity state is the covered entity location, not a count of Texas residents affected.
Sources
State AG breach portals
State AG reporting & notices
Federal registries
Breach databases & aggregators
News & analysis
Recent Texas Healthcare Breaches (2026)
| Organization | Individuals Affected | Type | Period |
|---|---|---|---|
| Nacogdoches Memorial Hospital n | 2,507,073 | Healthcare Provider | Mar 30, 2026 |
| North Texas Behavioral Health Authority | 285,086 | Healthcare Provider | Mar 6, 2026 |
| Texas Health and Human Services Commission | 68,066 | Health Plan | Jan 5, 2026 |
| Blue Fish Pediatrics | 62,150 | Healthcare Provider | Jun 17, 2026 |
| Eyemart Express, LLC | 25,000 | Healthcare Provider | May 18, 2026 |
Figures from public breach reporting; see sources below. Counts and entries change as OCR updates the portal.
Also in the Texas OAG Breach Database
The Texas Attorney General’s breach database lists additional Texas healthcare and dental providers:
| Provider | City | Texans Affected | Date Published |
|---|---|---|---|
| Texas Centers for Infectious Disease Associates | Fort Worth | 19,213 | 07/01/2025 |
| Pecan Tree Dental, PLLC | Grand Prairie | 13,300 | 01/30/2026 |
| PET Imaging of Dallas Northeast | Garland | 1,875 | 07/17/2025 |
| Dallas County MHMR (Metrocare Services) | Dallas | 542 | 04/11/2025 |
| Winkler County Hospital District | Kermit | 533 | 06/18/2025 |
| Legent Health (PSN Group, LLC) | Plano | 469 | 07/01/2025 |
| C&C Dental Family, PLLC | Tyler | 421 | 10/21/2025 |
Why Email Security Matters Here
Many healthcare breaches begin with phishing or compromised email — as in the Barrio Comprehensive Family Health Care Center incident above, which stemmed from unauthorized access to the email system. The HIPAA Security Rule requires a documented risk analysis and safeguards for ePHI in transit — areas our audit scores directly.
Check any practice’s posture at audit.emailmenow.com/?industry=healthcare-practices&state=texas.
Recommendations for Practices
- Enforce DMARC, strict SPF, and DKIM; add MTA-STS and security headers.
- Complete and document a HIPAA security risk analysis.
- Train staff and oversee Business Associate vendors.
Related trackers
- Healthcare AG breach tracker
- Washington healthcare breaches (2026)
- Texas OAG YTD dashboard
- HIPAA / HHS OCR statistics
- Law firm breach tracker
- Washington law firm breaches (2026)
- CA July roundup
- TX July roundup
- WA May roundup
- TX Parks breach
- Have I Been Pwned
- HIBP July roundup
- Breach data week (July)
- HHS OCR July roundup
- SEC 8-K July roundup
- Monitoring guide
- All trackers