Paubox

110 stats11 reports

All Statistics

53% of email-related healthcare breaches occurred on Microsoft 365.

HealthcareEmail SecurityEmail RiskEmail BreachMicrosoft 365

Microsoft 365 is adopted by approximately 79% of healthcare organizations.

HealthcareEmail SecurityEmail RiskMicrosoft 365

74% of breached healthcare organizations lacked effective DMARC enforcement (41% missing entirely, 33% monitor-only).

HealthcareEmail SecurityEmail RiskDMARC

16% of email-related healthcare breaches in 2025 involved business associates.

HealthcareHealthcare Data Breaches

Approximately 3 million email addresses in the healthcare sector may be at risk of exposure to cyberattacks due to unverified email delivery practices.

Email SecurityHealthcare

Approximately 4.5% of outbound healthcare email connections were delivered to servers with expired or self-signed certificates.

Email SecurityHealthcare

68.8% of healthcare organizations analyzed had a 'Medium Risk' email security posture.

Email SecurityEmail BreachHealthcareEmail Security Posture

43.3% of healthcare email breaches involved Microsoft 365.

Email SecurityEmail BreachHealthcareMicrosoft 365

IT leaders estimate only 5% of known phishing attacks are reported by healthcare employees to their security teams.

Email SecurityEmail BreachHealthcarePhishing

107 email-related HIPAA breaches were reported to the Department of Health and Human Services in just the first half of 2025.

HealthcareHIPAA breachEmail

The current pace of healthcare breaches in 2025 suggests the year is set to exceed 180 email breaches, which was the total reported last year.

Healthcare

In one enforcement case, a clinic was fined $25,000 for a single message that contained protected health information (PHI) and was sent to the wrong person without encryption

HealthcareEmailPHIHIPAA breach

25% of healthcare organizations have not formally approved any staff use of AI in email.

HealthcareEmail securityAI

41% of healthcare IT and compliance leaders feel confident they could detect improper AI use before a HIPAA violation occurs.

HealthcareEmail securityAIHIPAACompliance

69% of healthcare IT leaders feel pressured to adopt AI faster than they can secure it.

HealthcareEmail securityAIAI securityCompliance

The sharp rise in Microsoft 365 email breaches in healthcare represents a 21% increase year-over-year.

HealthcareEmailMicrosoft

The Episource breach affected 5.4 million individuals

HealthcareEmail

The largest single email breach, affecting United Seating and Mobility, exposed over half a million records.

HealthcareEmail

98% of small healthcare practices claim their platforms "encrypt emails by default".

HealthcareEmailEmail encryption

Phishing attacks now account for over 70% of healthcare data breaches as of 2024.

HealthcareData breachPhishing

One-third of small healthcare practices report not having enough time for compliance tasks.

HealthcareCompliance

4 out of 5 rural healthcare leaders say their infrastructure cannot support advanced email security.

HealthcareEmail security

Rural healthcare organisations trail urban ones by 22% in adopting AI-based threat detection.

HealthcareAIThreat detection

6 out of 10 rural healthcare providers say their current secure email platform causes regular complaints and workflow delays.

HealthcareEmail

53% of healthcare IT leaders cited lack of vendor support as the most common barrier to adopting secure, compliant email solutions.

HealthcareEmail

54% of healthcare IT leaders cited implementation complexity as the most common barrier to adopting secure, compliant email solutions.

HealthcareEmail

86% of healthcare IT leaders say their current email security tools create workflow friction, causing staff to bypass security processes.

HealthcareEmailEmail security tools

60% of healthcare organizations surveyed experienced email-related security incidents last year that exposed sensitive patient data.

EmailEmail threatsHealthcare

Only 5% of known phishing attacks are reported to healthcare security teams.

PhishingHealthcare

Only 4% of known HIPAA email violations are reported to healthcare security teams.

EmailHIPAA violationHealthcare

Less than one-fifth of total healthcare email incidents involved identity abuse via stolen credentials, yet these remained the most damaging type of attack.

HealthcareIdentity AbuseStolen Login CredentialsEmail SecurityEmail Attack

Stolen login credentials led to the most damaging email-related healthcare breaches in 2025, exposing more than 630,000 patient records.

HealthcareEmail SecurityEmail AttackStolen Login CredentialsExposed Healthcare Data

Approximately 17% of healthcare email breaches were the result of phishing-driven mailbox takeovers.

HealthcareEmail SecurityEmail AttackPhishing

56% of breached healthcare organizations had permissive or missing SPF records (9% missing, 46% soft fail).

HealthcareEmail SecurityEmail RiskSPF Records

31% of breached Microsoft 365 healthcare organizations were classified as High Risk.

HealthcareEmail SecurityEmail RiskMicrosoft 365

170 email-related healthcare breaches occured in 2025.

HealthcareEmail SecurityEmail RiskEmail Breach

41% of breached healthcare organizations fell into a high-risk category based on their email configuration, up from 31% in 2024.

HealthcareEmail SecurityEmail RiskEmail Configuration

Proofpoint, Barracuda and Mimecast accounted for 19% of email healthcare breaches in 2025.

HealthcareEmail BreachMimecastProofpointBarracuda

85% of healthcare IT leaders said they suspected staff were using unauthorized AI tools.

HealthcareUnauthorized AI

Only 26% of healthcare IT leaders reported having visibility into staff usage of unauthorized AI tools.

HealthcareUnauthorized AI

There was a 264% increased surge of ransomware attacks on healthcare organizations.

Email SecurityEmail BreachHealthcareRansomware

Barracuda, Mimecast, and Proofpoint account for 26.7% of healthcare email breaches in 2024.

Email SecurityEmail BreachHealthcare

1.1% of healthcare organizations analyzed had a 'Low Risk' email security posture.

Email SecurityEmail BreachHealthcareEmail Security Posture

31.1% of healthcare organizations analyzed had a 'High Risk' email security posture.

Email SecurityEmail BreachHealthcareEmail Security Posture

94% of healthcare organizations have begun updating security policies to address generative AI threats in email.

HealthcareEmail securityAIAI policy

16% of healthcare IT and compliance leaders admit compliance was never consulted before AI email tools were enabled.

HealthcareEmail securityAICompliance

75% of healthcare organizations say AI has added confusion, not clarity, to email compliance.

HealthcareEmail securityAICompliance

58% of healthcare organizations have not signed a BAA for an AI email tool so far.

HealthcareEmail securityAIBAA

Only 16% of healthcare organizations have trained most of their staff (75-100%) who have access to PHI on AI usage in email.

HealthcareEmail securityAIPHITraining

21% of respondents from healthcare organizations believe a Business Associate Agreement (BAA) isn’t required for an AI email assistant.

HealthcareEmail securityAIBAA