171 published accounts of health record breaches from 87 countries and territories
A breach, as we file it: the record was stolen, leaked, hacked, or read by staff with no part in the person's care.
Published October 2024 to September 2026, found in sources in 39 languages: 171 of all 442 cases. By region, 7 in Africa, 28 in the Americas, 30 in Asia, 86 in Europe, 8 in the Middle East and 12 in Oceania. Of these, a regulator or court decided 61, the organization involved admitted 60 and 50 are allegations not decided. The sources: 35 decisions by regulators and ombudsmen, 4 court judgments and 132 reports by edited news outlets. 24 decisions are known to us from a news report of it. The list last changed on October 7, 2026.
Each case is filed under one kind of problem when it is written, by the rule above; the cases here are the ones filed under it. These cases are not a sample: they show what is published and findable, not how common breaches are.
Each case's id links its line on Real cases, the one address to cite. Every case, every kind of problem, by country: Real cases.
By month and region
all cases that monthcases filed as breacha month not yet overevery panel on the same scale, 0 to 15 cases a month
Africa47 cases, 25 countries and territoriesAmericas89 cases, 29 countries and territoriesAsia76 cases, 25 countries and territoriesEurope187 cases, 47 countries and territoriesMiddle East25 cases, 13 countries and territoriesOceania18 cases, 6 countries and territories
Each bar counts the cases whose source was published that month, October 2024 to October 2026, by region. Pick a kind of problem to see its share of each bar. Counts show what was published and what our searches found, not how often problems happen. October 2026 runs only to October 3, 2026, the newest source date, so its bars are drawn as outlines. Every case as a spreadsheet (CSV).
See the numbers
Cases filed as breach, by month of the source and by region
Month
Africa
Americas
Asia
Europe
Middle East
Oceania
All
October 2024
1
0
1
2
0
0
4
November 2024
0
0
2
2
0
0
4
December 2024
2
1
0
3
0
0
6
January 2025
0
1
0
3
1
0
5
February 2025
0
0
2
6
0
0
8
March 2025
0
1
2
4
0
2
9
April 2025
0
1
3
3
1
0
8
May 2025
0
0
0
3
0
0
3
June 2025
0
2
2
1
0
4
9
July 2025
0
2
1
6
0
1
10
August 2025
0
0
2
2
0
1
5
September 2025
0
1
0
5
0
0
6
October 2025
0
0
2
2
1
0
5
November 2025
1
0
0
2
0
1
4
December 2025
0
1
0
4
0
0
5
January 2026
0
0
0
0
0
1
1
February 2026
2
1
1
1
1
1
7
March 2026
0
0
1
2
1
0
4
April 2026
1
4
0
7
0
0
12
May 2026
0
5
3
4
0
0
12
June 2026
0
3
1
4
0
0
8
July 2026
0
1
1
5
1
0
8
August 2026
0
2
2
4
1
0
9
September 2026
0
2
4
11
1
1
19
October 2026 (so far)
0
0
0
0
0
0
0
All
7
28
30
86
8
12
171
Cases filed as breach, by how settled they are and by region
How settled
Africa
Americas
Asia
Europe
Middle East
Oceania
All
A regulator or court decided
2
5
6
42
3
3
61
The organization admitted the problem
1
12
10
31
1
5
60
Alleged, not decided
4
11
14
13
4
4
50
All
7
28
30
86
8
12
171
Cases filed as breach, by kind of source and by region
About 50 nurses and doctors are charged with unlawfully reading one patient's record with no part in his care. He learned of it when a staff member mentioned details of his care. He said he lost faith in healthcare.
Attackers used a flaw in practice software used by hundreds of clinics to take names, national ID numbers, contacts and discharge documents. It went unnoticed for over two weeks. The vendor said it fixed the flaw and forced password changes.
A health insurance member has sued doctors and former insurer staff, saying they pulled her file from a confidential database and forged her signature to bill for procedures she never received.
After a cyberattack exposed health documents belonging to 99,416 people, a review found gaps in protection, weak oversight of tech suppliers and late notice to those affected. The portal operator and Health NZ were ordered to strengthen safeguards.
