Report by Paubox
2025 Healthcare Email Security Report
Key Findings
43.3% of healthcare email breaches involved Microsoft 365.
IT leaders estimate only 5% of known phishing attacks are reported by healthcare employees to their security teams.
There was a 264% increased surge of ransomware attacks on healthcare organizations.
Barracuda, Mimecast, and Proofpoint account for 26.7% of healthcare email breaches in 2024.
1.1% of healthcare organizations analyzed had a 'Low Risk' email security posture.
68.8% of healthcare organizations analyzed had a 'Medium Risk' email security posture.
31.1% of healthcare organizations analyzed had a 'High Risk' email security posture.
43% of healthcare email breaches were tied to Microsoft 365.
98.9% of breached organizations lacked MTA-STS protections.
Solara Medical Supplies had a $9.76 million settlement due to email security failures.
There has been a 264% increase in ransomware attacks on healthcare since 2018.
Only 1.1% of analyzed healthcare organizations had a low-risk email security posture.
Solara Medical Supplies' $9.76 million settlement was due to a phishing-related breach affecting 114,000 patient records.
37.2% of healthcare Microsoft 365 users had DMARC in ‘monitor-only’ mode.
There has been a 50% increase in healthcare cybersecurity spending since 2018.
L.A. Care received a $1.3 million fine for systemic security lapses.
HIPAA fines exceeding $9 million were issued due to email security failures.