 |
Patient Protect |
|
HIPAA Pulse |
|
|
Special Edition
Q2 ROLLUP
July 8, 2026 · The Quarter in Breaches
|
|
One Pattern, Four Names & the Verified Brief, Available Now
|
Impact concentrates upstream. Frequency shows up downstream. Q2 made both halves of that pattern harder to ignore.
Six months ago, we published a simple finding: healthcare breach risk does not spread evenly. The largest impact tends to concentrate upstream, at the vendors, administrators, and platforms that hold data for many providers at once. Q2 sharpened that finding rather than erasing it. This is a special edition: instead of the last two weeks, it covers the last three months, and every fact here was reported and fact-checked in a HIPAA Pulse issue as it happened.
The largest verified disclosure of the quarter came from Xsolis, an AI utilization-management vendor holding data across hundreds of healthcare clients. But the rest of the verified record looked very different: dermatology, radiology, orthopedics, oncology, neurology, ophthalmology — the long tail of independent care. That is the real Q2 story. Impact concentrates upstream. Frequency shows up downstream. Independent practices sit in the middle, responsible for both their own systems and the vendors they trust. The preliminary version of the Q2 Verified Breach Brief is available now, with the full report following shortly. Rather than publish a shaky quarter total, it reports the ten disclosures we could independently verify, a minimum affected floor of 2,698,826 people, and the methodology behind what we excluded.
|
|
The Verified Floor, Not a Quarter Total
2,698,826
affected individuals, at minimum, across ten independently verified Q2 disclosures. Q1's baseline number — 67.6% of affected patients from four upstream incidents — was the pattern this quarter tested. Q2's verified record supported the upstream half and showed the other half just as clearly: most of the verified disclosures, by count, happened at small, independent practices, not at large platforms.
|
|
The Quarter, in Four Movements
|
Q1
|
The Baseline: Concentration
Q1 showed that breach impact was not evenly distributed. Four upstream incidents drove 67.6% of affected individuals across the quarter. The lesson was simple: risk clusters where data aggregates.
|
|
RAR
|
The Repeat-Victim Warning
Radiology Associates of Richmond disclosed a second breach affecting 266,183 people within roughly fifteen months of its first. This is a governance story more than a vendor-concentration one: after one breach, how do you prove the underlying access problem was actually fixed?
|
|
DENT
|
The Administrator Layer
DentaQuest was not part of the verified-ten floor in the Q2 brief, but it was one of the quarter's important Pulse stories. An extortion group claimed to publish a large dataset tied to a dental benefits administrator, showing how downstream patients and providers can be exposed through entities they may never directly interact with.
|
|
XSOL
|
The AI Vendor
Xsolis, an AI utilization-management vendor, reported a breach affecting 1,396,519 people. One affected health system had ended its relationship with Xsolis in 2021, yet its patients' data was still present in the environment. That is the Q2 story in one sentence: aggregation plus retention becomes exposure.
|
|
|
The Constant Underneath
Across every issue this quarter, hacking-driven incidents stayed dominant — between roughly 70% and 86% of the breaches in each window's tracked data. Whatever the headline entity, the entry method rarely changed.
| May 13 |
|
| May 27 |
|
| June 10 |
|
| June 24 |
|
Hacking / IT Incident share of breach filings, per issue. Patient Protect dashboard, OCR + State AG entries. The Q2 Verified Breach Brief explains why a single quarter total isn't published below.
|
|
|
Three Things Q2 Made Clear
The Breach That Reaches Your Patients May Not Start With You
For independent practices, the breach that affects your patients may begin somewhere else — with a vendor, administrator, clearinghouse, analytics platform, or AI tool. That is precisely why a vendor inventory is one of the most important security documents an independent practice can keep.
Time Is Its Own Exposure
Two of the quarter's stories were really about time. Radiology Associates of Richmond shows how long disclosure and remediation timelines can stretch. Xsolis shows how old data can remain exposed years after a vendor relationship ends. Slow disclosure and long retention widen the same window — the window an attacker eventually finds.
The Rule Meant to Address This Is Still Waiting
The proposed HIPAA Security Rule update is still unresolved. Its May finalization target passed without a final rule, and more than 100 provider groups have pushed for withdrawal. But the direction is still clear: OCR is already enforcing the current rule, and risk analysis remains the recurring failure point. Waiting for the final rule is not a compliance strategy.
|
| |
|
Preliminary Version Available · Secure Care Research Institute
The Q2 2026 Verified Breach Brief
Ten disclosures individually verified against HHS OCR and independent reporting — a floor of at least 2,698,826 affected individuals, not a rounded quarter estimate. The lead finding: Xsolis, an AI utilization-management vendor, alone accounts for over half that floor. A second finding: Radiology Associates of Richmond's second breach in roughly fifteen months. Full methodology, source reconciliation, and recommendations for covered entities and business associates included.
This preliminary version is live now. The full report follows shortly.
|
|
|
The Half-Year System Check
One consolidated checklist drawn from the whole quarter. If you do nothing else before Q3, do these five.
1 |
Build a real vendor inventory. Every vendor, administrator, clearinghouse, and analytics platform that touches your patients' data — with a current BAA for each. This was the through-line across the quarter's major Pulse stories. If you have one artifact by Q3, make it this. |
|
2 |
Add a data-disposition step to vendor offboarding. When a relationship ends, get written confirmation the vendor purged or returned your data. Xsolis is what happens without it. |
|
3 |
Tighten your breach-discovery clock. Name one person responsible for date-stamping any potential breach the day it surfaces. RAR is what a slow, ambiguous discovery timeline eventually costs. |
|
4 |
Put MFA on every inbox. Phishing was the entry point in the quarter's biggest breach and remains the most common one in healthcare. MFA on email is the highest-leverage control you can finish this week. |
|
5 |
Get your risk analysis current. A missing or stale risk analysis is OCR's single most-cited finding — the gap behind this quarter's enforcement settlements. It's also the foundation every Security Rule change builds on. Do it before the rule forces the timeline. |
|
|
All Five in One Pass.
The free HIPAA Risk Assessment covers vendor inventory, BAA completeness, data flows, and your risk analysis in one sitting. 30 minutes, no account, produces the kind of documented artifact OCR would expect to see.
|
|
|
Into Q3
Two things will define next quarter's coverage. Whether OCR publishes a final Security Rule or lets the proposal lapse — either outcome reshapes the compliance calendar for every independent practice. And whether the upstream concentration pattern holds a fourth quarter running. Based on the last six months, independent practices should plan as if the next headline breach may come from a vendor most patients never knew was holding their data.
Regular biweekly coverage resumes with the next issue. The preliminary Q2 Verified Breach Brief is linked above, with the full report following shortly — if the ten-disclosure floor and the AI-vendor finding are new to you, that's the place to start.
Next Pulse drops July 22.
Editorial coverage at hipaapulse.com. Operational response at patient-protect.com/hipaa-pulse. This briefing comes from Patient Protect.
|
 |
Patient Protect |
Chicago, IL · patient-protect.com · HIPAA Pulse
|
Instagram
LinkedIn
X
|
|
This rollup summarizes breaches reported and fact-checked in HIPAA Pulse issues across Q2 2026. Figures reflect the sources cited in each original issue: HHS OCR and State AG filings, entity notices, and SecurityWeek reporting. The Q2 Verified Breach Brief documents the full verification methodology, including why a single quarter-level total was not published.
You're receiving HIPAA Pulse because you subscribed at patient-protect.com. Unsubscribe · Privacy Policy
© 2026 Patient Protect LLC. All rights reserved.
|
|
|