Healthcare Cybersecurity Statistics 2026
By Axis Intelligence Research
Co-authors: Marcus Chen (Cybersecurity & Privacy) · Jennifer Miller (Digital Health) | Last updated: August 3, 2026 | License: CC BY 4.0
Healthcare held the highest average breach cost of any industry for a thirteenth consecutive year in 2026, at $6.64 million per incident — but that figure fell 10.5% while the number of large U.S. healthcare breaches hit an all-time record of 772. Axis Intelligence Research finds the sector’s cost premium over the global average has nearly halved in a single reporting cycle.
Quick Answer
Healthcare data breaches cost an average of $6.64 million in 2026, the highest of any industry for the thirteenth year running, according to the IBM Cost of a Data Breach Report 2026 released July 29, 2026. U.S. covered entities and business associates reported a record 772 large breaches to HHS in 2025, exposing the protected health information of approximately 138.5 million people. Axis Intelligence Research calculates a Healthcare Breach Accountability Ratio (HBAR) of 688:1 — the sector’s estimated aggregate breach exposure divided by the federal penalties actually imposed that year.
Key Findings
- Axis Intelligence Research finds that healthcare’s average breach cost premium over the global average compressed from 1.67× in 2025 to 1.33× in 2026, based on IBM Cost of a Data Breach figures — the sector is still the most expensive, but by the narrowest margin in years.
- Axis Intelligence Research finds that nine breaches accounted for 72.4% of all individuals affected by U.S. healthcare data breaches in 2025, while the remaining 763 large breaches averaged 50,011 people each.
- Axis Intelligence Research finds that business associates filed 17.6% of large healthcare breach reports in 2025 but accounted for 71.4% of the exposure volume in the year’s nine largest incidents.
- The Healthcare and Public Health sector reported 460 ransomware complaints and 182 data breach complaints to the FBI Internet Crime Complaint Center in 2025 — 19.8% of all critical-infrastructure cyber complaints and more than any of the other 15 sectors.
- Axis Intelligence Research finds that HHS Office for Civil Rights resolved 21 enforcement actions totalling $8,330,066 in 2025 — roughly six cents per individual whose protected health information was breached that year, and one action for every 36.8 large breaches reported.
How Much Does a Healthcare Data Breach Cost in 2026?
$6.64 million, on average. That is the figure IBM published on July 29, 2026 in the Cost of a Data Breach Report 2026, conducted by Ponemon Institute and drawn from 602 breached organisations across 16 countries and 17 industries, covering incidents between March 2025 and February 2026. It is the thirteenth consecutive year healthcare has topped the industry table.
The number that matters more is the direction. Healthcare’s average fell 10.5% from $7.42 million in the 2025 edition, while the global average across all industries rose 12% to a record $4.99 million and the U.S. average across all sectors reached $11.5 million.
| Metric | 2025 report | 2026 report | Change | Source |
|---|---|---|---|---|
| Healthcare average breach cost | $7.42M | $6.64M | −10.5% | IBM Cost of a Data Breach |
| Global average, all industries | $4.44M | $4.99M | +12% | IBM Cost of a Data Breach |
| U.S. average, all industries | $10.22M | $11.5M | +12.5% | IBM Cost of a Data Breach |
| Healthcare premium over global | 1.67× | 1.33× | −0.34× | Axis Intelligence Research calculation |
| Mean time to identify and contain | 241 days | 247 days | +6 days | IBM Cost of a Data Breach |
The Axis premium-compression calculation
Axis Intelligence Research divides IBM’s healthcare sector average by IBM’s global all-industry average for the same report year:
- 2025: $7.42M ÷ $4.44M = 1.671×
- 2026: $6.64M ÷ $4.99M = 1.331×
Both inputs come from the same instrument, the same methodology and the same publication cycle, which is what makes the ratio meaningful. Axis Intelligence Research estimates the compression at 0.34× in one cycle — the sharpest single-year narrowing of healthcare’s cost premium in the report’s recent history. Two mechanisms are consistent with the data and we cannot separate them from IBM’s published figures alone: healthcare costs genuinely falling, or non-healthcare costs rising fast enough to close the gap. The 12% global increase suggests the second is doing most of the work.
