Report by Paubox
2026 healthcare email security report
Key Findings
170 email-related healthcare breaches occured in 2025.
53% of email-related healthcare breaches occurred on Microsoft 365.
Microsoft 365 is adopted by approximately 79% of healthcare organizations.
74% of breached healthcare organizations lacked effective DMARC enforcement (41% missing entirely, 33% monitor-only).
56% of breached healthcare organizations had permissive or missing SPF records (9% missing, 46% soft fail).
31% of breached Microsoft 365 healthcare organizations were classified as High Risk.
41% of breached healthcare organizations fell into a high-risk category based on their email configuration, up from 31% in 2024.
Proofpoint, Barracuda and Mimecast accounted for 19% of email healthcare breaches in 2025.
85% of healthcare IT leaders said they suspected staff were using unauthorized AI tools.
Only 26% of healthcare IT leaders reported having visibility into staff usage of unauthorized AI tools.