Scenario wins: SynapseSeer (16) Panshul42 (8) smingers-bot (8) hayek-bot (5) Mantic (4) lewinke-thinking-bot* (4)
| Figure/Metric | Value | Source | Significance |
|---|---|---|---|
| Hacking Breaches (2024) | 534 | HHS OCR Report | Establishes a 2024 baseline of 44.5 hacking breaches per month. |
| Hacking Breaches (Jan 1-Jun 5, 2026) | 246 | Medcurity/HHS | Shows a 2026 run-rate of approximately 48 hacking breaches per month. |
| Record Total Breaches (2025) | 772 | HIPAA Journal | Indicates a peak period of breach reporting (avg. 64.3 total breaches/month). |
| Hacking % of Total (2026 YTD) | 87% | Medcurity | Confirms that Hacking/IT Incidents remain the dominant breach type. |
| Hacking Breaches (Feb 2026) | 57 | HIPAA Journal | Highlights potential for monthly volatility and surges above the average. |
The question asks how many HHS OCR 500+-record breach portal rows will show a Breach Submission Date in July 2026 and a Type of Breach containing “Hacking/IT Incident” (deduped only by exact Name + State + Submission Date), as observed on the portal by the 2026-08-12 snapshot. Forecasters agree the resolution is about posted submission dates (not incident dates) and that OCR verification/posting lag means an Aug.12 snapshot will likely undercount some late-July submissions. Historical July tallies from OCR/HIPAA Journal cluster in the high‑30s to around 40 in recent Julys (36 in 2024, ~40 in 2025), while the 2026 Jan–May run‑rate is lumpy but centered in the low‑to‑mid‑40s (36, 57, 61, 36, ~42 for Jan–May); teams therefore anchor the forecast in the high‑30s/low‑40s after a modest downward adjustment for posting lag. All teams flag a meaningful upside tail driven by vendor/business‑associate or mass‑exploitation events (one vendor incident can create many covered‑entity rows under the question’s dedupe rule). Quantitatively, forecasters centered near ~39–41 with substantial dispersion and assigned roughly a mid‑teens to ~20% chance of exceeding the question’s provided upper bound. The recommended resolution workflow is to pull the OCR CSV/Excel on Aug.12, filter submission dates 07/01–07/31/2026 and Type contains “Hacking/IT Incident,” then group by exact Name+State+Submission Date.
Forecast: Probability distribution:
We are forecasting the count of unique 500+ HIPAA breaches whose Breach Submission Date is in July 2026 and whose Type of Breach contains “Hacking/IT Incident”, as displayed on the OCR portal as of 2026-08-12.
Two drivers dominate:
Synthesis: I expect the Aug 12 snapshot to capture something like ~60–80% of the eventual July hacking/IT count in a typical-processing scenario (pulling the median down into the low 30s), with a meaningful downside tail if OCR slows again (teens) and an upside tail if processing is fast and/or a batch update happens before Aug 12 (bringing the count near the full-month level and potentially above 47). I therefore place the median at 31, with about ~10–20% probability mass above the 47 open-upper bound (expressed by p90+ past-bound values).
An amateur forecast is likely to anchor on the “full month” July hacking/IT volume (~40–55) and ignore that the question resolves on an early snapshot (Aug 12), which can miss late-posted July submissions. My forecast explicitly models this administrative/processing lag (using the team’s evidence that the portal can run weeks behind) while still keeping an upper tail for scenarios where July is high-volume and/or OCR posts quickly. I’m moderately confident this improves calibration versus either (a) ignoring lag entirely (too high) or (b) assuming an extreme multi-month backlog persists unchanged (too low).
Forecast rationale (numeric):
— Iteration 1 — Across the forecasts, the main reasoning pattern is to start with recent HIPAA breach filing volume and then narrow to Hacking/IT Incident cases using the historically high share of cyber-related breaches.
Overall, the collective reasoning points to a highly cyber-skewed breach category, with the final July 2026 HHS-reported count likely shaped by a combination of recent breach volume, high hacking prevalence, and especially reporting lag/backlog effects. The central view leans toward a count in the moderate-to-high tens, with uncertainty wide enough to permit both a notably lower observed total and a higher, backlog-inflated one.
— Iteration 2 — The forecasts converge on a centered estimate around 38–40 Hacking/IT Incident HIPAA breaches reported to HHS for July 2026, with most of the probability mass in the high 20s to low/mid 50s.