Marcus Chen writes: A falling average breach cost in healthcare is the kind of number that gets misread in a board deck. It does not mean fewer attacks, and it does not mean better defence. IBM’s sample is 602 organisations globally; HHS’s is every U.S. covered entity that had to notify. Those two datasets disagreed sharply this year, and when a cost-per-incident metric falls while an incident-count metric sets a record, the honest reading is that the denominator moved. More incidents, spread across more mid-sized organisations with smaller record counts, drags an average down without a single hospital becoming safer. Compare the same figure to itself three years back — $10.93 million in the 2023 report — and the question stops being “why did it fall?” and becomes “what changed in who is getting breached?”
How Many Healthcare Data Breaches Were Reported in 2025 and 2026?
772 large breaches were reported to the HHS Office for Civil Rights breach portal for 2025 — an all-time record, beating the previous high of 746 set in 2023. That is 2.12 large breaches every day for a year.
Under the HITECH Act, OCR must publish every reported breach affecting 500 or more individuals. Smaller breaches are reported but not published individually.
Large healthcare data breaches by year
| Year | Large breaches reported | Individuals affected | Source |
|---|---|---|---|
| 2021 | 715 | — | HHS OCR breach portal |
| 2022 | 719 | — | HHS OCR breach portal |
| 2023 | 746 | 160M+ | HHS OCR breach portal; HHS NPRM |
| 2024 | 741 | ~289M | HHS OCR breach portal |
| 2025 | 772 | ~138.5M | HHS OCR breach portal |
| 2026 (to Apr 30) | 252 | — | HHS OCR breach portal |
Between October 21, 2009 and April 30, 2026, 7,670 large healthcare breaches were reported to OCR. Through the end of 2025, those breaches had exposed or impermissibly disclosed the protected health information of 1,013,066,481 individuals — 2.96 times the U.S. population, at an average of 136,569 people per breach.
What the 2026 run-rate actually shows
The 252 breaches reported for January 1 to April 30, 2026 look like a decline. They are not, or at least not yet. Axis Intelligence Research calculates the run-rate at 2.10 breaches per day, which annualises to approximately 766 — statistically indistinguishable from 2025’s record 772. Through May 31, 319 breaches gives 2.11 per day and an annualised 771.
There is also a reporting artefact in the way. A 43-day U.S. federal government shutdown from October 1 to November 12, 2025 halted additions to the OCR breach portal, and the backlog has not cleared. In March 2026, three months after HHS staff returned, no breaches at all were added to the portal for that month; by June 2026, OCR was still posting March filings. Early-year totals should be read as a floor, not a count.
Which Healthcare Breaches Exposed the Most Records?
Nine did most of the damage. Axis Intelligence Research calculates that the nine largest healthcare breaches disclosed for 2025 account for 100,341,346 individuals — 72.4% of the roughly 138.5 million people affected that year. The other 763 large breaches share the remaining 27.6%, averaging 50,011 individuals each.
| Rank | Entity | Type | Individuals | Year | Source |
|---|---|---|---|---|---|
| 1 | Conduent Business Services LLC | Business associate | 62,224,658 | 2025 | HHS OCR breach portal |
| 2 | Aflac Incorporated | Health plan | 13,924,906 | 2025 | HHS OCR breach portal |
| 3 | Episource, LLC | Business associate | 6,725,572 | 2025 | HHS OCR breach portal |
| 4 | Yale New Haven Health System | Provider | 5,556,702 | 2025 | HHS OCR breach portal |
| 5 | PIH Health, Inc. | Provider | 2,947,264 | 2025 | HHS OCR breach portal |
| 6 | DaVita Inc. | Provider | 2,689,826 | 2025 | HHS OCR breach portal |
| 7 | Veradigm LLC | Business associate | 2,672,036 | 2025 | HHS OCR breach portal |
| 8 | Anne Arundel Dermatology | Provider | 1,905,000 | 2025 | HHS OCR breach portal |
| 9 | Kettering Adventist Healthcare | Provider | 1,695,382 | 2025 | HHS OCR breach portal |
Conduent alone represents 44.9% of the entire year’s exposure and is now the third-largest healthcare breach on record, behind Change Healthcare (192,700,000 individuals, 2024) and Anthem (78,800,000, 2015).
