Healthcare Code Compliance Security Index 2026

The first large-scale analysis of code-level compliance across 3,000 healthcare repositories

3,000+

Repos Scanned

13,427

Confirmed Violations

6,861

Critical Severity

43.6%

Repos with Violations

Published March 26, 2026 by Scrutora

Confirmed violations across every compliance framework

HIPAA

42.8%

With Violations

1,285 repos

GDPR

43.5%

With Violations

1,304 repos

SOC 2

43.6%

With Violations

1,309 repos

DPDPA

43.6%

With Violations

1,309 repos

Grade distribution across all scanned repositories

A+/A 59.4%
B/C 16.8%
D/F 23.7%
PassingFailing

What we found

๐Ÿ‡ฎ๐Ÿ‡ณ

DIVOC

India

National vaccination platform logs Aadhaar numbers, names, DOB, gender, phone, and home address to plaintext application logs for every certificate issued

CRITICAL
๐Ÿ‡บ๐Ÿ‡ธ

VA notification-api

US

Veterans Affairs SMS system disables TLS verification with explicit security warning suppression

CRITICAL
๐Ÿ‡บ๐Ÿ‡ธ

OpenEMR

US

Most deployed open-source EMR exports patient SSNs to plaintext CSV files with zero encryption

CRITICAL
๐Ÿ‡บ๐Ÿ‡ธ

Metriport

US

Patient medical records sent to AI model without de-identification or tokenization

HIGH
๐Ÿ‡ฌ๐Ÿ‡ง

OpenSAFELY

UK

NHS research platform disables TLS for queries across 58 million patient records

CRITICAL

These are five examples from a much larger dataset. The full report documents verified findings across 15+ named repositories, including:

GoogleCDCCMSUS Veterans AffairsOpenEMRMirth Connect (NextGen)NHS DigitalIBMOpenSAFELYOpenCRVSLibreHealthERPNextABDMDIVOCMetriport

Each finding includes exact file paths, line numbers, severity classifications, and compliance mappings across HIPAA, GDPR, SOC 2, and DPDPA.

Additional findings across healthcare repositories in the US, UK, EU, India, and sub-Saharan Africa are currently undergoing validation and will be published in subsequent editions of the Index.

Methodology

9

Languages

Python, JavaScript, TypeScript, Java, C#, Swift, Kotlin, Go, PHP

4

Frameworks

HIPAA, GDPR, SOC 2, DPDPA

240+

Checks

Across 310+ rules mapped to specific regulatory sections

Figures reflect the scanner configuration at the time of this study (March 2026) and are deliberately frozen. Scrutora now covers 26 frameworks, 12 languages and 310+ rules across code, IaC and cloud.

All repositories were analyzed using AST-based static analysis, mapping code patterns to specific regulatory requirements. The scanner identifies compliance gaps at the code level: unencrypted PHI exports, missing audit trails, weak authentication, PHI in application logs, and unprotected data flows to AI/ML pipelines. Full methodology, including false positive suppression and taint tracking details, is documented in the report.

Access the full report

The full report contains technical details not published on this page: complete findings for all 15+ repositories including file paths, line numbers, and framework citations. Methodology documentation covering AST parsing, taint tracking, and false positive suppression. CERT-In correspondence timeline. Vendor responses received. Scoring breakdown for all repositories including top performers.

We will only use your email to send the report. No spam.

Published by Scrutora

All affected organizations were notified through responsible disclosure prior to publication.