Overall, the shared view is a mid-30s to low-40s forecast with a center near 40, tempered by reporting timing and the possibility of occasional large cyber-related bursts.
— Iteration 3 — The forecasts share a common structure:
Historical baseline as the anchor: All of the reasoning starts from recent monthly Hacking/IT breach volumes, especially the 2024 pace of roughly 50–54 incidents per month. This serves as the main reference point for July 2026.
Downward adjustments from reporting mechanics: Each rationale then trims that baseline because the HHS count is not a pure “events occurred” measure. Two recurring adjustments are:
Seasonality and distribution concerns: The estimates allow for month-to-month volatility, with the count potentially lower in a quiet month or higher if a vendor-related or large-scale incident triggers a batch of filings. The distribution is described as right-skewed, with occasional spikes from major breach clusters.
Use of recent 2026 conditions: One rationale also notes that Q1 2026 breach activity was elevated, which supports staying near the historical baseline rather than expecting a sharp drop. This tempers the downward adjustments and keeps the central estimate in the mid-range.
There is strong agreement that July 2026 is more likely in the low-to-mid 40s than near or above 50, and that the outcome is probably below 47.5.
The main variation is in how aggressively the baseline is reduced: one estimate lands around 40, while others settle in the mid-40s. The spread reflects differing assumptions about how much late-month reporting lag and deduplication will suppress the visible count.
Summary of Rationales
Baseline Volume and Threat Landscape Forecasters broadly agree that the underlying baseline for “Hacking/IT Incident” breaches remains high, historically accounting for the vast majority of major healthcare data breaches. The rationales anticipate a surge in raw submissions during July 2026, driven by several massive third-party vendor and supply-chain compromises discovered in May and June (e.g., Xsolis, OpenLoop Health, CareCloud). Under the HIPAA Breach Notification Rule’s 60-day mandate, downstream covered entities must file individual reports. Because deduplication rules do not consolidate reports from different affected hospitals or clinics, this fragmented reporting is expected to generate a high volume of unique submissions in July.
The Snapshot Constraint and OCR Verification Lag The most critical factor shaping the forecasts is the resolution snapshot date of August 12, 2026—just 12 days after the end of July. The HHS OCR does not publish reports automatically; submissions must undergo a verification process that historically takes a minimum of 14 days. Furthermore, multiple rationales highlight evidence of a severe, ongoing administrative backlog at the OCR in 2026, with processing delays reportedly stretching from three to six weeks.
Impact on Final Visibility Because organizations heavily skew their filings toward the end of the calendar month or the very end of their 60-day legal deadlines, a disproportionately large chunk of July’s reports will be submitted in late July. Consequently, forecasters expect that the combination of standard verification times and the severe 2026 processing backlog will act as a heavy filter. While the true number of July submissions is expected to be inflated by recent cyber threats, the actual number publicly visible on the portal by the August 12 snapshot will be significantly truncated, likely only reflecting submissions from the first half of the month or fast-tracked placeholder reports.
Question: How many HIPAA breaches categorized as a “Hacking/IT Incident” will be reported to the HHS during July 2026? Final Prediction: Probability distribution:
Total Cost: extra_metadata_in_explanation is disabled Time Spent: extra_metadata_in_explanation is disabled LLMs: extra_metadata_in_explanation is disabled Bot Name: extra_metadata_in_explanation is disabled
Forecaster 1: Probability distribution:
Forecaster 2: Probability distribution:
The research combines recent 2026 reporting, multi-year historical base rates, and qualitative drivers to produce a quantitative forecast that July 2026 will see about 45–60 HIPAA breaches categorized as “Hacking/IT Incident,” with a central estimate of roughly 50–55 breaches. It derives this range from: (a) early-2026 observation that 91.5% of reported 2026 breaches were hacking/IT incidents (173 of 189 as of June 9, 2026); (b) 2025 and Q1‑2026 monthly averages (2025 ≈52 hacking/IT breaches/month, Q1‑2026 ≈61/month); and (c) several reference‑class monthly estimates and recent monthly counts that produced a 70% confidence interval of 45–60 and a wider 90% interval of 35–70.
The research also documents key risk drivers (ransomware prevalence, rising third‑party vendor involvement, AI‑assisted phishing, and recent large vendor incidents) and mitigating factors (shorter detection/containment times, OCR reorganization, and fewer ransom payments). It highlights important data‑quality and timing uncertainties—especially OCR reporting backlogs and a late‑2025 federal shutdown that produced reporting delays—and notes no active prediction markets specifically forecasting July 2026 HIPAA breach counts were found.
