Paubox

111 stats11 reports

All Statistics

170 email-related healthcare breaches occured in 2025.

HealthcareEmail SecurityEmail RiskEmail Breach

53% of email-related healthcare breaches occurred on Microsoft 365.

HealthcareEmail SecurityEmail RiskEmail BreachMicrosoft 365

Microsoft 365 is adopted by approximately 79% of healthcare organizations.

HealthcareEmail SecurityEmail RiskMicrosoft 365

16% of email-related healthcare breaches in 2025 involved business associates.

HealthcareHealthcare Data Breaches

Approximately 3 million email addresses in the healthcare sector may be at risk of exposure to cyberattacks due to unverified email delivery practices.

Email SecurityHealthcare

Approximately 4.5% of outbound healthcare email connections were delivered to servers with expired or self-signed certificates.

Email SecurityHealthcare

43.3% of healthcare email breaches involved Microsoft 365.

Email SecurityEmail BreachHealthcareMicrosoft 365

IT leaders estimate only 5% of known phishing attacks are reported by healthcare employees to their security teams.

Email SecurityEmail BreachHealthcarePhishing

There was a 264% increased surge of ransomware attacks on healthcare organizations.

Email SecurityEmail BreachHealthcareRansomware

107 email-related HIPAA breaches were reported to the Department of Health and Human Services in just the first half of 2025.

HealthcareHIPAA breachEmail

The current pace of healthcare breaches in 2025 suggests the year is set to exceed 180 email breaches, which was the total reported last year.

Healthcare

In one enforcement case, a clinic was fined $25,000 for a single message that contained protected health information (PHI) and was sent to the wrong person without encryption

HealthcareEmailPHIHIPAA breach

25% of healthcare organizations have not formally approved any staff use of AI in email.

HealthcareEmail securityAI

69% of healthcare IT leaders feel pressured to adopt AI faster than they can secure it.

HealthcareEmail securityAIAI securityCompliance

94% of healthcare organizations have begun updating security policies to address generative AI threats in email.

HealthcareEmail securityAIAI policy

The largest single email breach, affecting United Seating and Mobility, exposed over half a million records.

HealthcareEmail

The sharp rise in Microsoft 365 email breaches in healthcare represents a 21% increase year-over-year.

HealthcareEmailMicrosoft

The Episource breach affected 5.4 million individuals

HealthcareEmail

More than 80% of small healthcare practices expressed confidence in their current HIPAA compliance posture.

HealthcareComplianceHIPAA

83% of small healthcare practices believe patient consent removes the need for encryption.

HealthcareEncryption

Nearly half of healthcare email breaches stem from Microsoft 365 alone.

HealthcareEmailEmail breachesMicrosoft 365

4 out of 5 rural healthcare leaders say their infrastructure cannot support advanced email security.

HealthcareEmail security

Rural healthcare organisations trail urban ones by 22% in adopting AI-based threat detection.

HealthcareAIThreat detection

6 out of 10 rural healthcare providers say their current secure email platform causes regular complaints and workflow delays.

HealthcareEmail

53% of healthcare IT leaders cited lack of vendor support as the most common barrier to adopting secure, compliant email solutions.

HealthcareEmail

54% of healthcare IT leaders cited implementation complexity as the most common barrier to adopting secure, compliant email solutions.

HealthcareEmail

86% of healthcare IT leaders say their current email security tools create workflow friction, causing staff to bypass security processes.

HealthcareEmailEmail security tools

Only 4% of known HIPAA email violations are reported to healthcare security teams.

EmailHIPAA violationHealthcare

60% of healthcare IT leaders reported email security breaches or security incidents last year.

EmailEmail threatsHealthcare

60% of healthcare organizations surveyed experienced email-related security incidents last year that exposed sensitive patient data.

EmailEmail threatsHealthcare

Stolen login credentials led to the most damaging email-related healthcare breaches in 2025, exposing more than 630,000 patient records.

HealthcareEmail SecurityEmail AttackStolen Login CredentialsExposed Healthcare Data

Approximately 17% of healthcare email breaches were the result of phishing-driven mailbox takeovers.

HealthcareEmail SecurityEmail AttackPhishing

Less than one-fifth of total healthcare email incidents involved identity abuse via stolen credentials, yet these remained the most damaging type of attack.

HealthcareIdentity AbuseStolen Login CredentialsEmail SecurityEmail Attack

74% of breached healthcare organizations lacked effective DMARC enforcement (41% missing entirely, 33% monitor-only).

HealthcareEmail SecurityEmail RiskDMARC

56% of breached healthcare organizations had permissive or missing SPF records (9% missing, 46% soft fail).

HealthcareEmail SecurityEmail RiskSPF Records

31% of breached Microsoft 365 healthcare organizations were classified as High Risk.

HealthcareEmail SecurityEmail RiskMicrosoft 365

41% of breached healthcare organizations fell into a high-risk category based on their email configuration, up from 31% in 2024.

HealthcareEmail SecurityEmail RiskEmail Configuration

Proofpoint, Barracuda and Mimecast accounted for 19% of email healthcare breaches in 2025.

HealthcareEmail BreachMimecastProofpointBarracuda

85% of healthcare IT leaders said they suspected staff were using unauthorized AI tools.

HealthcareUnauthorized AI

Only 26% of healthcare IT leaders reported having visibility into staff usage of unauthorized AI tools.

HealthcareUnauthorized AI

Barracuda, Mimecast, and Proofpoint account for 26.7% of healthcare email breaches in 2024.

Email SecurityEmail BreachHealthcare

1.1% of healthcare organizations analyzed had a 'Low Risk' email security posture.

Email SecurityEmail BreachHealthcareEmail Security Posture

68.8% of healthcare organizations analyzed had a 'Medium Risk' email security posture.

Email SecurityEmail BreachHealthcareEmail Security Posture

31.1% of healthcare organizations analyzed had a 'High Risk' email security posture.

Email SecurityEmail BreachHealthcareEmail Security Posture

16% of healthcare IT and compliance leaders admit compliance was never consulted before AI email tools were enabled.

HealthcareEmail securityAICompliance

75% of healthcare organizations say AI has added confusion, not clarity, to email compliance.

HealthcareEmail securityAICompliance

58% of healthcare organizations have not signed a BAA for an AI email tool so far.

HealthcareEmail securityAIBAA

Only 16% of healthcare organizations have trained most of their staff (75-100%) who have access to PHI on AI usage in email.

HealthcareEmail securityAIPHITraining

21% of respondents from healthcare organizations believe a Business Associate Agreement (BAA) isn’t required for an AI email assistant.

HealthcareEmail securityAIBAA

83% of healthcare IT and compliance leaders have raised concerns about AI security.

HealthcareEmail securityAIAI security