Healthcare Code Compliance Security Index 2026
The first large-scale analysis of code-level compliance across 3,000 healthcare repositories
3,000+
Repos Scanned
13,427
Confirmed Violations
6,861
Critical Severity
43.6%
Repos with Violations
Published March 26, 2026 by Scrutora
Confirmed violations across every compliance framework
HIPAA
42.8%
With Violations
1,285 repos
GDPR
43.5%
With Violations
1,304 repos
SOC 2
43.6%
With Violations
1,309 repos
DPDPA
43.6%
With Violations
1,309 repos
Grade distribution across all scanned repositories
What we found
DIVOC
India
National vaccination platform logs Aadhaar numbers, names, DOB, gender, phone, and home address to plaintext application logs for every certificate issued
CRITICALVA notification-api
US
Veterans Affairs SMS system disables TLS verification with explicit security warning suppression
CRITICALOpenEMR
US
Most deployed open-source EMR exports patient SSNs to plaintext CSV files with zero encryption
CRITICALMetriport
US
Patient medical records sent to AI model without de-identification or tokenization
HIGHOpenSAFELY
UK
NHS research platform disables TLS for queries across 58 million patient records
CRITICALThese are five examples from a much larger dataset. The full report documents verified findings across 15+ named repositories, including:
Each finding includes exact file paths, line numbers, severity classifications, and compliance mappings across HIPAA, GDPR, SOC 2, and DPDPA.
Additional findings across healthcare repositories in the US, UK, EU, India, and sub-Saharan Africa are currently undergoing validation and will be published in subsequent editions of the Index.
Methodology
9
Languages
Python, JavaScript, TypeScript, Java, C#, Swift, Kotlin, Go, PHP
4
Frameworks
HIPAA, GDPR, SOC 2, DPDPA
240+
Checks
Across 310+ rules mapped to specific regulatory sections
Figures reflect the scanner configuration at the time of this study (March 2026) and are deliberately frozen. Scrutora now covers 26 frameworks, 12 languages and 310+ rules across code, IaC and cloud.
All repositories were analyzed using AST-based static analysis, mapping code patterns to specific regulatory requirements. The scanner identifies compliance gaps at the code level: unencrypted PHI exports, missing audit trails, weak authentication, PHI in application logs, and unprotected data flows to AI/ML pipelines. Full methodology, including false positive suppression and taint tracking details, is documented in the report.
Access the full report
The full report contains technical details not published on this page: complete findings for all 15+ repositories including file paths, line numbers, and framework citations. Methodology documentation covering AST parsing, taint tracking, and false positive suppression. CERT-In correspondence timeline. Vendor responses received. Scoring breakdown for all repositories including top performers.
Published by Scrutora
All affected organizations were notified through responsible disclosure prior to publication.