Sources used in the research (websites referenced or searched)
Based on my research, I estimate that 45-60 HIPAA breaches categorized as “Hacking/IT Incident” will be reported to HHS during July 2026, with a central estimate around 50-55 breaches. However, I found no active prediction markets specifically addressing this question.
As of June 9, 2026, the healthcare breach landscape shows:
The percentage of breaches caused by hacking/IT incidents has been steadily increasing, from ~80% in 2024-2025 to over 91% in early 2026.
Important caveat: The HHS OCR portal experienced significant delays in 2025-2026:
These delays may create artificial variance in monthly submission counts.
I found NO active prediction markets (Metaculus, Manifold, Kalshi, or others) specifically forecasting HIPAA breach counts for July 2026. My searches returned only general healthcare cybersecurity market analyses [19][20][21], which project industry growth but do not provide breach forecasts.
Based on multiple reference classes:
| Reference Class | Monthly Estimate | Confidence |
|---|---|---|
| 2025 annual average (52 per month) | 42-52 | Moderate - older data |
| Q1 2026 average (61 per month) | 55-67 | High - recent but may include backlog |
| Jan-June 2026 actual (32.6 per month) | 28-38 | Low - seems artificially low |
| Individual 2026 months reported | 40-66 | Moderate - high variance |
| 2026 trend + 91% hacking rate | 50-60 | Moderate-High |
I accept the critic’s Round 4 point: my Round 3 forecast probably applied the “~3-week lag” too mechanically. The official portal snapshot still strongly supports lag as the dominant variable: on June 26, the portal’s newest displayed under-investigation submission dates were June 5/3/2, and it also announced a June 26–27 maintenance window. But that does not imply a simple “visible fraction = 22/31 of July” calculation. Submission dates are lumpy, and a cutoff around July 22 could capture more than a proportional share of July rows. (ocrportal.hhs.gov)
The May anchor is especially useful. The visible May 2026 portal rows contain about 42 unique Hacking/IT breaches under the Metaculus duplicate rule, with the two Gastro Health / FL / 05/22/2026 rows collapsing to one unique breach. May is also somewhat front-/mid-loaded: only a few visible Hacking/IT rows occur after May 22, so a July cutoff around July 22 might still capture a large fraction of the eventual July total. I do not want to overfit May’s exact date pattern, but it is a real reason to move slightly upward from my prior. (ocrportal.hhs.gov)
I still think the main bearish argument remains correct. HIPAA Journal says OCR usually has up to about a two-week delay, but March 2026 was much worse: no March submissions were added during March, rows only began appearing in mid-April, and later backfill added many more March rows. That means even “through July 22” may be incomplete by August 12 if backfilling remains uneven. (hipaajournal.com)
For latent July volume, I continue to center the full-month unique Hacking/IT count in the mid-to-high 40s, not 50+. April had 36 Hacking/IT incidents out of 47 total breaches, March had 61 of 66, and Medcurity’s OCR pull through June 5 found 246 of 283 H1 2026 large-breach reports were Hacking/IT. So classification risk is low; visibility/posting cadence is the key uncertainty. (hipaajournal.com)
Net: I move modestly upward from Round 3. I now put the median around 37, with about 21–22% probability above 47, conditional on the question not resolving Ambiguous/annulled. The left tail remains fat for stale portal/backfill failure; the right tail remains fat for partial OCR normalization, batch posting, or a vendor-linked cluster.
