Paubox

91 STATS10 REPORTS

All Statistics

16% of email-related healthcare breaches in 2025 involved business associates.

PauboxHealthcare's email security certificate crisis·Jan 7, 2026
HealthcareHealthcare Data Breaches

Approximately 4.5% of outbound healthcare email connections were delivered to servers with expired or self-signed certificates.

PauboxHealthcare's email security certificate crisis·Jan 7, 2026
Email SecurityHealthcare

Approximately 3 million email addresses in the healthcare sector may be at risk of exposure to cyberattacks due to unverified email delivery practices.

PauboxHealthcare's email security certificate crisis·Jan 7, 2026
Email SecurityHealthcare

43.3% of healthcare email breaches involved Microsoft 365.

Paubox2025 healthcare email security report·Dec 1, 2025
Email SecurityEmail BreachHealthcareMicrosoft 365

IT leaders estimate only 5% of known phishing attacks are reported by healthcare employees to their security teams.

Paubox2025 healthcare email security report·Dec 1, 2025
Email SecurityEmail BreachHealthcarePhishing

There was a 264% increased surge of ransomware attacks on healthcare organizations.

Paubox2025 healthcare email security report·Dec 1, 2025
Email SecurityEmail BreachHealthcareRansomware

Barracuda, Mimecast, and Proofpoint account for 26.7% of healthcare email breaches in 2024.

Paubox2025 healthcare email security report·Dec 1, 2025
Email SecurityEmail BreachHealthcare

1.1% of healthcare organizations analyzed had a 'Low Risk' email security posture.

Paubox2025 healthcare email security report·Dec 1, 2025
Email SecurityEmail BreachHealthcareEmail Security Posture

68.8% of healthcare organizations analyzed had a 'Medium Risk' email security posture.

Paubox2025 healthcare email security report·Dec 1, 2025
Email SecurityEmail BreachHealthcareEmail Security Posture

31.1% of healthcare organizations analyzed had a 'High Risk' email security posture.

Paubox2025 healthcare email security report·Dec 1, 2025
Email SecurityEmail BreachHealthcareEmail Security Posture

107 email-related HIPAA breaches were reported to the Department of Health and Human Services in just the first half of 2025.

PauboxWhat healthcare gets wrong about HIPAA and email security·Nov 10, 2025
HealthcareHIPAA breachEmail

The current pace of healthcare breaches in 2025 suggests the year is set to exceed 180 email breaches, which was the total reported last year.

PauboxWhat healthcare gets wrong about HIPAA and email security·Nov 10, 2025
Healthcare

In one enforcement case, a clinic was fined $25,000 for a single message that contained protected health information (PHI) and was sent to the wrong person without encryption

PauboxWhat healthcare gets wrong about HIPAA and email security·Nov 10, 2025
HealthcareEmailPHIHIPAA breach

25% of healthcare organizations have not formally approved any staff use of AI in email.

PauboxShadow AI is outpacing healthcare email security·Oct 14, 2025
HealthcareEmail securityAI

94% of healthcare organizations have begun updating security policies to address generative AI threats in email.

PauboxShadow AI is outpacing healthcare email security·Oct 14, 2025
HealthcareEmail securityAIAI policy

69% of healthcare IT leaders feel pressured to adopt AI faster than they can secure it.

PauboxShadow AI is outpacing healthcare email security·Oct 14, 2025
HealthcareEmail securityAIAI securityCompliance

75% of healthcare organizations say AI has added confusion, not clarity, to email compliance.

PauboxShadow AI is outpacing healthcare email security·Oct 14, 2025
HealthcareEmail securityAICompliance

58% of healthcare organizations have not signed a BAA for an AI email tool so far.

PauboxShadow AI is outpacing healthcare email security·Oct 14, 2025
HealthcareEmail securityAIBAA

Only 16% of healthcare organizations have trained most of their staff (75-100%) who have access to PHI on AI usage in email.

PauboxShadow AI is outpacing healthcare email security·Oct 14, 2025
HealthcareEmail securityAIPHITraining

62% of healthcare IT and compliance leaders have observed staff experimenting with ChatGPT or similar tools even though they’re unsanctioned.

PauboxShadow AI is outpacing healthcare email security·Oct 14, 2025
HealthcareEmail securityAIComplianceChatGPT

21% of respondents from healthcare organizations believe a Business Associate Agreement (BAA) isn’t required for an AI email assistant.

PauboxShadow AI is outpacing healthcare email security·Oct 14, 2025
HealthcareEmail securityAIBAA

95% of healthcare organizations report staff are already using AI tools.

PauboxShadow AI is outpacing healthcare email security·Oct 14, 2025
HealthcareEmail securityAI

83% of healthcare IT and compliance leaders have raised concerns about AI security.

PauboxShadow AI is outpacing healthcare email security·Oct 14, 2025
HealthcareEmail securityAIAI security

16% of healthcare IT and compliance leaders admit compliance was never consulted before AI email tools were enabled.

PauboxShadow AI is outpacing healthcare email security·Oct 14, 2025
HealthcareEmail securityAICompliance

41% of healthcare IT and compliance leaders feel confident they could detect improper AI use before a HIPAA violation occurs.

PauboxShadow AI is outpacing healthcare email security·Oct 14, 2025
HealthcareEmail securityAIHIPAACompliance

Only 42% of healthcare organizations have signed a Business Associate Agreement (BAA) covering any AI assistant used in email.