A public specialist centre emailed an invitation to a patient event using CC instead of BCC, so all 467 recipients could see each other's addresses. The centre apologised and reported the incident to the health ministry and the privacy regulator.
The paper reported cases documented by the health ministry in which practitioners photographed patients during care and published the images online. In one case the ministry cancelled a licence and imposed a fine.
A hospital employee photographed patients and a document holding sensitive personal data and shared the images outside the hospital. The hospital confirmed it, disciplined the worker and reported the case to the data protection authority and police.
A security firm reported that a hacking group stole a database from an unnamed Czech health facility and offered it for sale. It reportedly held patient contacts with health records, booking details with payment and insurance data, and staff profiles.
A doctor deliberately took 3,976 patients' personal data while preparing to open a practice. The privacy regulator fined the hospital for late notification and weak supervision of staff, but found no breach of security duties.
Disciplinary files that the public health insurer and claims review agency gave a lawmaker show staff viewing relatives' and an ex-partner's data, querying colleagues, and emailing sensitive screening files home. Penalties ranged from reprimand to dismissal.
A ransomware group said it took about 2.44 terabytes of hospital data, including patient records and scans, and demanded payment. The hospital in Mindanao said its first checks found no sign of a breach and it was still investigating.
A mass email inviting donors to a blood drive showed every recipient's address. Hundreds of donors were affected. The hospital apologised the next day and said no health or donation history was shared.
An IT company serving medical practices said a cyberattack affected 40 practices. It filed a police complaint, notified the data protection authority and said experts found no data leak. Services were later restored.
A health services company notified the data protection authority that a ransomware attack encrypted its data over two days. It could not yet say which people or data categories were affected. The board ordered the notice published.
Intruders reached paper patient records in disused health service storage and filmed them. The data protection regulator found records insecure and damaged, breaches reported late, and affected people not told, and imposed a fine.
France's data regulator fined a private hospital 500,000 euros after an attacker used one compromised account to reach data on 524,867 patients, some including health data. Access needed no multifactor login and suspicious activity went undetected.
Someone repeatedly entered a records system used by over 300 Estonian dental and health providers and downloaded patients' ID codes, emails and health data. Police arrested a suspect; prosecutors said the data appears not to have been shared.
Attackers encrypted the system holding a national specialist hospital's clinical plans and images and demanded payment. The hospital's leadership said it refused to negotiate, reported the attack to prosecutors and police, and rescheduled 194 patients.
A patient saw in the national e-health log that a sanatorium's staff had opened a referral written for a different specialist. The regulator found no lawful basis for viewing it and reprimanded the sanatorium.
A hacking group claimed it broke into a private medical practice and posted about 9,400 records for free download, including names, national ID numbers, addresses, medicines, doctors' notes and scanned medical documents. The practice was not named.
A company storing electronic medical records for healthcare providers told federal regulators hackers stole personal information and medical records of more than 3.75 million people, including Social Security numbers, health information, ID numbers and banking details.
A forum poster claimed to have breached the national health insurer's database and offered data for sale, posting a sample of over 342,000 records linking insured people's identity numbers to their chosen doctors. The insurer is reviewing but cannot confirm.
Hackers copied insurance policy numbers, claims and benefits data, medical record numbers and Social Security numbers from a health billing software vendor. The vendor reported 3.8 million people affected to federal regulators about nine months after discovering the intrusion.
An investigation into teaching hospitals quoted a trainee who said students filmed a procedure on their phones and the patient's name appeared in the footage. No one told the patient. The health ministry did not reply.
A hospital group's chief executive told police that patients' personal details and medical records, with staff data and internal documents, were posted on an outside website. The state cyber bureau registered a case and is investigating.
A health worker who supervised a colleague opened the colleague's national health record to check whether sick leave was open. The person had restricted access to their health data. The regulator still found the lookup unlawful and issued a reprimand.
A user claiming to hold a private hospital's database reportedly posted patients' identity numbers, addresses, diagnoses, prescriptions and insurance details online. The leak was unconfirmed and neither the hospital nor authorities had commented when reported.
