Department of Health and Human Services: data breaches in 2021 exposed the health information of 40M+ people in the US, up from 26M in 2020
Nicole Wetsman / The Verge : Tweets: @gregafish and @adam_k_levin Tweets: Greg Fish / @gregafish : Hospitals' lackadaisical attitude towards cybersecurity is costing people lives and money. And the hacks are increasing, with over 40 million Americans affected. https://www.theverge.com/... Adam Levin / @adam_k_levin : For hackers, your health information is the gift that will keep on giving. https://www.theverge.com/...
Context & Ripple Effects
The HHS tally is the official confirmation of a curve that was already visible: a report earlier in 2019 counted more than 32 million patient records stolen in just six months, double all of 2018, and the 40M+ figure for 2021 — up from 26 million in 2020 — shows the trajectory held. Commentators cited in the piece frame the stakes bluntly: Greg Fish argues hospitals' lax cybersecurity is costing lives and money, and Adam Levin notes stolen health data is 'the gift that keeps on giving' for fraudsters because it cannot be reissued like a credit card.
The pattern did not plateau after this report: [[a:878005|UnitedHealth later disclosed over 100 million people had data stolen in the Change Healthcare ransomware attack]], and hospital systems like Ascension and NYC Health + Hospitals have since disclosed multi-million-person breaches of their own — making the 2021 numbers an early marker of a structural problem rather than a bad year.
First-order effects
- Over 40 million Americans whose health information was exposed in 2021 face long-tail identity-theft and insurance-fraud risk, since medical records — unlike payment cards — cannot simply be canceled and replaced.
- Hospital operators named in the breach data absorb direct remediation costs and operational disruption, with the article's cited commentators arguing the sector's underinvestment in security is now visibly costing both money and patient safety.
Second-order effects
- Healthcare's breach economics — high-value, non-reissuable records at under-secured institutions — make the sector a preferred ransomware target, a bet later borne out by the Change Healthcare attack that stole records of a substantial proportion of the US population and forced clearinghouse-level contingency planning across the industry.
- Payers, clearinghouses and health-management vendors such as HealthEC, whose 2023 breach hit roughly 4.5 million patients, come under pressure from hospital customers to prove security posture, shifting procurement toward vendors who can demonstrate it.
Third-order effects
- If the escalation from 26 million to 40 million-plus exposed records continues — and the subsequent 100-million-record Change Healthcare breach suggests it did — health data protection moves from an IT line item to a regulatory and board-level concern for HHS and hospital systems, with breach disclosure becoming a recurring operational cost of US healthcare.
- The concentration of patient data in clearinghouses and health systems turns single breaches into population-scale events, pushing the industry toward treating medical-record infrastructure as critical infrastructure rather than ordinary enterprise IT.
The trend: US healthcare data breaches are compounding year over year, converting patient-record security from a hospital IT problem into a system-wide infrastructure and regulatory issue.