Recent HIPAA breaches

Recent HIPAA breaches in healthcare. Updated daily from the HHS OCR Wall of Shame. Run the same scan we use → toughlovesec.win/free-scan

Run a free pre-scan → 📅 Talk to founder (20min)
EntityStateRecordsBreach typeDate postedCommentary
Issaqueena Pediatric Dentistry PA SC 501 Hacking/IT Incident 02/04/2026 Hacking/IT incident affecting 501 records — typical OCR follow-up window is 60 days.
Wee Care Pediatrics, LLC UT 2,127 Hacking/IT Incident 02/14/2026 Hacking/IT incident affecting 2,127 records — typical OCR follow-up window is 60 days.
VNS Behavioral Health Inc. (“VNS Health”) NY 739 Hacking/IT Incident 02/18/2026 Hacking/IT incident affecting 739 records — typical OCR follow-up window is 60 days.
Kin Counseling Services PLLC CO 500 Hacking/IT Incident 03/02/2026 Hacking/IT incident affecting 500 records — typical OCR follow-up window is 60 days.
Tieu Dental Corporation CA 8,918 Hacking/IT Incident 03/05/2026 Hacking/IT incident affecting 8,918 records — typical OCR follow-up window is 60 days.
Renovo Chiropractic & Wellness WA 538 Theft 03/16/2026 Theft of device/media — encryption (§164.312(a)(2)(iv)) is the first thing OCR will ask about.
Coastal Skin Surgery & Dermatology FL 6,173 Hacking/IT Incident 03/17/2026 Hacking/IT incident affecting 6,173 records — typical OCR follow-up window is 60 days.
Virginia Department of Behavioral Health and Developmental Services VA 724 Unauthorized Access/Disclosure 04/07/2026 Unauthorized access — workforce training (§164.308(a)(5)) and access logs (§164.312(b)) usually flagged.

What this is

This dashboard pulls every breach posted to the U.S. Department of Health and Human Services Office for Civil Rights "Wall of Shame" that affects 500+ patients. We filter to small healthcare practices — dental, therapy, behavioral health, family medicine, pediatric, OB-GYN, chiropractic, podiatry, optometry, dermatology — because that's where the §164 audit gap is widest.

If a practice from your network shows up here, the OCR follow-up letter is typically delivered within 60 days. A free pre-scan tells you exactly what they'll ask about.

Refund
Any unused credits refunded on request — email lemorris@toughlovesec.win.
Privacy
We never store your bank password. Plaid handles auth. Access tokens encrypted at rest. Stripe handles cards — we never see card numbers.
Built by
@atmpushout, solo, on Android. ~$1.61 starting capital. Real product, real founder. lemorris@toughlovesec.win
Contact
Email · GitHub · Twitter
© TOUGH LOVE SECURITY · toughlovesec.win · Atlanta, GA
LIVE
— requests served today
— agents connected