Geography
Delaware: 31 healthcare breach filings.
Delaware entities have reported 31 breaches of 500 or more individuals to HHS since 2014, the 46th most of the 52 states and territories on the register, covering 5,339,813 individuals (31st by people affected). 1 are still under investigation. Hacking/IT Incident is the breach type on 71% of them, and network server the most common location (61%).
Filings
31
46th of 52 states and territories
Individuals affected
5,339,813
Median filing 14,095
Largest filing
3,179,835
Cerebral, Inc, 2023
Hacking / IT share
71%
12 filings involve a business associate
Direct answer / Delaware on the HHS portal
The largest Delaware filing is Cerebral, Inc (3,179,835 individuals, submitted 1 March 2023). The busiest year was 2020 with 8 filings. Healthcare Providers account for 81% of the state's filings. 17 filings of 10,000 or more individuals have their own page; the remaining 14 are listed in the table at the foot of this page.
Section DE.1 / Largest filings
Ten largest Delaware breaches
| # | Covered entity | Type | Individuals | Submitted | Breach type | Location | BA |
|---|---|---|---|---|---|---|---|
| 1 | Cerebral, Inc | Business Associate | 3,179,835 | 1 Mar 2023 | |||
| 2 | ConnectOnCall.com, LLC | Business Associate | 914,138 | 11 Dec 2024 | |||
| 3 | Bayhealth Medical Center | Healthcare Provider | 497,047 | 4 Oct 2024 | |||
| 4 | Simon Eye Management | Healthcare Provider | 144,780 | 14 Sep 2021 | |||
| 5 | Brandywine Urology Consultants, PA | Healthcare Provider | 131,825 | 27 Mar 2020 | |||
| 6 | Bayhealth Medical Center, Inc. | Healthcare Provider | 78,006 | 20 Nov 2020 | |||
| 7 | Mid-Delaware Imaging | Healthcare Provider | 77,110 | 30 Mar 2020 | |||
| 8 | Beebe Medical Foundation | Healthcare Provider | 56,953 | 28 Dec 2020 | |||
| 9 | Delaware Guidance Services for Children and Youth, Inc. | Healthcare Provider | 50,000 | 22 Feb 2019 | |||
| 10 | La Red Health Center | Healthcare Provider | 39,759 | 20 Oct 2023 |
Section DE.2 / By year
Delaware filings by submission year
Each year links to the national year page.
Section DE.3 / Composition
Breach type, location and who filed
Multi-valued fields count once per value.
Type of breach
Location of breached information
Covered entity type
Section DE.4 / Notification law
What Delaware law required alongside HIPAA
State notification statute
Delaware: Del. Code tit. 6, Ch. 12B
- Notice to individuals
- Without unreasonable delay, no later than 60 days after determining a breach occurred
- Attorney general threshold
- 500 or more Delaware residents (No later than when individual notices are sent)
- Private right of action
- No: Statute preserves existing common-law and other statutory rights
- Penalty
- Enforced by the AG Consumer Protection Division; may recover direct economic damages
The HIPAA Breach Notification Rule runs alongside the state statute: notice to affected individuals and to HHS without unreasonable delay and no later than 60 days after discovery.
Section DE.5 / Filing pages
17 filings of 10,000 or more individuals
Each links to a page with the full filing, its rank in the state and year, OCR's closing summary where the case is archived, peers, and the modelled cost.
Section DE.6 / All other filings
14 filings below 10,000 individuals
Listed in full from the HHS export, largest first. These filings do not have their own page.
| Covered entity | Type | Individuals | Submitted | Breach type | Location | BA |
|---|---|---|---|---|---|---|
| Delaware Department of Health and Social Services, Division of Public Health | Healthcare Provider | 9,930 | 12 Nov 2020 | |||
| Medical Oncology Hematology Consultants, PA | Healthcare Provider | 8,591 | 26 Apr 2019 | |||
| Delaware Department of Health and Social Services, Division of Developmental Disabilities Services | Healthcare Provider | 7,000 | 20 Oct 2022 | |||
| Brandywine Counseling & Community Services, Inc | Healthcare Provider | 4,139 | 17 Jul 2020 | |||
| Henrietta Johnson Medical Center | Healthcare Provider | 4,001 | 27 Jun 2023 | |||
| AmeriHealth Caritas Delaware | Health Plan | 2,823 | 1 Jul 2024 | |||
| Beebe Medical Center | Healthcare Provider | 1,883 | 31 Jan 2014 | |||
| Ambucor Health Solutions, an unincorporated division of The ScottCare Corporation | Business Associate | 1,679 | 22 Jul 2016 | |||
| Christiana Care Health Services, Inc. | Healthcare Provider | 1,229 | 14 Sep 2020 | |||
| Premier Physical Therapy and Sports Performance, Limited Partnership | Healthcare Provider | 982 | 12 Oct 2022 | |||
| Instabase, Inc. | Health Plan | 908 | 13 Apr 2026 | |||
| Bayhealth Medical Center, Inc. | Healthcare Provider | 565 | 18 May 2021 | |||
| Center for Child Development, INC | Healthcare Provider | 540 | 2 Jan 2025 | |||
| Highmark Delaware | Business Associate | 508 | 14 May 2018 |
Index / Other states
Every state on the register
98
32
164
92
776
139
144
33
463
226
22
29
358
200
98
80
124
66
37
170
241
238
189
55
164
36
60
55
38
174
57
511
207
19
276
80
120
339
32
41
86
15
196
633
68
15
157
185
47
126
19
Index / Companion schedules
13 HHS breach register
→Hub: every filing, by state, year and entity.
04 Biggest breaches
→Mega-breaches with primary-source cost figures.
Industry / Healthcare
→IBM 2026: $6.64M average, 13 years at #1.
Regulation / HIPAA penalties
→OCR enforcement tiers and the 60-day rule.
11 50-state laws
→Deadline, AG threshold and penalties per state.
Cost / Per record
→Where the per-record model is reliable.
Provenance
Source: U.S. Department of Health and Human Services, Office for Civil Rights, Breach Portal (breaches affecting 500 or more individuals), retrieved 2026-08-28. Public domain. Individuals affected and dates as reported by the covered entity.
Portal: ocrportal.hhs.gov breach report. Statutory basis: HITECH Act section 13402(e)(4): the Secretary must post a list of breaches of unsecured protected health information affecting 500 or more individuals. Breaches affecting fewer than 500 individuals are reported to OCR annually and are not posted, so they are not on this register. Status wording follows the portal's two tabs ("Cases Currently Under Investigation" and "Archive") as of 28 August 2026; a filing moves to the archive when OCR closes the case. Modelled costs on this site are a method applied to the reported count, using IBM Cost of a Data Breach per-record figures, and are never a cost disclosed by the entity.
Corrections: if you represent a listed entity and the portal row has been amended, email [email protected] with the portal entry and we will re-pull the export.