Geography
North Dakota: 19 healthcare breach filings.
North Dakota entities have reported 19 breaches of 500 or more individuals to HHS since 2011, the 49th most of the 52 states and territories on the register, covering 792,366 individuals (46th by people affected). 0 are still under investigation. Hacking/IT Incident is the breach type on 68% of them, and network server the most common location (42%).
Filings
19
49th of 52 states and territories
Individuals affected
792,366
Median filing 6,457
Largest filing
510,574
Adaptive Health Integrations, 2022
Hacking / IT share
68%
4 filings involve a business associate
Direct answer / North Dakota on the HHS portal
The largest North Dakota filing is Adaptive Health Integrations (510,574 individuals, submitted 11 April 2022). The busiest year was 2023 with 4 filings. Healthcare Providers account for 79% of the state's filings. 8 filings of 10,000 or more individuals have their own page; the remaining 11 are listed in the table at the foot of this page.
Section ND.1 / Largest filings
Ten largest North Dakota breaches
| # | Covered entity | Type | Individuals | Submitted | Breach type | Location | BA |
|---|---|---|---|---|---|---|---|
| 1 | Adaptive Health Integrations | Healthcare Provider | 510,574 | 11 Apr 2022 | |||
| 2 | Dakota Eye Institute | Healthcare Provider | 107,143 | 23 Oct 2023 | |||
| 3 | DMS Health Technologies, Inc. | Healthcare Provider | 48,336 | 21 Jun 2023 | |||
| 4 | State of North Dakota | Healthcare Provider | 35,416 | 27 Oct 2020 | |||
| 5 | Pembina County Memorial Hospital | Healthcare Provider | 23,811 | 25 Mar 2024 | |||
| 6 | Southwest Healthcare Services | Healthcare Provider | 15,996 | 1 Apr 2023 | |||
| 7 | Brady Martz & Associates PC | Business Associate | 13,655 | 17 Jan 2024 | |||
| 8 | Elbowoods Memorial Health Center | Health Plan | 10,000 | 21 Aug 2013 | |||
| 9 | McKenzie County Healthcare System, Inc. | Healthcare Provider | 8,345 | 16 Feb 2024 | |||
| 10 | Family Healthcare Center | Healthcare Provider | 6,457 | 11 Jan 2024 |
Section ND.2 / By year
North Dakota filings by submission year
Each year links to the national year page.
Section ND.3 / Composition
Breach type, location and who filed
Multi-valued fields count once per value.
Type of breach
Location of breached information
Covered entity type
Section ND.4 / Notification law
What North Dakota law required alongside HIPAA
State notification statute
North Dakota: N.D. Cent. Code Ch. 51-30
- Notice to individuals
- In the most expedient time possible and without unreasonable delay
- Attorney general threshold
- 250 or more North Dakota residents (Same timeline as individual notification)
- Private right of action
- No: Only the North Dakota Attorney General may enforce
- Penalty
- Up to $5,000 per violation under the consumer fraud statute, plus fees and costs
The HIPAA Breach Notification Rule runs alongside the state statute: notice to affected individuals and to HHS without unreasonable delay and no later than 60 days after discovery.
Section ND.5 / Filing pages
8 filings of 10,000 or more individuals
Each links to a page with the full filing, its rank in the state and year, OCR's closing summary where the case is archived, peers, and the modelled cost.
| Covered entity | Type | Individuals | Submitted | Breach type | Location | BA |
|---|---|---|---|---|---|---|
| Adaptive Health Integrations | Healthcare Provider | 510,574 | 11 Apr 2022 | |||
| Dakota Eye Institute | Healthcare Provider | 107,143 | 23 Oct 2023 | |||
| DMS Health Technologies, Inc. | Healthcare Provider | 48,336 | 21 Jun 2023 | |||
| State of North Dakota | Healthcare Provider | 35,416 | 27 Oct 2020 | |||
| Pembina County Memorial Hospital | Healthcare Provider | 23,811 | 25 Mar 2024 | |||
| Southwest Healthcare Services | Healthcare Provider | 15,996 | 1 Apr 2023 | |||
| Brady Martz & Associates PC | Business Associate | 13,655 | 17 Jan 2024 | |||
| Elbowoods Memorial Health Center | Health Plan | 10,000 | 21 Aug 2013 |
Section ND.6 / All other filings
11 filings below 10,000 individuals
Listed in full from the HHS export, largest first. These filings do not have their own page.
| Covered entity | Type | Individuals | Submitted | Breach type | Location | BA |
|---|---|---|---|---|---|---|
| McKenzie County Healthcare System, Inc. | Healthcare Provider | 8,345 | 16 Feb 2024 | |||
| Family Healthcare Center | Healthcare Provider | 6,457 | 11 Jan 2024 | |||
| North Dakota Department of Human Services | Health Plan | 2,452 | 1 Jun 2017 | |||
| Kemmet Dental Design | Healthcare Provider | 2,000 | 12 Nov 2013 | |||
| Catholic Charities of North Dakota | Healthcare Provider | 1,901 | 23 Apr 2021 | |||
| CoreLink Administrative Solutions, LLC | Business Associate | 1,813 | 6 Aug 2018 | |||
| Jacobson Memorial Hospital Care Center | Healthcare Provider | 1,545 | 23 Feb 2021 | |||
| Langdon Prairie Health | Healthcare Provider | 1,152 | 18 Apr 2025 | |||
| Medcenter One | Healthcare Provider | 650 | 17 Nov 2011 | |||
| St. Luke's Medical Center | Healthcare Provider | 600 | 16 Jan 2017 | |||
| 360 Physical Therapy, LLC | Healthcare Provider | 520 | 21 Dec 2023 |
Index / Other states
Every state on the register
98
32
164
92
776
139
144
31
33
463
226
22
29
358
200
98
80
124
66
37
170
241
238
189
55
164
36
60
55
38
174
57
511
207
276
80
120
339
32
41
86
15
196
633
68
15
157
185
47
126
19
Index / Companion schedules
13 HHS breach register
→Hub: every filing, by state, year and entity.
04 Biggest breaches
→Mega-breaches with primary-source cost figures.
Industry / Healthcare
→IBM 2026: $6.64M average, 13 years at #1.
Regulation / HIPAA penalties
→OCR enforcement tiers and the 60-day rule.
11 50-state laws
→Deadline, AG threshold and penalties per state.
Cost / Per record
→Where the per-record model is reliable.
Provenance
Source: U.S. Department of Health and Human Services, Office for Civil Rights, Breach Portal (breaches affecting 500 or more individuals), retrieved 2026-08-28. Public domain. Individuals affected and dates as reported by the covered entity.
Portal: ocrportal.hhs.gov breach report. Statutory basis: HITECH Act section 13402(e)(4): the Secretary must post a list of breaches of unsecured protected health information affecting 500 or more individuals. Breaches affecting fewer than 500 individuals are reported to OCR annually and are not posted, so they are not on this register. Status wording follows the portal's two tabs ("Cases Currently Under Investigation" and "Archive") as of 28 August 2026; a filing moves to the archive when OCR closes the case. Modelled costs on this site are a method applied to the reported count, using IBM Cost of a Data Breach per-record figures, and are never a cost disclosed by the entity.
Corrections: if you represent a listed entity and the portal row has been amended, email [email protected] with the portal entry and we will re-pull the export.