Form: Cost-of-Breach DisclosureSource: IBM Cost of a Data BreachFiled: 28 Apr 2026
DataBreachCost.comOpen calc
Independent breach-cost research, read by security and risk leaders.Sponsor this site →
State File SD / HHS OCR Breach Register15 filings, 2013 to 2025

Geography

South Dakota: 15 healthcare breach filings.

South Dakota entities have reported 15 breaches of 500 or more individuals to HHS since 2013, the 51st most of the 52 states and territories on the register, covering 178,652 individuals (52nd by people affected). 1 are still under investigation. Hacking/IT Incident is the breach type on 53% of them, and network server the most common location (47%).

Filings

15

51st of 52 states and territories

Individuals affected

178,652

Median filing 1,632

Largest filing

106,763

Black Hills Regional Eye Institute, 2025

Hacking / IT share

53%

3 filings involve a business associate

Direct answer / South Dakota on the HHS portal

The largest South Dakota filing is Black Hills Regional Eye Institute (106,763 individuals, submitted 31 March 2025). The busiest year was 2015 with 3 filings. Healthcare Providers account for 80% of the state's filings. 4 filings of 10,000 or more individuals have their own page; the remaining 11 are listed in the table at the foot of this page.

Section SD.1 / Largest filings

Ten largest South Dakota breaches

#Covered entityTypeIndividualsSubmitted
1Black Hills Regional Eye InstituteHealthcare Provider106,76331 Mar 2025
2Huron Regional Medical Center, Inc.OpenHealthcare Provider25,3986 Jun 2025
3Siouxland Anesthesiology, Ltd.Healthcare Provider13,00031 Jul 2015
4Plastic Surgery Associates of South DakotaHealthcare Provider10,22927 Jul 2017
5Stronghold Counseling Services, Inc.Healthcare Provider8,50021 Feb 2013
6AAA Collections, Inc.Business Associate4,63515 Dec 2022
7Sage Medical Professionals LLCBusiness Associate2,13829 Dec 2021
8Indian Health Service, Aberdeen Area OfficeHealth Plan1,63213 Nov 2014
9VA Black Hills Health Care SystemHealthcare Provider1,1684 Aug 2015
10Prairie Lakes Healthcare SystemHealthcare Provider1,16420 Dec 2022

Section SD.2 / By year

South Dakota filings by submission year

Each year links to the national year page.

YearFilingsIndividuals affected
201318,500
201411,632
2015315,279
2017110,229
201921,260
202112,138
202236,878
20231575
20252132,161

Section SD.3 / Composition

Breach type, location and who filed

Multi-valued fields count once per value.

Type of breach

Hacking/IT Incident8 (53%)
Unauthorized Access/Disclosure4 (27%)
Theft1 (7%)
Loss1 (7%)
Improper Disposal1 (7%)

Location of breached information

Network Server7 (47%)
Paper/Films5 (33%)
Email2 (13%)
Desktop Computer1 (7%)

Covered entity type

Healthcare Provider12 (80%)
Business Associate2 (13%)
Health Plan1 (7%)

Section SD.4 / Notification law

What South Dakota law required alongside HIPAA

State notification statute

South Dakota: S.D. Codified Laws 22-40-19 et seq.

Notice to individuals
No later than 60 days from discovery or notification of the breach
Attorney general threshold
More than 250 South Dakota residents (Within the 60-day window)
Private right of action
No: No PROA; only the Attorney General can enforce
Penalty
Up to $10,000 per day per violation; may be prosecuted as a deceptive practice

The HIPAA Breach Notification Rule runs alongside the state statute: notice to affected individuals and to HHS without unreasonable delay and no later than 60 days after discovery.

Section SD.5 / Filing pages

4 filings of 10,000 or more individuals

Each links to a page with the full filing, its rank in the state and year, OCR's closing summary where the case is archived, peers, and the modelled cost.

Covered entityTypeIndividualsSubmitted
Black Hills Regional Eye InstituteHealthcare Provider106,76331 Mar 2025
Huron Regional Medical Center, Inc.OpenHealthcare Provider25,3986 Jun 2025
Siouxland Anesthesiology, Ltd.Healthcare Provider13,00031 Jul 2015
Plastic Surgery Associates of South DakotaHealthcare Provider10,22927 Jul 2017

Section SD.6 / All other filings

11 filings below 10,000 individuals

Listed in full from the HHS export, largest first. These filings do not have their own page.

Covered entityTypeIndividualsSubmitted
Stronghold Counseling Services, Inc.Healthcare Provider8,50021 Feb 2013
AAA Collections, Inc.Business Associate4,63515 Dec 2022
Sage Medical Professionals LLCBusiness Associate2,13829 Dec 2021
Indian Health Service, Aberdeen Area OfficeHealth Plan1,63213 Nov 2014
VA Black Hills Health Care SystemHealthcare Provider1,1684 Aug 2015
Prairie Lakes Healthcare SystemHealthcare Provider1,16420 Dec 2022
Sioux Falls VA Health Care SystemHealthcare Provider1,11130 Jul 2015
Dow Rummel VillageHealthcare Provider1,07920 Jul 2022
Regional Health Medical Clinic - Flormann StreetHealthcare Provider6961 Apr 2019
Oyate Health CenterHealthcare Provider5752 May 2023
Sioux Falls VA Health Care SystemHealthcare Provider5641 Oct 2019

Index / Other states

Every state on the register

Index / Companion schedules

Provenance

Source: U.S. Department of Health and Human Services, Office for Civil Rights, Breach Portal (breaches affecting 500 or more individuals), retrieved 2026-08-28. Public domain. Individuals affected and dates as reported by the covered entity.

Portal: ocrportal.hhs.gov breach report. Statutory basis: HITECH Act section 13402(e)(4): the Secretary must post a list of breaches of unsecured protected health information affecting 500 or more individuals. Breaches affecting fewer than 500 individuals are reported to OCR annually and are not posted, so they are not on this register. Status wording follows the portal's two tabs ("Cases Currently Under Investigation" and "Archive") as of 28 August 2026; a filing moves to the archive when OCR closes the case. Modelled costs on this site are a method applied to the reported count, using IBM Cost of a Data Breach per-record figures, and are never a cost disclosed by the entity.

Corrections: if you represent a listed entity and the portal row has been amended, email [email protected] with the portal entry and we will re-pull the export.