Form: Cost-of-Breach DisclosureSource: IBM Cost of a Data BreachFiled: 28 Apr 2026
DataBreachCost.comOpen calc
Independent breach-cost research, read by security and risk leaders.Sponsor this site →
State File WY / HHS OCR Breach Register19 filings, 2010 to 2025

Geography

Wyoming: 19 healthcare breach filings.

Wyoming entities have reported 19 breaches of 500 or more individuals to HHS since 2010, the 50th most of the 52 states and territories on the register, covering 287,419 individuals (50th by people affected). 0 are still under investigation. Unauthorized Access/Disclosure is the breach type on 53% of them, and network server the most common location (37%).

Filings

19

50th of 52 states and territories

Individuals affected

287,419

Median filing 5,615

Largest filing

164,010

Wyoming Department of Health, 2021

Hacking / IT share

37%

6 filings involve a business associate

Direct answer / Wyoming on the HHS portal

The largest Wyoming filing is Wyoming Department of Health (164,010 individuals, submitted 29 April 2021). The busiest year was 2013 with 3 filings. Healthcare Providers account for 68% of the state's filings. 7 filings of 10,000 or more individuals have their own page; the remaining 12 are listed in the table at the foot of this page.

Section WY.1 / Largest filings

Ten largest Wyoming breaches

#Covered entityTypeIndividualsSubmitted
1Wyoming Department of HealthHealth Plan164,01029 Apr 2021
2Cheyenne Regional Medical CenterHealthcare Provider17,54910 Dec 2019
3Community Action partnership of Natrona CountyHealthcare Provider15,00020 Apr 2011
4Cheyenne Radiology Group & MRI, P.C.Healthcare Provider12,2229 Feb 2023
5Wyoming Department of HealthHealth Plan11,93519 Dec 2013
6Wyoming Department of HealthHealth Plan11,93516 Dec 2013
7Rocky Mountain Oncology CareHealthcare Provider10,26827 Jun 2025
8Wyoming Department of HealthHealth Plan9,0232 Mar 2010
9Wind River Family and Community Health CareHealthcare Provider8,9467 Dec 2021
10Rocky Mountain Oncology CareHealthcare Provider5,61524 Oct 2025

Section WY.2 / By year

Wyoming filings by submission year

Each year links to the national year page.

YearFilingsIndividuals affected
201019,023
2011115,000
2013326,570
201411,607
201613,184
201825,083
2019219,703
20213173,856
202211,652
2023112,222
202413,636
2025215,883

Section WY.3 / Composition

Breach type, location and who filed

Multi-valued fields count once per value.

Type of breach

Unauthorized Access/Disclosure10 (53%)
Hacking/IT Incident7 (37%)
Theft1 (5%)
Loss1 (5%)

Location of breached information

Network Server7 (37%)
Email6 (32%)
Paper/Films3 (16%)
Desktop Computer2 (11%)
Electronic Medical Record1 (5%)

Covered entity type

Healthcare Provider13 (68%)
Health Plan5 (26%)
Business Associate1 (5%)

Section WY.4 / Notification law

What Wyoming law required alongside HIPAA

State notification statute

Wyoming: Wyo. Stat. 40-12-501, 40-12-502

Notice to individuals
In the most expedient time possible and without unreasonable delay
Attorney general threshold
No AG notification requirement
Private right of action
No: No PROA; the AG may bring civil action
Penalty
AG may seek injunctive relief, compliance orders, and damages; no statutory penalty cap specified

The HIPAA Breach Notification Rule runs alongside the state statute: notice to affected individuals and to HHS without unreasonable delay and no later than 60 days after discovery.

Section WY.5 / Filing pages

7 filings of 10,000 or more individuals

Each links to a page with the full filing, its rank in the state and year, OCR's closing summary where the case is archived, peers, and the modelled cost.

Covered entityTypeIndividualsSubmitted
Wyoming Department of HealthHealth Plan164,01029 Apr 2021
Cheyenne Regional Medical CenterHealthcare Provider17,54910 Dec 2019
Community Action partnership of Natrona CountyHealthcare Provider15,00020 Apr 2011
Cheyenne Radiology Group & MRI, P.C.Healthcare Provider12,2229 Feb 2023
Wyoming Department of HealthHealth Plan11,93519 Dec 2013
Wyoming Department of HealthHealth Plan11,93516 Dec 2013
Rocky Mountain Oncology CareHealthcare Provider10,26827 Jun 2025

Section WY.6 / All other filings

12 filings below 10,000 individuals

Listed in full from the HHS export, largest first. These filings do not have their own page.

Covered entityTypeIndividualsSubmitted
Wyoming Department of HealthHealth Plan9,0232 Mar 2010
Wind River Family and Community Health CareHealthcare Provider8,9467 Dec 2021
Rocky Mountain Oncology CareHealthcare Provider5,61524 Oct 2025
Gillette Medical ImagingHealthcare Provider4,47618 Jan 2018
Elkhorn Valley Rehabilitation HospitalHealthcare Provider3,63629 Mar 2024
Wyoming Medical CenterHealthcare Provider3,18420 Apr 2016
Hansen and Associates, Inc.Business Associate2,70015 Jul 2013
Wyoming Department of HealthHealth Plan2,15425 Jun 2019
Cheyenne Regional Medical CenterHealthcare Provider1,6525 Jul 2022
North Big Horn HospitalHealthcare Provider1,6071 Dec 2014
Campbell County Hospital DistrictHealthcare Provider90024 Feb 2021
High Plains Surgical AssociatesHealthcare Provider60715 Jan 2018

Index / Other states

Every state on the register

Index / Companion schedules

Provenance

Source: U.S. Department of Health and Human Services, Office for Civil Rights, Breach Portal (breaches affecting 500 or more individuals), retrieved 2026-08-28. Public domain. Individuals affected and dates as reported by the covered entity.

Portal: ocrportal.hhs.gov breach report. Statutory basis: HITECH Act section 13402(e)(4): the Secretary must post a list of breaches of unsecured protected health information affecting 500 or more individuals. Breaches affecting fewer than 500 individuals are reported to OCR annually and are not posted, so they are not on this register. Status wording follows the portal's two tabs ("Cases Currently Under Investigation" and "Archive") as of 28 August 2026; a filing moves to the archive when OCR closes the case. Modelled costs on this site are a method applied to the reported count, using IBM Cost of a Data Breach per-record figures, and are never a cost disclosed by the entity.

Corrections: if you represent a listed entity and the portal row has been amended, email [email protected] with the portal entry and we will re-pull the export.