Healthcare Data Breach Statistics

35 STATS13 SOURCES

In 2025, Financial Services had 739 compromises; Healthcare had 534 compromises; Professional Services had 478 compromises; Manufacturing had 299 compromises; Education had 188 compromises (2025)

Industry BreachesFinancial ServicesHealthcare

16% of email-related healthcare breaches in 2025 involved business associates.

HealthcareHealthcare Data Breaches

43.3% of healthcare email breaches involved Microsoft 365.

Email SecurityEmail BreachHealthcareMicrosoft 365

IT leaders estimate only 5% of known phishing attacks are reported by healthcare employees to their security teams.

Email SecurityEmail BreachHealthcarePhishing

There was a 264% increased surge of ransomware attacks on healthcare organizations.

Email SecurityEmail BreachHealthcareRansomware

Barracuda, Mimecast, and Proofpoint account for 26.7% of healthcare email breaches in 2024.

Email SecurityEmail BreachHealthcare

1.1% of healthcare organizations analyzed had a 'Low Risk' email security posture.

Email SecurityEmail BreachHealthcareEmail Security Posture

68.8% of healthcare organizations analyzed had a 'Medium Risk' email security posture.

Email SecurityEmail BreachHealthcareEmail Security Posture

31.1% of healthcare organizations analyzed had a 'High Risk' email security posture.

Email SecurityEmail BreachHealthcareEmail Security Posture

107 email-related HIPAA breaches were reported to the Department of Health and Human Services in just the first half of 2025.

HealthcareHIPAA breachEmail

In one enforcement case, a clinic was fined $25,000 for a single message that contained protected health information (PHI) and was sent to the wrong person without encryption

HealthcareEmailPHIHIPAA breach

17% of insider incidents involved personal healthcare information.

Fortinet2025 Insider Risk Report·7mo ago
Insider riskData lossHealthcare information

96% of healthcare organizations researched had at least two data loss or exfiltration incidents involving sensitive and confidential healthcare data in the past two years.

HealthcareExfiltrationData lossConfidential dataSensitive data

On average, healthcare organizations experienced 18 data loss or exfiltration incidents in the past two years.

HealthcareExfiltrationData loss

36% of healthcare organizations that experienced data loss or exfiltration incidents say it caused delays in procedures and tests that resulted in poor outcomes.

HealthcareExfiltrationData lossCyber attack consequences

55% of healthcare organizations say data loss or exfiltration incidents impacted patient care.

HealthcareExfiltrationData lossCyber attack consequences

54% of healthcare organizations that experienced data loss or exfiltration incidents say it increased the mortality rate.

HealthcareExfiltrationData lossCyber attack consequences

Between 2019 and 2023, healthcare experienced large losses primarily from ransomware (57.1%), followed by data breaches (28.6%) and other causes (14.3%).

Cyber insuranceCyber claimsRansomwareData breachHealthcare

The 2025 breach at DaVita compromised over 900,000 patients' personal and clinical data.

HealthcareBreach

Nearly half of healthcare email breaches stem from Microsoft 365 alone.

HealthcareEmailEmail breachesMicrosoft 365

In 2025, healthcare breaches took an average of 224 days to detect and another 84 days to contain—making it over 10 months total.

HealthcareData breachDetection

Vision Upright MRI faced a $5,000 fine plus two years of federal monitoring after a server breach exposed over 21,000 individuals' medical imaging records.

HealthcareData breach

Phishing attacks now account for over 70% of healthcare data breaches as of 2024.

HealthcareData breachPhishing

The healthcare sector experienced an average of two healthcare breaches per day in the first half of 2025.

Forescout2025H1 Threat Review·9mo ago
ThreatsHealthcareBreach

The healthcare sector saw a $2.35 million reduction in costs compared to 2024.

Data breachHealthcareData breach cost

Breaches across the healthcare sector take the longest to identify and contain at 279 days, which is more than 5 weeks longer than the global average of 241 days.

Data breachHealthcareDetect

Healthcare breaches remained the most expensive, averaging $7.42 million.

Data breachHealthcareData breach cost

More than half (56%) of healthcare leaders say outdated infrastructure would delay breach recovery.

HealthcareData breachInfrastructure

Almost 25% of healthcare leaders acknowledge it could take up to a month to detect and contain a data breach.

HealthcareData breachDetection

32% of healthcare organizations suffered a breach in the past 12 months.

HealthcareBreach

70% of patients say they would consider switching providers after a data breach.

HealthcareProtected health informationPHIData breach

The healthcare sector had the most third-party breaches (78) but a below-average rate of 32.2%.

SecurityScorecard2025 Global Third-Party Breach Report·1y ago
Third-party BreachesHealthcare

43% of healthcare email breaches were tied to Microsoft 365.

Email securityData breachMicrosoft 365Healthcare

98.9% of breached organizations lacked MTA-STS protections.

Data breachHealthcare

Solara Medical Supplies' $9.76 million settlement was due to a phishing-related breach affecting 114,000 patient records.

Data breachPhishingHealthcare