Updated prediction:
Percentile 0.1: 1.0
Percentile 1: 6.8
Percentile 5: 16.8
Percentile 10: 21.9
Percentile 20: 27.6
Percentile 30: 31.4
Percentile 40: 34.6
Percentile 50: 37.1
Percentile 60: 39.9
Percentile 70: 43.5
Percentile 80: 47.7
Percentile 90: 55.1
Percentile 95: 62.5
Percentile 99: 78.0
Percentile 99.9: 98.0
I accept the critic’s main point: the Aug. 12 snapshot/censoring mechanism should dominate the forecast more than the eventual July breach count. The live HHS OCR portal I can access shows a maintenance notice for June 26–27 and top visible “Under Investigation” submission dates only through June 5, 2026, which supports treating a ~2–3 week publication frontier as a central scenario, not just a low-tail oddity. (ocrportal.hhs.gov) HIPAA Journal’s March report is also directly relevant: it says March breaches were not added during March, began appearing only in mid-April, and continued receiving additions after the report was first published. (hipaajournal.com)
I still do not want to collapse the high tail too much. The eventual full-month July Hacking/IT count should still be anchored in the low/mid-40s: HHS’s 2024 report says Hacking/IT incidents were 81% of large-breach reports, and Medcurity reports 246 Hacking/IT incidents out of 283 ≥500-person reports submitted Jan. 1–June 5, 2026. (hhs.gov) A catch-up batch, a return toward normal posting cadence, or a many-covered-entity vendor cluster can still produce a visible count above 47.
That said, the critic’s “slightly lower” adjustment is persuasive. April was soft at 36 Hacking/IT incidents out of 47 large breaches, and a rough read of the visible May portal rows points to a low-40s Hacking/IT month rather than a high-40s/50s month; the duplicate Gastro Health / FL / 05/22/2026 rows also illustrate why this question’s de-duplication rule is a small downward adjustment. (hipaajournal.com) My current model is: eventual July unique Hacking/IT count centered around 42–46, multiplied by a visibility fraction centered around 70–80%, with a fat low tail for stale portal behavior and a still-meaningful upper tail for catch-up/cluster scenarios.
Conditioning on the question resolving numerically and not being annulled/ambiguous, I move the median down to about 35 and put P(>47) around 24–25%.
Updated prediction:
Percentile 0.1: 0.4
Percentile 1: 3.4
Percentile 5: 11.4
Percentile 10: 16.4
Percentile 20: 23.4
Percentile 30: 28.4
Percentile 40: 32.4
Percentile 50: 35.4
Percentile 60: 39.4
Percentile 70: 43.4
Percentile 80: 50.4
Percentile 90: 62.4
Percentile 95: 74.4
Percentile 99: 96.4
Percentile 99.9: 120.4
Modal: 35-41 (24.6%) • frontier aggregate • 6m48s
Resolution sources/checks:
Edge cases:
frontier_1 - Modal: 41-47 (29.0%)
frontier_2 - Modal: 29-35 (22.0%)
frontier_3 - Modal: 35-41 (24.0%)
frontier_4 - Modal: 35-41 (45.0%)
Material notes
Guidance
Revision
| Bin | Probability |
|---|---|
| 0-6 | 1.1% |
| 6-12 | 2.4% |
| 12-18 | 5.0% |
| 18-24 | 9.0% |
| 24-29 | 12.5% |
| 29-35 | 19.3% |
| 35-41 | 24.6% |
| 41-47 | 17.6% |
| Above 47 | 8.6% |
wooley_rhino • run 3f26a51d • $3.2 • 6m48s
Extracted Percentile Values: {0.1: 16, 1.0: 23, 5.0: 30, 10.0: 34, 15.0: 37, 20.0: 39, 25.0: 41, 30.0: 43, 35.0: 45, 40.0: 46.5, 45.0: 48, 46.0: 48.3, 47.0: 48.7, 48.0: 49, 49.0: 49.4, 50.0: 49.8, 51.0: 50.2, 52.0: 50.6, 53.0: 51, 54.0: 51.5, 55.0: 52, 60.0: 53.5, 65.0: 55.5, 70.0: 57.5, 75.0: 60, 80.0: 62.5, 85.0: 65.5, 90.0: 69.5, 95.0: 73.5, 99.0: 80, 99.9: 88}
Model’s Answer: This is a cumulative-count forecast with a fairly strong base rate and meaningful month-to-month variance.
The most useful anchor is the recent run rate of large HIPAA breaches and the share that are classified as Hacking/IT Incident. The research consistently points to roughly the low 60s per month for all large breaches in the record 2025 environment, with hacking making up roughly three quarters to a bit over nine tenths depending on the month. That implies a broad baseline around the high 40s to low 50s Hacking/IT incidents in a typical month.
Recent month-specific evidence supports that range but also shows real volatility. March 2026 was very high, with 61 hacking incidents out of 66 large breaches. April 2026 was noticeably lower, with 36 hacking incidents out of 47 large breaches. That is a wide swing, which argues against overconfidence. I would not project March’s very high share straight through, but I also would not assume April’s softer month represents a new normal. The structural story still points upward or at least persistently elevated: vendor breaches, phishing, ransomware, and multi-client incidents are still common, and reporting lag means July submissions can include older incidents whose investigations only recently matured.