A report says a doctor at a clinic filmed a patient during care and posted it as an advertisement. A physician called publishing such footage without consent a breach of medical secrecy.
A family member with power of attorney obtained the record's access log and found entries by staff outside the care team. The hospital admitted improper access but withheld names; the commission said the names must be given.
Spain's data protection authority fined 23andMe 2.4 million euros after a hacker used stolen passwords to reach sensitive health and genetic data of about 2,600 Spanish residents. The regulator found its safeguards insufficient.
A member reported he could open a relative's medical file because of a system fault. The regulator found the fund knew in November 2025 but reported only in January, and fined it 256,000 shekels. The fund plans to appeal.
A patient in the Bashkortostan region learned people outside her care knew details from her medical file. The regional health ministry confirmed a worker at another hospital had accessed it unlawfully and dismissed him, but refused her the inspection file.
An attacker broke into a private health provider's system, downloaded its patient database and published the data of about 33,000 people online. The Supreme Court refused his appeal, so the appeal court's sentence of six years and 11 months stands.
Freedom of information requests found Scotland's health boards logged more than 5,000 data breaches over four years, including staff sharing confidential patient information and records wrongly accessed. At least 182 staff were disciplined and police were informed six times.
A ransomware attack on an organisation running public health units in several states affected records of about 500,000 patients. The data authority opened a sanction case, citing poor notice to those affected. The operator denies any data leaked.
An adult patient says an automatic clinic notice about her care went to a family member. The health ministry said the clinic had likely never updated a relative's number added years earlier, and it is reviewing the SMS system.
A small GP surgery recorded a mistyped email address without checking it, then sent the patient's personal data, unencrypted, from a free email account to a stranger. After the regulator engaged, it moved to secure email and a patient portal.
A reported ransomware attack on a private hospital group encrypted electronic clinical records and booking systems, forcing staff back to paper and delaying admissions, tests and appointments while attackers reportedly demanded payment.
A leaked staff login let an outsider open 63 patients' files, and a later ransomware attack hit systems holding records of about 383,000 patients. The regulator found security was inadequate and fined the company 450,000 euros.
A newspaper reports that an attacker allegedly took 14.8 million records and 10.6 million photos from the public health system in 2025, including clinical histories and emergency forms, later passed off as civil registry data.
The National Health Fund confirmed a cyber incident after a hacker group said it held clients' medication data. The fund reported it to the Information Commissioner and police investigators and said affected stakeholders were contacted.
An NHS hospital trust confirmed that thousands of patient records, including test results, were stolen from a third-party testing provider's systems. The supplier said the data, possibly including names, NHS numbers and postcodes, was published on the dark web.
Hard drives two public hospitals sent for destruction were listed on internet auctions, holding names, addresses, clinical notes and nursing records for up to 510,000 people. The disposal firm said destroyed and intact drives were kept in identical containers.
A district court convicted a former nurse of data intrusion for unauthorised record lookups over several years, ordering a conditional sentence and 115,000 kronor in damages. Nineteen cases were tried; about 60 people had reported her to police.
Details from a patient's record were broadcast on a television programme. The public health insurer issued a statement rejecting the leak and opened an internal audit to identify the people who breached its system and supplied the information.
Data about a woman's medical test could be opened directly from a major search engine, with no password. A Santa Catarina court found two clinics failed to protect it and upheld R$5,000 in damages, ordering the data removed.
A fact-checking investigation found at least 40 purchase files on the insurer's public procurement search showing members' clinical histories, test results and ID copies. The insurer called it a serious anomaly, removed the files and opened internal inquiries.
A police cybersecurity official said attackers hit hospital or health ministry data twice in one month, threatening to expose details of thousands of doctors and patients, including diagnostic imaging, and warned that health sector security is weak.
The national health insurer said attackers hit one of its information systems and technical checks pointed to a possible data exfiltration. Its director later said no leak had yet appeared online and the investigation was continuing.
Attackers claimed to be selling 700 GB from a national government health database, including clinical records and personal details of up to 52 million people. A national deputy filed requests for information. The leak was unconfirmed.
