Healthcare Data Breach Statistics

35 STATS13 SOURCES

In 2025, Financial Services had 739 compromises; Healthcare had 534 compromises; Professional Services had 478 compromises; Manufacturing had 299 compromises; Education had 188 compromises (2025)

Identity Theft Resource CenterIdentity Theft Resource Center 2025 Annual Data Breach Report: Record Number of Data Compromises in 2025; 79 Percent Jump Over Five Years.html·Jan 28, 2026
Industry BreachesFinancial ServicesHealthcare

16% of email-related healthcare breaches in 2025 involved business associates.

PauboxHealthcare's email security certificate crisis·Jan 7, 2026
HealthcareHealthcare Data Breaches

43.3% of healthcare email breaches involved Microsoft 365.

Paubox2025 healthcare email security report·Dec 1, 2025
Email SecurityEmail BreachHealthcareMicrosoft 365

IT leaders estimate only 5% of known phishing attacks are reported by healthcare employees to their security teams.

Paubox2025 healthcare email security report·Dec 1, 2025
Email SecurityEmail BreachHealthcarePhishing

There was a 264% increased surge of ransomware attacks on healthcare organizations.

Paubox2025 healthcare email security report·Dec 1, 2025
Email SecurityEmail BreachHealthcareRansomware

Barracuda, Mimecast, and Proofpoint account for 26.7% of healthcare email breaches in 2024.

Paubox2025 healthcare email security report·Dec 1, 2025
Email SecurityEmail BreachHealthcare

1.1% of healthcare organizations analyzed had a 'Low Risk' email security posture.

Paubox2025 healthcare email security report·Dec 1, 2025
Email SecurityEmail BreachHealthcareEmail Security Posture

68.8% of healthcare organizations analyzed had a 'Medium Risk' email security posture.

Paubox2025 healthcare email security report·Dec 1, 2025
Email SecurityEmail BreachHealthcareEmail Security Posture

31.1% of healthcare organizations analyzed had a 'High Risk' email security posture.

Paubox2025 healthcare email security report·Dec 1, 2025
Email SecurityEmail BreachHealthcareEmail Security Posture

107 email-related HIPAA breaches were reported to the Department of Health and Human Services in just the first half of 2025.

PauboxWhat healthcare gets wrong about HIPAA and email security·Nov 10, 2025
HealthcareHIPAA breachEmail

In one enforcement case, a clinic was fined $25,000 for a single message that contained protected health information (PHI) and was sent to the wrong person without encryption

PauboxWhat healthcare gets wrong about HIPAA and email security·Nov 10, 2025
HealthcareEmailPHIHIPAA breach

17% of insider incidents involved personal healthcare information.

Fortinet2025 Insider Risk Report·Oct 16, 2025
Insider riskData lossHealthcare information

96% of healthcare organizations researched had at least two data loss or exfiltration incidents involving sensitive and confidential healthcare data in the past two years.

Proofpoint2025 Ponemon Healthcare Cybersecurity Report ·Oct 8, 2025
HealthcareExfiltrationData lossConfidential dataSensitive data

On average, healthcare organizations experienced 18 data loss or exfiltration incidents in the past two years.

Proofpoint2025 Ponemon Healthcare Cybersecurity Report ·Oct 8, 2025
HealthcareExfiltrationData loss

36% of healthcare organizations that experienced data loss or exfiltration incidents say it caused delays in procedures and tests that resulted in poor outcomes.

Proofpoint2025 Ponemon Healthcare Cybersecurity Report ·Oct 8, 2025
HealthcareExfiltrationData lossCyber attack consequences

55% of healthcare organizations say data loss or exfiltration incidents impacted patient care.

Proofpoint2025 Ponemon Healthcare Cybersecurity Report ·Oct 8, 2025
HealthcareExfiltrationData lossCyber attack consequences

54% of healthcare organizations that experienced data loss or exfiltration incidents say it increased the mortality rate.

