
If you work in behavioral health, you have almost certainly heard someone mutter about the HIPAA “Wall of Shame.”
It is not a courtroom. It is not a fine. It is a public website.
And once your organization’s name is on it, Google never forgets.
What the Wall of Shame actually is
The nickname is unofficial. The list is not.
HHS Office for Civil Rights posts every reported breach of unsecured protected health information affecting 500 or more people. Covered entities and business associates must report those incidents. HHS must publish them.
Official list: https://ocrportal.hhs.gov/ocr/breach/breach_report_hip.jsf
HHS reporting page: https://www.hhs.gov/hipaa/for-professionals/breach-notification/breach-reporting/index.html
Each listing typically shows the organization, state, entity type, number of people affected, report date, type of incident, where the data lived, whether a vendor was involved, and a short description.
Recent reports still under investigation stay on the active list. Older and closed cases move to an archive. They are not deleted.
Breaches under 500 people still get reported to HHS. They do not appear on the public wall.
Why the numbers keep getting worse
Exact counts shift as OCR posts new reports. The pattern does not.
- Thousands of large breaches since 2009; cumulative people affected run into the hundreds of millions.
- Hacking / IT incidents now dominate — usually 80%+ of large reports, higher in 2026 snapshots.
- Business associates (billing, EHR, cloud, RCM) show up constantly. A clinic can run a tight shop and still land on the list because a vendor got hit.
- 2024 was warped by mega-incidents such as Change Healthcare. 2025 set records for number of large incidents.
Lost laptops used to be the story. Stolen credentials and ransomware are the story now.
Why this hits recovery harder
HIPAA is the floor. SUD treatment also lives under 42 CFR Part 2.
A leaked chart here is not “just another healthcare record.” It can include diagnosis, tox screens, MAT, relapse history, family involvement, or court-ordered care — things a person would never put on a job application.
People already delay treatment because they fear being labeled. A public breach notice confirms that fear.
What actually puts a program on the list
- No current, organization-wide risk analysis
- Vendors treated as someone else’s problem
- Email and stolen logins (no MFA)
- Unencrypted or poorly segmented systems
- Workforce shortcuts: wrong email, personal texting, paper left out
- “We’re too small” — specialty practices and small vendors are regular entries now
If you are a person in recovery
Ask how notes are stored and who can see them. Be careful with portal messages and unsecured email. Read breach letters if you get one. The portal confirms the public report. You can file an OCR complaint here: https://www.hhs.gov/hipaa/filing-a-complaint/index.html
If you run a program
Do a real Security Rule risk analysis. Inventory every business associate and ask how they handle Part 2, not just “HIPAA generally.” MFA everywhere PHI lives. Encrypt devices and backups. Train the boring stuff. Know the 60-day clock. Practice the incident before ransomware writes the script.
Privacy is not the opposite of good treatment. In this field it is part of treatment.
Official portal: https://ocrportal.hhs.gov/ocr/breach/breach_report_hip.jsf
Dr. Daniel J. Callahan, DSW
Happy Recovery
This article was drafted with the help of AI. I directed the topic, checked the facts, revised the language, and take responsibility for what is published here.