A specialist doctor opened an adult's health record six times over several years without a treatment relationship or consent. The data protection authority ruled those look-ups unlawful but imposed no fine.
A radiology network operating in seven cantons was attacked again in April 2026 and postponed some examinations. It could not yet say whether data was taken. In an attack a year earlier, patient data was stolen and a ransom demanded.
A software firm that ran a hospital's online appointment system copied registration details of about 2.88 million patients into its own database over several years. A court convicted the firm and its managers, with fines and prison terms.
For about 48 hours, a people-search website let anyone enter a Chilean ID number and see that person's diagnoses under the national guaranteed-care scheme, alongside address and contact details. Police and the cybersecurity agency are investigating.
A member of the public found, through a search engine, a hospital file listing about 2,820 patients' phone numbers and planned operations, online for months. The hospital reported late, never told patients, and was fined 25,000 euros.
A public hospital's administrative support worker opened another person's electronic record several times with no work reason and told others what it showed. The prefectural hospital bureau suspended her for three months.
Ontario's privacy commissioner found several workers at an Ontario hospital network opened patient records without authority between 2023 and 2025. In one breach up to 326 patients were affected, and some were not told for ten months.
A patient complained that an outsider obtained exact details of her care from a public health centre. The data protection agency could not confirm a leak because staff denied it; she received no sign of an internal inquiry.
A maker of electronic patient record software confirmed that ransomware attackers stole patients' personal data, including medical records, from several Dutch healthcare institutions. It first said theft was unlikely. Sixty-six institutions reported a breach to the data protection authority.
Reporters said they could search and download insured people's medical histories, signatures and phone numbers from a site run by hackers who offered the data for sale. Security experts said they had warned the institution for weeks.
A patient saw in the national health portal that a hospital worker had opened their record on several dates without reason. The county governor found clear breaches of confidentiality but closed the case without sanction.
A hospital's log checks showed a nurse had opened the electronic files of several patients he was not treating, more than once and over a long period. He admitted it, citing curiosity and boredom. The tribunal reprimanded him.
The health ministry confirmed an attack that encrypted internal files at its national laboratory. It said backups restored the files and it found no evidence that patient data was accessed, but some processes and its web platform were interrupted.
Reporters found that people arrested in a police crackdown were routinely tested, and their test results and names were then printed in national newspapers. Health workers said frightened patients are now staying away from clinics.
Attackers encrypted servers at a private hospital. The breach notice published by the data protection authority lists patients, staff and visitors among those affected, with data including sexual life and biometric details. The number affected was not yet known.
Records of about 6,500 patients of a private clinic, with names, addresses, phone numbers and doctors' reports, were posted online. The data protection commissioner opened an inspection and said the clinic had not yet reported the breach.
The national health regulator confirmed unauthorised access to its document system. Reports say files downloaded included medical histories and patients' petitions and complaints, about 1.6 percent of its document store.
A ransomware attack encrypted personal data held by a public health institution. On inspection the data protection regulator found the institution lacked proper technical and organisational safeguards and was poorly prepared to handle security incidents.
A national lab network reported unauthorised access, through a server run by an outside IT supplier, to patient names, emails, encrypted passwords, analysis reports and social security numbers. It was the network's second attack in about a year.
Staff recorded patients during procedures and the video spread online. The provincial health department, which runs the hospital, suspended senior staff and said the recording breached medical ethics and undermined patient privacy.
A patient checked the access log in the national health record system and found a doctor they had left kept viewing their results and prescriptions for 19 months. The doctor also ignored their access request. The regulator imposed a fine.
A ransomware group listed a private hospital on its leak site, claimed to hold 110 GB of its data, posted images of systems it said it had accessed, and threatened to publish the data unless paid.
Attackers reached files of 1,500 doctors using one practice software. Administrative data on 15 million patients leaked, and the health minister said sensitive doctor annotations on 164,000 patients were exposed. The vendor said structured medical records were intact.
A hacker group claimed to have stolen and posted documents of more than 10,000 patients, including referrals and sick-leave notes. The fund said it was checking the claim with national cyber authorities and had reported to the privacy regulator.