PauboxShadow AI is outpacing healthcare email security·Oct 14, 2025
HealthcareEmail securityAIBAA

The largest single email breach, affecting United Seating and Mobility, exposed over half a million records.

Paubox2025 mid-year email breach data reveals there's no slowing down·Sep 5, 2025
HealthcareEmail

More than 1.6 million patient records were compromised across all analysed email-related healthcare incidents that occurred in the first half of 2025.

Paubox2025 mid-year email breach data reveals there's no slowing down·Sep 5, 2025
HealthcareEmail

Incidents involving Mimecast email customers accounted for 8% in healthcare.

Paubox2025 mid-year email breach data reveals there's no slowing down·Sep 5, 2025
HealthcareEmailMimecast

Incidents involving Barracuda email customers accounted for 5% in healthcare.

Paubox2025 mid-year email breach data reveals there's no slowing down·Sep 5, 2025
HealthcareEmailBarracuda

79% of breached healthcare organizations have ineffective DMARC protection. This is up dramatically from 65% in 2024.

Paubox2025 mid-year email breach data reveals there's no slowing down·Sep 5, 2025
HealthcareEmailDMARC

Incidents involving Proofpoint email customers accounted for 6% in healthcare.

Paubox2025 mid-year email breach data reveals there's no slowing down·Sep 5, 2025
HealthcareEmailProofpoint

Business associates (including billing vendors, imaging firms, and outsourced IT providers) were involved in 17 of the 107 email-related breaches in healthcare. This represents 16% of all incidents.

Paubox2025 mid-year email breach data reveals there's no slowing down·Sep 5, 2025
HealthcareEmailThird-party risk

41% of healthcare organizations are now classified as high-risk. This compares to just 31% last year.

Paubox2025 mid-year email breach data reveals there's no slowing down·Sep 5, 2025
HealthcareEmail

Cyberattacks are cited as the leading cause of critical workflow disruptions by 50% of healthcare organizations.

Paubox2025 mid-year email breach data reveals there's no slowing down·Sep 5, 2025
HealthcareEmail

IT leaders estimate that only 5% of known phishing attacks in healthcare are actually reported by employees to security teams.

Paubox2025 mid-year email breach data reveals there's no slowing down·Sep 5, 2025
HealthcareEmailPhishingSecurity awareness training

The sharp rise in Microsoft 365 email breaches in healthcare represents a 21% increase year-over-year.

Paubox2025 mid-year email breach data reveals there's no slowing down·Sep 5, 2025
HealthcareEmailMicrosoft

The Episource breach affected 5.4 million individuals

Paubox2025 mid-year email breach data reveals there's no slowing down·Sep 5, 2025
HealthcareEmail

81% of healthcare email breaches were classified as hacking or IT incidents.

Paubox2025 mid-year email breach data reveals there's no slowing down·Sep 5, 2025
HealthcareEmail

Microsoft 365 environments now account for 52% of all healthcare email breaches. This represents a dramatic surge from 43% just one year ago.

Paubox2025 mid-year email breach data reveals there's no slowing down·Sep 5, 2025
HealthcareEmailMicrosoft

The average healthcare email breach exposed nearly 16,000 individual records in the first half of 2025.

Paubox2025 mid-year email breach data reveals there's no slowing down·Sep 5, 2025
HealthcareEmail

More than 80% of small healthcare practices expressed confidence in their current HIPAA compliance posture.

PauboxWhat small healthcare practices get wrong about HIPAA and email security·Aug 19, 2025
HealthcareComplianceHIPAA

Nearly half of healthcare email breaches stem from Microsoft 365 alone.

PauboxWhat small healthcare practices get wrong about HIPAA and email security·Aug 19, 2025
HealthcareEmailEmail breachesMicrosoft 365

In 2025, healthcare breaches took an average of 224 days to detect and another 84 days to contain—making it over 10 months total.

PauboxWhat small healthcare practices get wrong about HIPAA and email security·Aug 19, 2025
HealthcareData breachDetection

Vision Upright MRI faced a $5,000 fine plus two years of federal monitoring after a server breach exposed over 21,000 individuals' medical imaging records.

PauboxWhat small healthcare practices get wrong about HIPAA and email security·Aug 19, 2025
HealthcareData breach

43% of small healthcare organisations reported experiencing a phishing or spoofing incident in the past year.

PauboxWhat small healthcare practices get wrong about HIPAA and email security·Aug 19, 2025
HealthcarePhishingSpoofing

83% of small healthcare practices believe patient consent removes the need for encryption.

PauboxWhat small healthcare practices get wrong about HIPAA and email security·Aug 19, 2025
HealthcareEncryption

Solara Medical faced a $9.76 million class-action settlement following a phishing attack.

PauboxWhat small healthcare practices get wrong about HIPAA and email security·Aug 19, 2025
HealthcarePhishing

64% of small healthcare practices believe patient portals are required for HIPAA compliance.

PauboxWhat small healthcare practices get wrong about HIPAA and email security·Aug 19, 2025
HealthcareComplianceHIPAA

20% of healthcare practices do not utilise any form of email archiving or audit trail.

PauboxWhat small healthcare practices get wrong about HIPAA and email security·Aug 19, 2025
HealthcareEmailCompliance