The exact resolution mechanics matter. This resolves on breaches with a July 2026 breach submission date, as displayed on the HHS portal by August 12, and deduped by entity, state, and submission date. That means this is not a forecast of incidents occurring in July, but of report submissions recorded in July and visible by resolution. Portal lag or clerical corrections can move the total a bit. Because the resolution date is only about two weeks after July ends, I slightly discount the raw underlying incident flow for the chance that some July submissions are added late or classification fields are updated after the cutoff. That pushes me a touch lower than a naive “annual average times hacking share” estimate.
My base case is therefore around 50 breaches. I think the most likely band is roughly the mid 40s to upper 50s, with a meaningful but not dominant chance of a low month in the 30s and a smaller but real chance of a very active month in the 60s or low 70s.
The assumptions that matter most are these. The first is that July’s total large-breach submissions remain near the recent 2025 to 2026 pace rather than dropping sharply; I put about a 30% chance on that being materially wrong. The second is that Hacking/IT stays near its recent dominant share rather than falling back toward the low 70s; I put about a 20% chance on that being materially wrong. The third is that portal timing and deduplication effects do not suppress the visible count by more than a few cases by August 12; I put about a 15% chance on that being materially wrong. Those failure modes are the main reason I keep the distribution fairly wide.
A low outcome would come from a softer total-breach month plus more non-hacking classifications and/or a few July submissions not yet visible on the portal by the resolution snapshot. I think something in the low 30s or below is possible but clearly minority-likelihood. A high outcome would come from one or more vendor-driven clusters, continued very high hacking share, and normal portal posting cadence. A result in the mid 60s or higher is plausible, but still distinctly less likely than a total near 50.
Percentile .1: 16 Percentile 1: 23 Percentile 5: 30 Percentile 10: 34 Percentile 15: 37 Percentile 20: 39 Percentile 25: 41 Percentile 30: 43 Percentile 35: 45 Percentile 40: 46.5 Percentile 45: 48 Percentile 46: 48.3 Percentile 47: 48.7 Percentile 48: 49 Percentile 49: 49.4 Percentile 50: 49.8 Percentile 51: 50.2 Percentile 52: 50.6 Percentile 53: 51 Percentile 54: 51.5 Percentile 55: 52 Percentile 60: 53.5 Percentile 65: 55.5 Percentile 70: 57.5 Percentile 75: 60 Percentile 80: 62.5 Percentile 85: 65.5 Percentile 90: 69.5 Percentile 95: 73.5 Percentile 99: 80 Percentile 99.9: 88
Forecast (July 2026, reported by Aug 12, 2026): median = 35.5492
I treated this as a forecast about what will be publicly listed on the OCR Breach Portal by August 12, 2026, not simply how many real-world July cyber incidents occur. That matters because for breaches affecting 500 or more people, entities must report to HHS without unreasonable delay and no later than 60 days from discovery, so July submission counts reflect reporting cadence as well as incident cadence. OCR also says that a large breach is not posted to the HHS Breach Portal the same day it is received; OCR first verifies the report, and this verification is generally completed within 14 days. (hhs.gov)
For the medium-term base rate, I used HHS’s official annual breach reports. For breaches affecting 500 or more individuals that occurred in 2022, OCR recorded 462 Hacking/IT incidents out of 626 total large breaches; for 2023 it was 590 out of 732; for 2024 it was 534 out of 663. That is an average of about 44.06 Hacking/IT incidents per month across those three years. HHS’s 2026 press release also says that hacking and ransomware are the most frequent type of large breach reported to OCR, which supports keeping hacking as the dominant category in 2026 as well. (hhs.gov)
I then checked the current OCR portal for a nearer-term reality check. The live HIPAA under-investigation page says it covers the last 24 months and currently displays 724 open HIPAA cases. In the first 100 displayed rows, the submission dates run from March 27, 2026 through June 5, 2026. By my manual count on that slice, after applying the question’s uniqueness rule (same name + state + submission date counts once), there are about 32 unique Hacking/IT incidents in April 2026 and 42 in May 2026. There is at least one visible duplicate-row example on the page—Gastro Health, Florida, 05/22/2026 appears twice—which is why I adjusted row counts down to unique-breach counts. The same slice implies a recent pace of about 38.86 unique Hacking/IT incidents per 31-day month. (ocrportal.hhs.gov)