An audit two patients requested showed a health worker they knew had opened both their medical records, over a personal matter, using a colleague's login. She lost her job, and a court found her guilty.
A government agency suspended a hospital worker, accusing him of escorting journalists through wards and broadcasting live on social media. The agency said this exposed vulnerable patients and compromised their privacy, and ordered an investigation.
A university hospital announced that a ransomware attack, entering through a VPN device used for medical equipment maintenance, led to the theft of names, addresses, birth dates and patient IDs of about 10,000 patients.
A national public health council said wide media coverage of arrests had exposed people's health status, noted that unauthorised disclosure is punished under a 2010 law and may engage state liability, and warned people may avoid testing.
A report says a cyberattack exposed patients' names, addresses, phones, emails and diagnoses, later offered for sale. The hospital filed a criminal complaint; earlier it said only part of a website was hit and patient records were safe.
After a ransomware attack on a patient portal, a woman told her records were affected could not log in, and the helpline cut her off. Another was told both that her data was and was not affected.
Data stolen in March from the company running a portal family doctors use to send prescriptions went on sale online: prescriptions, sick notes, exemption certificates, emails, phones and addresses. The company reported it to police and warned patients of phishing.
A ransomware group reportedly took about 250 GB from a private clinic, including clinical records, test results and identity card copies. Chile's consumer agency ordered the clinic to report how many patients were affected and how they were told.
A patient asked her hospital group who had opened her electronic record. The list showed a therapist working there had viewed her test results three times. The regulator reprimanded the hospital for weak access controls; an appeal is pending.
A patient learned his report had gone to an address one letter different from his, carrying his name, birth date and tax code. The regulator found no address check was in place and issued a formal warning.
The hospital said attackers took personal data of patients and staff from its systems and threatened to publish it in the media and online. It reported the attack to police, the data regulator and the digital security authority.
The regulator found the lab had suffered breaches and not notified affected people within a reasonable time. It ordered better security and notification processes, then fined the lab R100,000 for not complying. The lab paid.
A doctor in Western Australia repeatedly opened a patient's records and passed details to a person the patient had a restraining order against. The State Administrative Tribunal found misconduct and the doctor was deregistered.
A hospital employee opened an adult patient's health record twice with no work reason. The data protection authority held the employee personally responsible and ruled the look-ups unlawful.
A health worker used work access to read an adult family member's national health record for personal reasons. The person said the information reached a third party. The regulator found no lawful basis and fined the worker 250 euros.
A specialist's report on a patient was printed from the hospital system using an absent doctor's login and read aloud in a public trial. The ombudsman found the hospital responsible for failing to protect the data.
Several large hospitals' online services released test reports and records to anyone with a patient's name and ID number. Someone a woman knew used this for two years to obtain and circulate her records. Some hospitals then added identity checks.
Asked by a newspaper, the hospital said no employee had been held responsible for recent leaks of patients' health information. It said all staff must now sign confidentiality contracts to stop disclosures to third parties.
The report lists several attacks on major hospitals, including encrypted servers, ransom demands and patient and staff records advertised for sale on cybercrime forums. It reports no statement from the hospitals and no penalty.
The health ministry said initial checks showed emails sent to and from the hospital on one day had leaked, including medical information in them. It said there was no sign so far of a leak from the central record system.
The state hospital body reported losing ten patients' medical files and three emergency registration forms. The regulator found no safeguards against loss, fined it 46,500 euros in total and ordered it to tell seven patients.
A patient obtained the log of who had opened their record and reported it to police. The wellbeing region found two employees had viewed nearly 150 people's records without a care relationship, and its chief medical officer apologised.
Attackers reached a municipal system the hospital used, taking names, personal codes and addresses of its staff and clients. The regulator found the hospital had not supervised the supplier or reported on time, and reprimanded it. The hospital appealed.
A video of an adult patient filmed inside the hospital without permission circulated online. The hospital said a technician was the suspect, called it a violation of patient privacy, apologised, and referred the matter to police.
