Revenue Cycle Insider

Technology & Innovation:

Another Day, Another Cybersecurity Breach in Healthcare

Question: The ransomware attack on Change Healthcare in 2024 shook the healthcare industry, and made a lot of organizations reassess their cybersecurity and incident response plans. Have data breaches calmed down since last year’s major outage?

Washington Subscriber

Answer: Sadly, no. While the number of healthcare data breaches affecting 500 or more individuals declined from 2023 (747 incidents) to 2024 (734 incidents), the number of affected individuals has skyrocketed since 2022. According to the U.S. Department of Health and Human Services (HHS) Office for Civil Rights (OCR) breach portal, more than 48.7 million individuals were affected in 2023 and 2024 saw over 259 million affected individuals. Of course, last year’s total includes the Change Healthcare breach.

So far, 2025 does not appear to be slowing down, with 218 data breaches affecting 500 or more individuals, as of publication. One of the bigger breaches of the year involves the Yale New Haven Health System (YNHHS).

On March 8, 2025, YNHHS “identified unusual activity affecting [its] Information Technology (IT) systems,” the health system wrote in a Notice of Data Security Incident. Since detecting the unauthorized access, YNHHS has been working with external cybersecurity experts, and it reported the breach to law enforcement.

According to the OCR breach portal, more than 5.55 million individuals were affected by the breach.

As stated by YNHHS, a third party accessed the health system’s network and collected copies of select data. The illegally gathered information may include:

  • Names
  • Dates of birth
  • Addresses
  • Email addresses
  • Races/ethnicities
  • Telephone numbers
  • Social Security numbers
  • Patient types
  • Medical record numbers

YNHHS also mentioned that the stolen data did not include financial accounts, payment information, electronic medical record information, or treatment information.

The health system began mailing letters to affected individuals on April 14, 2025, and stated in the incident notice “we are offering complimentary credit monitoring and identity protection services to individuals whose Social Security number was involved. Patients are also encouraged to review statements they receive from their healthcare providers and immediately report any inaccuracies to the provider.”

Mike Shaughnessy, BA, CPC, Development Editor, AAPC

Other Articles of

May 2025

View All
Subscribe to newsletter