Those two lenses point in the same general area but not exactly the same number: the multi-year annual base rate suggests a low-to-mid 40s month, while the very recent portal cadence suggests a high-30s to low-40s month. I put more weight on the recent portal cadence because this question resolves off the portal as displayed on a near-term date, and almost all July 2026 submissions that resolve numerically should still be in the under-investigation tab by August 12 rather than already archived; that last point is an inference from OCR’s description of first verifying reports and only later closing investigations. (ocrportal.hhs.gov)
I also adjusted slightly downward for the August 12 cutoff. Because OCR says verification generally takes up to about 14 days, a small share of very late-July submissions could still be missing from the public portal at the resolution timestamp, even if they were actually submitted during July. On the other hand, the cutoff is still late enough that most of July should be visible. (hhs.gov)
Putting this together, my center is about 40 reported unique July 2026 Hacking/IT breaches visible on the portal by August 12. I encoded that judgment as a mixture of three negative-binomial scenarios: a lower scenario (mean 34.5) for a quieter month and/or more late-July verification lag, a baseline scenario (mean 40.5), and a higher scenario (mean 46.0) for a busier cyber month and somewhat faster posting. The weighted mean of those scenarios is 40.1. This leaves real mass in the upper tail above 47, but my median expectation stays around 40 because the recent portal cadence is a bit below the straight historical annual average.
I treat this as a question about what will be visible on the OCR portal by August 12, 2026, not the eventual final July total after later backfilling. HHS says breaches affecting 500 or more individuals must be reported without unreasonable delay and no later than 60 days after discovery; if the number affected is uncertain, the filer should provide an estimate, and later addenda can supplement or modify the report. That matters because July filings can appear before investigations are complete, and portal timing is part of the uncertainty here. (hhs.gov)
The long-run base rate is strongly cyber-heavy. HHS’s 2023 report to Congress says OCR received 732 large-breach notifications and that Hacking/IT Incident comprised 81% of 500+ breaches; the 2024 report says 663 such notifications and the same 81% hacking share. As a crude annual baseline, that is about 49 and 43 hacking-type large breaches per month, respectively. (hhs.gov)
Recent portal-derived monthly data are in the same general range but choppy: January 2026 had 46 large breaches, 36 of them hacking/IT; February had 63 total and 57 hacking/IT; March had 66 total and 61 hacking/IT; April had 47 total and 36 hacking/IT. July has recently been a bit softer than some spring months: July 2024 had 43 total and 36 hacking/IT, while July 2025 had 48 total and about 40 hacking/IT. Also, from January 1 to April 30, 2026, total large breaches were 252 versus 276 in the same period of 2025, a decline of 8.7%, which nudges me a bit below July 2025 rather than above it. (hipaajournal.com)
The key adjustment is publication lag. In the current official OCR portal snapshot, the newest visible June submission date on the under-investigation page is June 5, and the list then drops back to May 29; I infer from that snapshot that the public portal was lagging by roughly 2-3 weeks at that moment. Independent portal-based reporting also says OCR has been slow to add cases in 2026: HIPAA Journal noted a typical delay of up to about two weeks, but also reported that the late-2025 43-day shutdown created a backlog, that as of April 10 only two March 2026 breaches were listed, and that as of June 2026 breaches were still being added for March. Because this question resolves on August 12, only 12 days after July ends, I expect the portal snapshot to capture only roughly two-thirds to three-quarters of July’s eventual submissions. (ocrportal.hhs.gov)
I also make a small downward adjustment for the question’s uniqueness rule. The official portal page already shows at least one duplicate entity-state-date combination: Gastro Health in Florida with a 05/22/2026 submission date appears twice. Because the resolution rule collapses rows sharing the same name, state, and submission date, the final resolved count should be slightly below raw row counts. (ocrportal.hhs.gov)
Putting that together, my central path is: an eventual July 2026 level in the high 30s for unique hacking/IT incidents, multiplied by a visibility factor around 0.7 by August 12, which lands near 26-27 visible unique breaches. I encode that uncertainty with an overdispersed negative-binomial distribution centered at 26.7 rather than a narrow Poisson, because both cyber-incident frequency and portal lag are materially uncertain. My median is about 26-27, most of the mass is in the high teens through the 30s, and the probability of finishing above 47 is small but not zero. (hhs.gov)