A random audit found an employee had looked into municipal care records without a work reason for around 15 years, affecting about 2,100 residents. The municipality reported it to police and said it saw no sign of onward sharing.
A patient saw patient record cards in a clear box on the front seat of a doctor's parked car, with one card's name, address, birth date and ID number readable. The regulator reprimanded the doctor and ordered the patient notified.
A woman found through the ELGA access log that a doctor had opened her stored results and medication data without consent and unconnected to any treatment by that doctor. The regulator found a violation and imposed a 1,000 euro fine.
A seller on a breach forum offered about 398,000 records said to include patients' national ID numbers, phone numbers, addresses and medical appointment details. The report said no official statement had been issued.
A lab running part of a national screening programme confirmed it was hacked. Test results, names, addresses, provider names and GP referrals of about 485,000 women, going back years, were stolen. The screening organisation said several years were involved.
The outlet reports indications that several staff at a public hospital opened a patient's medical records without a care reason. The hospital operator said patient confidentiality is of the utmost importance.
A large private hospital hired a small contractor to destroy patient records but did not oversee the work. Over 1,000 record pages leaked and were reused as snack bags. The regulator fined the hospital and the contractor.
Hackers broke into a private clinic network owned by an insurer, the company confirmed, alongside attacks on two pharmacy chains. Services were disrupted; the clinic said patient data leakage had not been confirmed.
After an attack disrupted all its German facilities, a hospital group said data on patients, staff and partners may have been accessed without authorisation and could be misused or passed to others.
A cyberattack left a private clinic's patient records unreachable for a week. The clinic, holding data on about 250,000 patients, did not report it in time and could not prove it told patients. The court confirmed a 309,000 crown fine.
Personal data of about 16.3 million people appeared online. The prime minister said preliminary findings pointed to medical organisations that had access to state databases but failed to protect them. A criminal case was opened.
After ransomware shut down its systems, a hospital told patients that personal data linked to their medical records may have been stolen. It could not yet confirm whether or how much was taken, and notified the data protection office.
A seller claimed to offer 400,000 lines of data from a private hospital group: patients' names, national ID and tax numbers, phones, emails, insurance policies, diagnoses and medical notes. The report carried no response from the hospital.
A photo of a computer screen showing a hospitalised patient's record spread online. The national health regulator ruled the disclosure a grave breach of confidentiality and fined the clinic more than 668,000 soles; the clinic said it would appeal.
The outlet reports that confidential information from the national health system was copied and leaked by the criminals who encrypted it and demanded a ransom, which the government refused to pay.
An unknown hospital employee photographed a patient's result in the hospital system and it was published by the media. The hospital neither reported the breach nor told the patient until their lawyer wrote. The regulator fined it.
After a ransomware attack, the regulator found a hospital's weak technical safeguards let an attacker roam its systems unnoticed for about seven days and copy at least 3 GB out. The hospital was fined 20,000 euros.
Another government minister told the outlet that protective software licences on the health records system had expired and backup procedures were not followed properly before hackers broke in, leaving the records exposed.
The outlet reports growing concern about illegal access to health records after hackers breached the national system, while patients were told to bring any medical records they hold to hospital because staff were working from manual data.
A video of a patient receiving hospital care circulated on social media. The hospitals authority called it a breach of privacy, condemned its sharing, and said staff found involved would face strict discipline.
The national incident response team CERT-PY said a cyber incident hit the Ministry of Health and was contained. A security expert warned that data taken in such attacks usually ends up exposed on dark web forums.
The health minister said a ransomware attack took down the national health information system, which holds patients' medical records and prescriptions. The ministry told people to bring their prescription cards because doctors could not open records.
A government agency sent a person's health information to the wrong address because a staff member recorded the house number incorrectly. The agency at first denied a mistake; after the regulator stepped in, it apologised and agreed to pay compensation.
A former public specialist centre employee was charged with accessing personal data of 18 patients without authorisation and downloading photos of 42 patients from its systems. The centre said it began an internal probe and filed a police report.
A district court confirmed the data protection authority's finding that the national patient portal had a serious security weakness letting users open others' health files and messages. It cut the fine on the Directorate of Health to ISK 8 million.
