Report: Over 8 Million Personal Healthcare Records breached in August 2016

Some 8.8 million personal healthcare records were breached during August 2016, according to the monthly Protenus Breach Barometer.

According to the report: “The number of breached records reported in August totals an unsettling 8,804,608. While this total does not exceed the staggering 11 million records we reported in June, it once again demonstrates that PHI breaches continue to be a huge problem for a wide array of institutions.”

These breaches stemmed from 44 separate reports of data breaches in August. From January through August, there were 233 reported data breaches in healthcare.


California had six incidents in August, the most of any state. Illinois, New York and Wisconsin each had three incidents while Florida and Maryland each had three.

Protenus is a healthcare data security and privacy monitoring company. The barometer is a snapshot of reported or disclosed breaches impacting the healthcare industry.

According to Protenus, 43% percent of breaches in August were insider incidents, including both accidental and intentional wrongdoing, while 29 percent involved hacking, malware or ransomware.

The largest breach in August, which involved 3.6 million records, was caused by hacking. The causes of another 17 percent were unknown, and 12 percent were caused by loss or theft, Protenus reported. Percentages add up to more than 100 percent due to rounding.

Business associates or vendors were involved in 19 percent of breaches. Those accounted for a disproportionate percentage such that the five business associate incidents for which there is data accounted for 47 percent of all breached records in August, the barometer said. Business associate-oriented breaches included insider errors that resulted in exposure of protected health information as well as ransomware attacks and other hacks.