Proofpoint2025 Ponemon Healthcare Cybersecurity Report ·Oct 8, 2025
HealthcareExfiltrationData lossCyber attack consequences

Between 2019 and 2023, healthcare experienced large losses primarily from ransomware (57.1%), followed by data breaches (28.6%) and other causes (14.3%).

AXA XLCyber Claims Unveiled: A Focused Study on Trends, Threats, and Tailored Solutions·Sep 9, 2025
Cyber insuranceCyber claimsRansomwareData breachHealthcare

The 2025 breach at DaVita compromised over 900,000 patients' personal and clinical data.

CobaltState of Pentesting in Healthcare 2025·Sep 3, 2025
HealthcareBreach

Nearly half of healthcare email breaches stem from Microsoft 365 alone.

PauboxWhat small healthcare practices get wrong about HIPAA and email security·Aug 19, 2025
HealthcareEmailEmail breachesMicrosoft 365

In 2025, healthcare breaches took an average of 224 days to detect and another 84 days to contain—making it over 10 months total.

PauboxWhat small healthcare practices get wrong about HIPAA and email security·Aug 19, 2025
HealthcareData breachDetection

Vision Upright MRI faced a $5,000 fine plus two years of federal monitoring after a server breach exposed over 21,000 individuals' medical imaging records.

PauboxWhat small healthcare practices get wrong about HIPAA and email security·Aug 19, 2025
HealthcareData breach

Phishing attacks now account for over 70% of healthcare data breaches as of 2024.

PauboxWhat small healthcare practices get wrong about HIPAA and email security·Aug 19, 2025
HealthcareData breachPhishing

The healthcare sector experienced an average of two healthcare breaches per day in the first half of 2025.

Forescout2025H1 Threat Review·Aug 4, 2025
ThreatsHealthcareBreach

The healthcare sector saw a $2.35 million reduction in costs compared to 2024.

IBMCost of a Data Breach Report 2025·Jul 30, 2025
Data breachHealthcareData breach cost

Breaches across the healthcare sector take the longest to identify and contain at 279 days, which is more than 5 weeks longer than the global average of 241 days.

IBMCost of a Data Breach Report 2025·Jul 30, 2025
Data breachHealthcareDetect

Healthcare breaches remained the most expensive, averaging $7.42 million.

IBMCost of a Data Breach Report 2025·Jul 30, 2025
Data breachHealthcareData breach cost

More than half (56%) of healthcare leaders say outdated infrastructure would delay breach recovery.

Omega Systems2025 Healthcare IT Landscape Report·Jun 4, 2025
HealthcareData breachInfrastructure

Almost 25% of healthcare leaders acknowledge it could take up to a month to detect and contain a data breach.

Omega Systems2025 Healthcare IT Landscape Report·Jun 4, 2025
HealthcareData breachDetection

32% of healthcare organizations suffered a breach in the past 12 months.

LevelBlue2025 LevelBlue Spotlight Report for Healthcare ·Jun 4, 2025
HealthcareBreach

70% of patients say they would consider switching providers after a data breach.

Patient ProtectThe Economics of ePHI Exposure: A Long-Term Impact Model of Healthcare Data Breaches·Jun 3, 2025
HealthcareProtected health informationPHIData breach

The healthcare sector had the most third-party breaches (78) but a below-average rate of 32.2%.

SecurityScorecard2025 Global Third-Party Breach Report·Mar 26, 2025
Third-party BreachesHealthcare

43% of healthcare email breaches were tied to Microsoft 365.

Paubox 2025 Healthcare Email Security Report·Mar 13, 2025
Email securityData breachMicrosoft 365Healthcare

98.9% of breached organizations lacked MTA-STS protections.

Paubox 2025 Healthcare Email Security Report·Mar 13, 2025
Data breachHealthcare

Solara Medical Supplies' $9.76 million settlement was due to a phishing-related breach affecting 114,000 patient records.

Paubox 2025 Healthcare Email Security Report·Mar 13, 2025
Data breachPhishingHealthcare