An outlet reports that a doctor posted video taken during care that showed a patient's body uncovered. The posting drew public criticism over patient confidentiality.
A clinic computer storing images and data from nearly two thousand examinations disappeared for four days, then reappeared. The hospital's internal review called it a data incident, its director confirmed it, and it was reported to the data protection office.
The state regulator reported a practice manager who took patient records home and left them unsecured, where party guests could see them, and who also sent photos of patient files to a partner by messaging app.
A user found that changing a web address in the national patient account showed other patients' documents, with names, national ID numbers, ID card numbers and health data. The ministry confirmed the flaw but would not name the facility.
A staff member with no role in the patient's care opened their record for personal reasons. The regulator found the access unauthorised. The provider had dismissed the employee and told the patient, so no further action followed.
Shanghai's cyberspace regulator penalised several online medical service firms. One had unpatched flaws and suspicious foreign access that led to data theft; another stored over 6.5 million patient records, including conditions and prescriptions, without encryption.
A disciplinary court suspended a public hospital doctor for six months. Prosecutors found she disclosed confidential medical information about patients online without their or the hospital's permission, and used patient information to promote clinics.
A hospital staff member opened a former patient's record on the hospital system for personal reasons and filmed the screen showing their ID number, address and contacts. The patient complained; she pleaded guilty and was fined.
A ransomware group said it took about 178,000 files from a private clinic, including invoices and treatment reports, and threatened to publish them. The clinic had not answered press questions when the report appeared.
A patient asked a private doctor for her full file and complained the doctor had also searched her electronic health record. The regulator found the lookup unlawful, done without her knowledge, and fined the doctor 5,000 euros.
Security researchers reported finding a file on a subsidiary website holding patient records, vaccination reports and identity documents. They told national cyber agencies; more than 60 days later the report saw no meaningful response and the chain had not replied.
Criminals put up for sale 665,128 medical test results with patients' personal details, taken from a company that stores imaging for about 30 clinics and hospitals in several provinces. After extortion failed, the data went on sale.
An employee opened the electronic health records of 70 people in Saskatchewan 210 times without a work reason. The commissioner found the health authority did not contain the breach properly or tell those affected enough.
After hackers took and posted names, ID and phone numbers of about 200,000 patients, a patient complained. The commission found weak cyber security, no rules for handling personal data and no breach plan, and ordered an audit and fixes.
Hackers entered a supplier's health systems through an account without multi-factor authentication. Data on 79,404 people was taken, including how to enter the homes of 890 people receiving care at home. The ICO fined the supplier £3.07m.
Women checked the access log for their records on sundhed.dk and saw that a doctor with no part in their care had looked them up. The regions found many more unauthorised lookups and reported him to police.
Ransomware hit the Yap State health department's network. The department shut down every computer and its digital health systems, said so in a public notice, and kept serving patients more slowly while systems were rebuilt.
A patient complained to the data protection regulator that a doctor kept accessing her medical records after she left his care. He sued her for libel. A court dismissed the suit, ruling her complaints were privileged.
The health ministry said attackers accessed hospital patient data, including names, addresses, phone numbers, birth dates and medical details. It advised everyone in Palau to watch for fraud and phishing messages.
After a ransomware attack, the hospital issued statements apologising and saying hackers may have stolen data while encrypting its systems. Millions of patient records were reportedly offered for sale; the ministry said the source still needed checking.
A health institution left large volumes of patient records in a closed building that intruders kept entering, scattering files inside. It did not remove them or tell patients for over nine months. The regulator fined it two million forints.
A person complained that staff at a family practice they did not use had opened their record and prescriptions. The practice blamed a mistyped personal code. The regulator found the lookup unrelated to care and issued a reprimand.
A former patient noticed a rehabilitation provider's app talked to its servers unencrypted, and that patient files, including medical reports, could be opened without authentication. The provider said the gap was closed and it saw no sign of data outflow.
A clinic sent a patient's identity number, contact details and test results to another patient by unsecured email, and sent that patient's data back the other way. It told neither patient nor the regulator, which fined it.
