Healthcare remains one of the most-breached sectors, and Texas organizations appear regularly in the HHS Office for Civil Rights (OCR) breach portal for incidents affecting 500 or more individuals. Texas was among the most-breached states in early 2026, and nationally, March 2026 alone saw 66 reported breaches affecting more than 8.74 million individuals.
Texas Healthcare Breaches by Month (OAG, 2026)
The dashboard below tracks Texas Attorney General breach notices in 2026 that exposed medical or health-insurance information, by month. So far that filter shows 256 reports and 25,103,884 Texans affected, current through Sep 4, 2026.
Interactive Tracker
Texas Healthcare Breaches: 2026 OAG Reports
Texans affected by 2026 breaches exposing medical or health-insurance data, by month
Show largest 2026 healthcare breach reports
| Entity | Published | Texans affected | Sector |
|---|---|---|---|
| Conduent Business Services, LLC (revised submission) | May 20, 2026 | 12,784,367 | Healthcare / Medical |
| DentaQuest, LLC | Jul 17, 2026 | 3,973,000 | Healthcare / Medical |
| Cerner Corporation | Jul 7, 2026 | 2,658,388 | Healthcare / Medical |
| Texas Tech University Health Sciences Center | Apr 27, 2026 | 738,506 | Government / Education |
| Episource, LLC | Feb 11, 2026 | 351,562 | Healthcare / Medical |
Source: Texas OAG Data Security Breach Reports, filtered to 2026 notices listing medical or health-insurance information. Data current through Sep 4, 2026. Totals may change as the OAG updates the portal.
Sources
State AG breach portals
State AG reporting & notices
Federal registries
Texas Entities on HHS OCR (2026)
The HHS OCR portal lists 29 Texas-located covered entities with breach submissions in 2026, reporting 5,919,848 individuals affected (entity location, not Texas-resident totals). Current through September 7, 2026.
Interactive Tracker
Texas Entities on HHS OCR: 2026 Submissions
HIPAA breach reports for Texas-located covered entities with 2026 submission dates
Show largest 2026 Texas HHS OCR breach reports
| Entity | Published | Individuals affected | Sector |
|---|---|---|---|
| Baylor Genetics | Aug 14, 2026 | 2,810,878 | Healthcare Provider |
| Nacogdoches Memorial Hospital n | Mar 30, 2026 | 2,507,073 | Healthcare Provider |
| North Texas Behavioral Health Authority | Mar 6, 2026 | 285,086 | Healthcare Provider |
| Texas Health and Human Services Commission | Jan 5, 2026 | 68,066 | Health Plan |
| Blue Fish Pediatrics | Jun 17, 2026 | 62,150 | Healthcare Provider |
Source: HHS OCR Breach Portal. Entity state is the covered entity location, not a count of Texas residents affected.
Sources
State AG breach portals
State AG reporting & notices
Federal registries
Breach databases & aggregators
News & analysis
Recent Texas Healthcare Breaches (2026)
| Organization | Individuals Affected | Type | Period |
|---|---|---|---|
| Baylor Genetics | 2,810,878 | Healthcare Provider | Aug 14, 2026 |
| Nacogdoches Memorial Hospital n | 2,507,073 | Healthcare Provider | Mar 30, 2026 |
| North Texas Behavioral Health Authority | 285,086 | Healthcare Provider | Mar 6, 2026 |
| Texas Health and Human Services Commission | 68,066 | Health Plan | Jan 5, 2026 |
| Blue Fish Pediatrics | 62,150 | Healthcare Provider | Jun 17, 2026 |
Figures from public breach reporting; see sources below. Counts and entries change as OCR updates the portal.
Also in the Texas OAG Breach Database
The Texas Attorney General’s breach database lists additional Texas healthcare and dental providers:
| Provider | City | Texans Affected | Date Published |
|---|---|---|---|
| Texas Centers for Infectious Disease Associates | Fort Worth | 19,213 | 07/01/2025 |
| Pecan Tree Dental, PLLC | Grand Prairie | 13,300 | 01/30/2026 |
| PET Imaging of Dallas Northeast | Garland | 1,875 | 07/17/2025 |
| Dallas County MHMR (Metrocare Services) | Dallas | 542 | 04/11/2025 |
| Winkler County Hospital District | Kermit | 533 | 06/18/2025 |
| Legent Health (PSN Group, LLC) | Plano | 469 | 07/01/2025 |
| C&C Dental Family, PLLC | Tyler | 421 | 10/21/2025 |
Why Email Security Matters Here
Many healthcare breaches begin with phishing or compromised email — as in the Barrio Comprehensive Family Health Care Center incident above, which stemmed from unauthorized access to the email system. The HIPAA Security Rule requires a documented risk analysis and safeguards for ePHI in transit — areas our audit scores directly.
Check any practice’s posture at audit.emailmenow.com/?industry=healthcare-practices&state=texas.
Recommendations for Practices
- Enforce DMARC, strict SPF, and DKIM; add MTA-STS and security headers.
- Complete and document a HIPAA security risk analysis.
- Train staff and oversee Business Associate vendors.
August 2026 note: Fort Worth’s JPS Health Network isolated systems after “suspicious activity.” That is not an HHS OCR or Texas OAG breach listing unless JPS later confirms unauthorized access to PHI.
Related trackers
- Healthcare AG breach tracker
- Washington healthcare breaches (2026)
- Texas OAG YTD dashboard
- HIPAA / HHS OCR statistics
- Law firm breach tracker
- Washington law firm breaches (2026)
- CA September roundup
- TX September roundup
- WA August roundup
- TX Parks breach
- Have I Been Pwned
- HIBP September roundup
- Breach data week (September)
- HHS OCR August roundup
- SEC 8-K September roundup
- Monitoring guide
- All trackers