The question resolves from the HHS OCR Breach Portal, which publicly lists HIPAA breaches affecting 500 or more individuals and separates cases into Under Investigation and Archive. HHS also says filers must submit a separate notice for each breach and may later file addenda that supplement or modify a prior notice, so portal timing and later edits matter for this market. (ocrportal.hhs.gov)
For the structural base rate, HHS’s 2024 report to Congress recorded 663 large breaches, and 81% of those were hacking/IT incidents, which is about 44.8 hacking breaches per month on average. HHS also said in April 2026 that hacking and ransomware are the most frequent type of large breach reported to OCR. (hhs.gov)
Recent monthly counts are elevated but choppy. OCR-based monthly reports compiled by HIPAA Journal show 36 hacking incidents in January 2026, 57 in February 2026, 61 in March 2026, and 36 in April 2026. For same-month seasonality, July 2024 had 36 hacking incidents, while July 2025 had 83.3% of 48 breaches caused by hacking or other IT issues, or about 40 incidents. Medcurity’s June 5, 2026 OCR pull found 246 hacking/IT incidents out of 283 large 2026 breaches year-to-date through June 5, about 86.9%, which supports keeping hacking as the dominant category in 2026. (hipaajournal.com)
I then adjust downward for publication lag and for the fact that the market resolves on August 12, 2026 rather than later in August. The March 2026 OCR-based report says portal publication typically lags receipt by up to about two weeks, and that report later gained 22 additional March entries after first publication. The July 2025 report similarly notes that July 2024 stood at 43 breaches when compiled in August 2024 but later rose to 49. That makes me expect the August 12 snapshot to be a few counts below the more mature late-August/September view of July 2026. (hipaajournal.com)
My center estimate is therefore about 40 unique July 2026 breaches whose Type of Breach contains ‘Hacking/IT Incident’. Intuitively: the long-run official baseline is about 45 per month, prior Julys look more like the high 30s to about 40, recent 2026 months have usually been between the mid-30s and low 60s, and then I shave a few counts for the early August 12 snapshot and for occasional same-name/state/date duplicate-row consolidation under the market’s unique-breach rule. I encode that judgment as a two-scenario mixture: a 65% normal-processing scenario centered at 43 and a 35% laggier-posting scenario centered at 34. That gives a mean of 39.85, with most probability mass in the 36-44 range, a meaningful but not dominant tail into the high 40s, and a smaller lag-driven tail into the low 30s. (hhs.gov)
I am forecasting the count that will be visible on the OCR portal at 2026-08-12 12:00:00+00:00, not the eventual fully backfilled July total. HHS says breaches affecting 500 or more individuals must be reported without unreasonable delay and no later than 60 calendar days from discovery, estimates may be used when the number affected is uncertain, and addenda may later supplement or modify an earlier submission. HHS also says large breaches are not posted to the public portal the same day OCR receives them; OCR verifies the report first, and that verification is generally completed within 14 days. (hhs.gov)
The current public portal behavior suggests meaningful listing lag still exists. The official OCR portal page says the under-investigation tab lists HIPAA breaches from the last 24 months that are currently under investigation, shows 724 rows on that tab, and in the current crawl the newest visible submission dates are only 06/02/2026 through 06/05/2026. That means the public-facing portal is clearly not real-time right now. Late additions are also a known issue: HIPAA Journal’s 2025 annual report says the 2024 total rose from 725 in the initial January 2025 compilation to 742 over the following months, and warns 2025 late additions could be larger because of the 43-day federal shutdown in late 2025. (ocrportal.hhs.gov)
For raw monthly hacking counts, the best July baselines are fairly moderate. HIPAA Journal’s July 2024 report counted 43 total large breaches, of which 36 were hacking/IT incidents. Its July 2025 report counted 48 total large breaches, and the causes section says 83.3% were hacking/IT incidents, which implies about 40 hacking breaches. So recent Julys have looked more like the upper 30s to around 40 hacking rows at point-in-time snapshots. (hipaajournal.com)
But 2026 has generally run hotter than those July baselines. The point-in-time monthly reports give 36 hacking breaches in January 2026, 57 in February, 61 in March, and 36 in April. Medcurity, using OCR portal data through June 5, reported 246 hacking/IT incidents out of 283 large 2026 breaches through June 5; because the official portal page currently shows five June 2-5 entries and all five are classified as Hacking/IT Incident, I infer that May contributed roughly 51 hacking rows by subtraction. That puts recent 2026 raw monthly hacking counts in a 36-61 range, with a center in the mid-to-high 40s before adjusting for duplicates and listing lag. (hipaajournal.com)
