Lexology March 12, 2025
In terms of healthcare data breaches, 2024 was the worst year ever, with the records of at least 53% of the U.S. population involved and two of the biggest healthcare data breaches of 2024 ranking in the top 10 of all time. In 2024 alone, there were 13 data breaches involving more than 1 million healthcare records—including the largest-ever healthcare data breach that affected an estimated 100 million individuals.
To combat this increase in cyberattacks and threats, in late 2024, the Department of Health and Human Services (HHS) issued a Notice of Proposed Rulemaking (NPRM) to modify the Security Rule under the Health Insurance Portability and Accountability Act of 1996 as amended by the Health Information Technology for Economic and...







