Geography
Wyoming: 19 healthcare breach filings.
Wyoming entities have reported 19 breaches of 500 or more individuals to HHS since 2010, the 50th most of the 52 states and territories on the register, covering 287,419 individuals (50th by people affected). 0 are still under investigation. Unauthorized Access/Disclosure is the breach type on 53% of them, and network server the most common location (37%).
Filings
19
50th of 52 states and territories
Individuals affected
287,419
Median filing 5,615
Largest filing
164,010
Wyoming Department of Health, 2021
Hacking / IT share
37%
6 filings involve a business associate
Direct answer / Wyoming on the HHS portal
The largest Wyoming filing is Wyoming Department of Health (164,010 individuals, submitted 29 April 2021). The busiest year was 2013 with 3 filings. Healthcare Providers account for 68% of the state's filings. 7 filings of 10,000 or more individuals have their own page; the remaining 12 are listed in the table at the foot of this page.
Section WY.1 / Largest filings
Ten largest Wyoming breaches
| # | Covered entity | Type | Individuals | Submitted | Breach type | Location | BA |
|---|---|---|---|---|---|---|---|
| 1 | Wyoming Department of Health | Health Plan | 164,010 | 29 Apr 2021 | |||
| 2 | Cheyenne Regional Medical Center | Healthcare Provider | 17,549 | 10 Dec 2019 | |||
| 3 | Community Action partnership of Natrona County | Healthcare Provider | 15,000 | 20 Apr 2011 | |||
| 4 | Cheyenne Radiology Group & MRI, P.C. | Healthcare Provider | 12,222 | 9 Feb 2023 | |||
| 5 | Wyoming Department of Health | Health Plan | 11,935 | 19 Dec 2013 | |||
| 6 | Wyoming Department of Health | Health Plan | 11,935 | 16 Dec 2013 | |||
| 7 | Rocky Mountain Oncology Care | Healthcare Provider | 10,268 | 27 Jun 2025 | |||
| 8 | Wyoming Department of Health | Health Plan | 9,023 | 2 Mar 2010 | |||
| 9 | Wind River Family and Community Health Care | Healthcare Provider | 8,946 | 7 Dec 2021 | |||
| 10 | Rocky Mountain Oncology Care | Healthcare Provider | 5,615 | 24 Oct 2025 |
Section WY.2 / By year
Wyoming filings by submission year
Each year links to the national year page.
Section WY.3 / Composition
Breach type, location and who filed
Multi-valued fields count once per value.
Type of breach
Location of breached information
Covered entity type
Section WY.4 / Notification law
What Wyoming law required alongside HIPAA
State notification statute
Wyoming: Wyo. Stat. 40-12-501, 40-12-502
- Notice to individuals
- In the most expedient time possible and without unreasonable delay
- Attorney general threshold
- No AG notification requirement
- Private right of action
- No: No PROA; the AG may bring civil action
- Penalty
- AG may seek injunctive relief, compliance orders, and damages; no statutory penalty cap specified
The HIPAA Breach Notification Rule runs alongside the state statute: notice to affected individuals and to HHS without unreasonable delay and no later than 60 days after discovery.
Section WY.5 / Filing pages
7 filings of 10,000 or more individuals
Each links to a page with the full filing, its rank in the state and year, OCR's closing summary where the case is archived, peers, and the modelled cost.
| Covered entity | Type | Individuals | Submitted | Breach type | Location | BA |
|---|---|---|---|---|---|---|
| Wyoming Department of Health | Health Plan | 164,010 | 29 Apr 2021 | |||
| Cheyenne Regional Medical Center | Healthcare Provider | 17,549 | 10 Dec 2019 | |||
| Community Action partnership of Natrona County | Healthcare Provider | 15,000 | 20 Apr 2011 | |||
| Cheyenne Radiology Group & MRI, P.C. | Healthcare Provider | 12,222 | 9 Feb 2023 | |||
| Wyoming Department of Health | Health Plan | 11,935 | 19 Dec 2013 | |||
| Wyoming Department of Health | Health Plan | 11,935 | 16 Dec 2013 | |||
| Rocky Mountain Oncology Care | Healthcare Provider | 10,268 | 27 Jun 2025 |
Section WY.6 / All other filings
12 filings below 10,000 individuals
Listed in full from the HHS export, largest first. These filings do not have their own page.
| Covered entity | Type | Individuals | Submitted | Breach type | Location | BA |
|---|---|---|---|---|---|---|
| Wyoming Department of Health | Health Plan | 9,023 | 2 Mar 2010 | |||
| Wind River Family and Community Health Care | Healthcare Provider | 8,946 | 7 Dec 2021 | |||
| Rocky Mountain Oncology Care | Healthcare Provider | 5,615 | 24 Oct 2025 | |||
| Gillette Medical Imaging | Healthcare Provider | 4,476 | 18 Jan 2018 | |||
| Elkhorn Valley Rehabilitation Hospital | Healthcare Provider | 3,636 | 29 Mar 2024 | |||
| Wyoming Medical Center | Healthcare Provider | 3,184 | 20 Apr 2016 | |||
| Hansen and Associates, Inc. | Business Associate | 2,700 | 15 Jul 2013 | |||
| Wyoming Department of Health | Health Plan | 2,154 | 25 Jun 2019 | |||
| Cheyenne Regional Medical Center | Healthcare Provider | 1,652 | 5 Jul 2022 | |||
| North Big Horn Hospital | Healthcare Provider | 1,607 | 1 Dec 2014 | |||
| Campbell County Hospital District | Healthcare Provider | 900 | 24 Feb 2021 | |||
| High Plains Surgical Associates | Healthcare Provider | 607 | 15 Jan 2018 |
Index / Other states
Every state on the register
98
32
164
92
776
139
144
31
33
463
226
22
29
358
200
98
80
124
66
37
170
241
238
189
55
164
36
60
55
38
174
57
511
207
19
276
80
120
339
32
41
86
15
196
633
68
15
157
185
47
126
Index / Companion schedules
13 HHS breach register
→Hub: every filing, by state, year and entity.
04 Biggest breaches
→Mega-breaches with primary-source cost figures.
Industry / Healthcare
→IBM 2026: $6.64M average, 13 years at #1.
Regulation / HIPAA penalties
→OCR enforcement tiers and the 60-day rule.
11 50-state laws
→Deadline, AG threshold and penalties per state.
Cost / Per record
→Where the per-record model is reliable.
Provenance
Source: U.S. Department of Health and Human Services, Office for Civil Rights, Breach Portal (breaches affecting 500 or more individuals), retrieved 2026-08-28. Public domain. Individuals affected and dates as reported by the covered entity.
Portal: ocrportal.hhs.gov breach report. Statutory basis: HITECH Act section 13402(e)(4): the Secretary must post a list of breaches of unsecured protected health information affecting 500 or more individuals. Breaches affecting fewer than 500 individuals are reported to OCR annually and are not posted, so they are not on this register. Status wording follows the portal's two tabs ("Cases Currently Under Investigation" and "Archive") as of 28 August 2026; a filing moves to the archive when OCR closes the case. Modelled costs on this site are a method applied to the reported count, using IBM Cost of a Data Breach per-record figures, and are never a cost disclosed by the entity.
Corrections: if you represent a listed entity and the portal row has been amended, email [email protected] with the portal entry and we will re-pull the export.