A clinic announced that ransomware hit its servers, possibly exposing about 300,000 patient and staff records, including contact details, medical history and checkup results. It paused new outpatient bookings and said it had consulted police.
A patient found that other people's test results on a large private laboratory's website could be opened by changing digits in a link. The data protection regulator found the laboratory failed to secure them and opened an administrative case.
A ransomware attack hit a private hospital's administrative systems. The clinical record system was not affected, but personal identity numbers, in some cases linked to diagnosis codes, were stolen and put up for sale. The hospital refused to pay.
A primary care doctor used her own login to open a person's clinical record three times, though the person was not her patient. A provincial court gave her a suspended prison term, six years' disqualification and 50,000 euros in damages.
A patient's clinical images were reportedly leaked by a hospital nurse and shared online with identity details. The Health Ministry said it was investigating; whether anyone faced action was not disclosed.
The government said attackers targeted the state health insurer seeking patients' personal and treatment data. The health minister said the attack was repelled, and the insurer stated policyholders' data were safe and had not leaked.
A ransomware attack on a claims-processing company exposed names, ID numbers, insurance details and medical information such as test results and medications. Its parent company raised the count to about 190 million people. Attackers used a stolen credential.
After a cyberattack on a nationwide chain of GP practices, hackers posted patient information including illness history, hospital referrals and medication. The chain had confirmed personal data on an unknown number of patients was compromised.
A TV programme received a bag of patients' results, operation lists and doctors' notes said to have been thrown out by a hospital. The hospital disputed where the bag came from; the data protection authority opened an inspection.
A report citing a dark web forum post said patient files from four hospitals, from 2010 to 2021, leaked with names, birth dates, passport numbers and plain-text passwords that reportedly still opened lab results.
A hospital nursing technician opened another person's record 18 times, though she was not caring for her, over a personal dispute. A labour court in Rio Grande do Sul upheld her dismissal for cause.
An attacker locked a hospital's servers and exported about 5 gigabytes of data. The regulator found security failings, including weak protection of access to the electronic patient record, and fined the hospital 390,000 euros. An appeal court later reduced it.
After a national telecom data leak, the health ministry confirmed attackers breached an internet-facing pharmaceutical dashboard. It said only counts of patients using services were exposed, not personal details, and took the system offline.
A patient received someone else's medical records, including name, birth date, national ID number and health data. The hospital did not report the breach or tell the affected person in time. The regulator fined it 29,648 zloty.
Over several years a physician assistant used work logins to the national health system and two hospital systems to view three people's health data for personal reasons. The regulator found no care purpose and fined him 500 euros.
The regulator investigated on its own initiative and found no role-based checks on who received sensitive data, which led to several breaches, plus no process for access or correction requests. An enforcement notice followed.
A public search page on an appointment booking platform reportedly showed patients' names, national ID numbers, phone numbers and appointment history. It came down only after a public post, and users were not told.
Ransomware encrypted all of a regional public hospital's data, stopping imaging and blood testing until services returned within 72 hours. The report says some patient data was deleted. The hospital confirmed the attack.
A hacker posted a database of about 758,000 people taken from hospital management software, including contact details, treating doctor, prescriptions and death declarations. The software maker said a privileged account at a client hospital was misused.
Hackers demanded $50,000 for data said to include patients' names, ID numbers, phone numbers and medical histories. The hospital publicly apologised for the risk of leaked data. One patient said they reported it to police; the promised call never came.
Health workers reportedly filmed a patient during treatment and the video circulated on social media. A provincial governor told staff they must keep professional secrecy and asked managers to identify who made it.
Records of more than 30 million customers, including ID images and claim documents, were offered through chatbots and later a website. The insurer acknowledged unauthorized and illegal access to certain data and obtained a court injunction.
A former patient complained that a staff member had viewed her health record while she was not in care there. The clinic confirmed repeated unauthorised access and misuse of login details, and notified police and the data protection authority.
A company that runs employer-requested sick-leave checks said hackers had taken 53,900 files, including names, addresses, incapacity levels and examining doctors' comments, and published them a week later. It warned of phishing using the data.