clinicians.build · interactive

The Breach Beat Is Background Noise

Two more health-data breach disclosures landed in a single Reuters factbox this week — Clover Health and Abbott — and barely made a ripple. That numbness has a shape. Here is every large breach reported to HHS since the "wall of shame" opened in 2009 — 6,501 reports, 625 million individuals — replayed as one accelerating drumbeat. Press replay and listen to it speed up. Then see what the official archive still doesn't contain.

Built on ↓ Reuters — US companies face rise in cyber attacks (Jul 17, 2026) · companion to today's ultra-shorts
Data: HHS OCR breach portal, reports of 500+ individuals · mimi_ws_1.hhsocr.breaches_confirmed + breaches_under_investigation via MIMI Labs

From one report every two days to one every twelve hours

Federal law makes every breach of 500+ people's health records a public record. In 2010, the portal's first full year, that meant a new entry every ~44 hours. By 2023 it was one every ~12 hours — 728 reports in a single year, 97% of the affected individuals via hacking. Somewhere in early 2022, the running total of reported records passed the population of the United States.

6,501
breach reports in the archive, Oct 2009 – Sep 2025
625.3M
individuals affected — ~1.8× the US population
12 hrs
average gap between reports, 2023
192.7M
biggest breach ever — still not in the archive

Every month of reports since the portal opened

Each bar is a month; red is hacking/IT incidents, navy is everything else — theft, loss, misdirected records, improper disposal. The old noise was lost laptops. The new noise is network intrusion. Hover any month for detail, including how many of its breaches topped a million people.

OCT 2009
0
breach reports so far
0
individuals affected (cumulative, by year)
avg hours between reports (year shown)
hacking share of reports (year shown)
hacking / IT incidentall other causesreported, still "under investigation" (not yet in archive)
Why the recent bars look calmer than reality: the archive's 2024–25 dip isn't safety — it's paperwork. Reports migrate from "under investigation" to the confirmed archive slowly, and the single largest health-data breach in US history (Change Healthcare, 192.7M people — more than half the country) has been parked in the pending list for two years. Toggle it on above and watch 2024 change shape.

What the wall of shame can't see

Dates are paperwork, not incidents. The x-axis is when entities reported to OCR — up to 60 days after discovery, which is itself often months after intrusion. The drumbeat you hear is the reporting pipeline, phase-shifted from the actual attacks.
The floor cuts off the base of the iceberg. Only breaches of 500+ individuals appear here. Sub-500 breaches are reported annually, in bulk, and never make this portal — so the true frequency line sits above every bar you see.
"Individuals affected" is the breached entity's own estimate, filed at submission time and revised later — sometimes by orders of magnitude (Change Healthcare's initial filing said 500). And the same person breached five times counts five times: 625M records ≠ 625M people.
A system that publishes its failures every 12 hours has, by definition, normalized them. For builders the signal is brutal and useful: assume the data your tool touches will be in one of these bars eventually — and design the blast radius, not just the feature. This week's Clover and Abbott disclosures aren't news. They're the metronome.
Read the source: Reuters cyber-attack factbox → Or read today's newsletter →
clinicians.dev · an experiment by clinicians.build
Data: HHS Office for Civil Rights breach portal, 500+ affected threshold. Tables: mimi_ws_1.hhsocr.breaches_confirmed (6,501 reports / 625,298,080 individuals through 2025-09-19) and breaches_under_investigation (744 open reports across 2023–25); extract mimi_src_file_date=2025-12-10; MimiLabs query 6a5f19de52c62e70720f131c, run 2026-07-21. Pending counts are a current open-investigation snapshot, not a historical incidence series; the cumulative-individuals counter steps by calendar year.
⚠︎ AI-generated · not reviewed by a human · verify against the linked sources before relying on it