The resolution rule, however, counts unique breaches by entity + state + breach submission date, not raw rows. The official portal does sometimes contain duplicate rows for the same entity/state/date combination; for example, Gastro Health in Florida appears twice on 05/22/2026 on the current page. So I apply a small deduplication haircut rather than treating raw row counts as exact uniques. The duplicate rate does not look huge, so I only trim a little, roughly a couple of percent. (ocrportal.hhs.gov)
My model is therefore: start with a raw July 2026 hacking count in the mid-to-high 40s, trim slightly for deduplication, and then apply a visibility discount because the question resolves on August 12 rather than after all later backfills. The biggest uncertainty is that visibility discount. HHS says posting usually follows verification within about 14 days, but the current portal evidence suggests the public display is running meaningfully behind that ideal, so I expect a meaningful minority of late-July submissions to still be missing on August 12. Combining low/base/high scenarios for activity and posting lag gives me a mean near 38.25 and a median around 38, so I concentrate most probability in the mid-30s to low-40s, while still leaving non-trivial mass above 47 if July is unusually active and OCR catches up faster than I expect. (hhs.gov)
My point estimate is 34 unique breaches. The main structural issue is lag: for breaches affecting 500 or more individuals, HHS says covered entities must notify the Secretary without unreasonable delay and no later than 60 calendar days after discovery, and OCR says large breaches are posted only after OCR verifies the report, a process that generally takes about 14 days. So the August 12, 2026 resolution date is not measuring the eventual final July total; it is measuring a lagged portal snapshot. (hhs.gov)
For a base rate, the best official annual anchor is HHS’s 2024 report to Congress: OCR counted 663 breaches affecting 500 or more individuals that occurred in 2024, and 534 of them, or 81%, were Hacking/IT incidents. That is about 44.5 hacking breaches per month. Recent July analogs are somewhat lower than that annual average: HIPAA Journal’s July 2024 report counted 43 large breaches on its August 19 pull, with 36 hacking incidents, and noted that the total later rose to 49; its July 2025 report counted 48 large breaches, with 83.3% of them hacking-related, or about 40 hacking incidents. Those analogs suggest that a full-month July total in the low-40s for Hacking/IT is a reasonable starting point before applying any August 12 posting-lag discount. (hhs.gov)
The current 2026 portal state argues against assuming full July visibility by August 12. In the live HHS portal fetch on June 26, 2026, the newest visible Breach Submission Date in the Under Investigation list was June 5, 2026. Medcurity also noted on June 19 that the newest visible submission date was June 2, and its full pull through June 5 found 283 large-breach reports year to date, of which 246, or 87%, were Hacking/IT incidents. That keeps the hacking share high in 2026, but it also shows that publication lag is still material. I also apply a small deduplication haircut because this market resolves on unique Name-State-Date triplets, and the live portal already shows at least one same-triplet duplicate example in May 2026, namely Gastro Health in Florida on 05/22/2026 appearing twice. (ocrportal.hhs.gov)
My quantitative model is a weighted blend of three anchors for the full-month July 2026 Hacking/IT total: 50% weight on the official 2024 monthly average of 44.5, 30% weight on the 2026 pace through June 5 of about 47.63 hacking breaches per month, and 20% weight on the July 2025 analog of about 40. That gives a full-month baseline of 44.54 Hacking/IT breaches. I then infer that about 78% of July submissions will be visible by August 12, given HHS’s stated roughly 14-day verification norm but the slower live-portal cadence observed in June 2026; finally I trim 2% for duplicate-triplet risk. The arithmetic gives 34.05, which I round to a point forecast of 34. (hhs.gov)
For the distribution, I used an overdispersed negative binomial rather than a Poisson, because uncertainty here is dominated by two regime questions: how many July hacking breaches are actually submitted, and how much of late July OCR has posted by August 12. That leaves most of my probability mass in roughly the high 20s through low 40s, with a small but real right tail above 47 if July is unusually busy and OCR posting runs faster than the June evidence suggests. Conversely, a result in the low 20s would most likely require both a softer-than-recent July and slower-than-expected posting into the portal.