← All guides

Reading the HHS Breach Portal

Breaches and enforcement7 min read

Reading the HHS Breach Portal

The HITECH Act requires HIPAA covered entities to report breaches of unsecured protected health information affecting 500 or more individuals to the Secretary of HHS within 60 days of discovery, and it requires HHS to post those reports publicly. The Office for Civil Rights publishes them on its breach portal, informally called the wall of shame. Business associates report to the covered entity, which reports to HHS, so the entity you see is usually the covered entity even when the incident happened at a vendor.

The portal has two lists. Cases under investigation are recent reports OCR is still reviewing. The archive holds resolved cases, and only archived rows carry OCR's narrative describing what happened and what the entity changed. Records are edited in place and moved between lists without a stable identifier, which is why any serious analysis needs its own change tracking, as this site does.

Every column comes from the entity's own report. Individuals affected is the entity's estimate at filing and is frequently revised later. Type of breach and location of breached information can each carry more than one value. A yes in the business associate column means a vendor was involved, not that the vendor is named.

Key points

  • 500-individual threshold

    Only breaches affecting 500 or more individuals appear on the portal. Smaller breaches are reported to HHS annually and are not published individually, so the portal undercounts incidents by design.

  • Under investigation versus archive

    The split is investigation status, not age. The current list reaches back years and the archive contains cases resolved last month. Moving to the archive means OCR closed the matter, with or without a corrective action plan.

  • Submission date

    The date the report was filed with HHS, not the date of the incident or of discovery. Discovery can be months earlier, and the report can legally be filed up to 60 days after discovery.

  • Web description

    OCR's closing narrative for archived cases. It typically states the cause, the scope, and the safeguards the entity implemented afterward. It is the closest thing to a public lessons-learned record in healthcare security.

  • Entity type

    Healthcare provider, health plan, healthcare clearinghouse, or business associate. When a business associate files directly, the entity type says so; more often the covered entity files and the business associate column is set to yes.

  • Location of breached information

    Where the data lived: network server, email, electronic medical record, paper, laptop, and so on. Network server plus hacking is the dominant modern pattern; email is a close second.

Common mistakes

  • Reports versus incidents

    One incident at a vendor can generate dozens of reports, one per covered entity client. Counting rows overstates incidents; summing individuals across those rows can double-count the same people.

  • Individuals affected versus records

    The figure counts people, not files or messages. It is also an initial estimate that entities revise; the portal shows the current figure, not the history.

  • Listed versus culpable

    A listing is a report, not a finding. Many archived cases close with no penalty. Treat a listing as a starting point for questions, never as a verdict on the organization.

Sources

;

See it in the live data.

Open the breach register