Two more health-data breach disclosures landed in a single Reuters factbox this week — Clover Health and Abbott — and barely made a ripple. That numbness has a shape. Here is every large breach reported to HHS since the "wall of shame" opened in 2009 — 6,501 reports, 625 million individuals — replayed as one accelerating drumbeat. Press replay and listen to it speed up. Then see what the official archive still doesn't contain.
From one report every two days to one every twelve hours
Federal law makes every breach of 500+ people's health records a public record. In 2010, the portal's first full year, that meant a new entry every ~44 hours. By 2023 it was one every ~12 hours — 728 reports in a single year, 97% of the affected individuals via hacking. Somewhere in early 2022, the running total of reported records passed the population of the United States.
6,501
breach reports in the archive, Oct 2009 – Sep 2025
625.3M
individuals affected — ~1.8× the US population
12 hrs
average gap between reports, 2023
192.7M
biggest breach ever — still not in the archive
The drumbeat
Every month of reports since the portal opened
Each bar is a month; red is hacking/IT incidents, navy is everything else — theft, loss, misdirected records, improper disposal. The old noise was lost laptops. The new noise is network intrusion. Hover any month for detail, including how many of its breaches topped a million people.
OCT 2009
0
breach reports so far
0
individuals affected (cumulative, by year)
–
avg hours between reports (year shown)
–
hacking share of reports (year shown)
hacking / IT incidentall other causesreported, still "under investigation" (not yet in archive)
Dashed bars: 744 reports (2023–2025) that sit in OCR's "under investigation" list — including Change Healthcare, reported Jul 19, 2024: 192,700,000 individuals, Kaiser (13.4M) and Ascension (5.5M). Add them and "quiet" 2024 becomes the worst year in history by records exposed: ~289M.
Why the recent bars look calmer than reality: the archive's 2024–25 dip isn't safety — it's paperwork. Reports migrate from "under investigation" to the confirmed archive slowly, and the single largest health-data breach in US history (Change Healthcare, 192.7M people — more than half the country) has been parked in the pending list for two years. Toggle it on above and watch 2024 change shape.
Critical lens
What the wall of shame can't see
Dates are paperwork, not incidents. The x-axis is when entities reported to OCR — up to 60 days after discovery, which is itself often months after intrusion. The drumbeat you hear is the reporting pipeline, phase-shifted from the actual attacks.
The floor cuts off the base of the iceberg. Only breaches of 500+ individuals appear here. Sub-500 breaches are reported annually, in bulk, and never make this portal — so the true frequency line sits above every bar you see.
"Individuals affected" is the breached entity's own estimate, filed at submission time and revised later — sometimes by orders of magnitude (Change Healthcare's initial filing said 500). And the same person breached five times counts five times: 625M records ≠ 625M people.
A system that publishes its failures every 12 hours has, by definition, normalized them. For builders the signal is brutal and useful: assume the data your tool touches will be in one of these bars eventually — and design the blast radius, not just the feature. This week's Clover and Abbott disclosures aren't news. They're the metronome.
clinicians.dev · an experiment by clinicians.build
Data: HHS Office for Civil Rights breach portal (hhsocr.breaches_confirmed, 6,501 reports through 2025-09-19; breaches_under_investigation, 744 pending reports), queried 2026-07-20 via MIMI Labs. Cumulative-individuals counter steps by calendar year.
⚠︎ AI-generated · not reviewed by a human · verify against the linked sources before relying on it