The number that was wrong for four months
This is the finding Axis Intelligence Research considers most consequential for anyone citing healthcare breach statistics. In February 2026, the 2025 victim total stood at 61,556,256 individuals. By June 2026, the same year’s total had been revised to approximately 138.5 million — an upward revision of 125%, or 76.9 million people. Conduent’s completed file review accounts for roughly 81% of that revision.
Every statistic published about 2025 healthcare breaches before roughly May 2026 understated the year by more than half. This is not an error by the publishers; it is how the OCR portal works. Entities file within 60 days of discovery, frequently using placeholder figures of 500 or 501 individuals, then amend once the file review concludes — often a year later.
Practical implication for anyone citing this data: always state the retrieval date. A healthcare breach total without a retrieval date is not a statistic, it is a snapshot with the timestamp cropped off.
Who Is Actually Being Breached — Providers or Their Vendors?
Both, but not in the proportions the headline counts suggest.
Business associates — the clearinghouses, billing vendors, revenue-cycle firms and analytics platforms that sit behind covered entities — filed 136 of the 772 breach reports in 2025, or 17.6%. Axis Intelligence Research calculates that those same business associates accounted for 71.4% of the exposure volume in the year’s nine largest incidents (Conduent, Episource and Veradigm together: 71,622,266 of 100,341,346 individuals).
Large healthcare breaches by reporting entity type
| Year | Provider | Health plan | Business associate | Clearinghouse | BA share |
|---|---|---|---|---|---|
| 2018 | 274 | 53 | 42 | 0 | 11.4% |
| 2021 | 516 | 104 | 93 | 2 | 13.0% |
| 2022 | 504 | 86 | 129 | 0 | 17.9% |
| 2023 | 469 | 103 | 172 | 2 | 23.1% |
| 2024 | 543 | 77 | 118 | 3 | 15.9% |
| 2025 | 575 | 59 | 136 | 2 | 17.6% |
Source: HHS OCR breach portal, by reporting entity. Retrieved 2026-08-03.
Business-associate-reported breaches rose 224% between 2018 and 2025. Health-plan-reported breaches moved the other way, down 43% from their 2021 peak of 104 to 59 in 2025.
One caveat that materially affects these figures: when a breach occurs at a business associate, it may be reported by the business associate or separately by each affected covered entity. Business-associate breaches are therefore systematically under-counted in reporting-entity tables. The 17.6% is a floor.
Jennifer Miller writes: The clinical read on vendor concentration is different from the security read. When a revenue-cycle vendor goes down, the failure does not present as a data-privacy event inside the hospital — it presents as claims not adjudicating, prior authorisations stalling, and pharmacy benefit checks timing out at the counter. The patient-facing symptom of a business-associate breach is a delay in care that nobody in the building attributes to a cyber incident, because the incident happened somewhere else. HHS’s own proposed rulemaking cites a study finding that a cyberattack at one hospital produced measurable increases in ambulance arrivals, waiting-room times and patients leaving without being seen at a neighbouring, unaffiliated medical centre. The blast radius of a healthcare breach is not the entity that files the report.
How Do Attackers Get Into Healthcare Organisations?
Ransomware-driven system intrusion, increasingly through unpatched software rather than stolen passwords.
Verizon’s 2026 Data Breach Investigations Report healthcare snapshot analysed 1,492 healthcare incidents (NAICS 62), of which 1,438 were confirmed data disclosures — a 96.4% disclosure rate. The report’s dataset covers November 2024 through October 2025.
| Metric | Healthcare (NAICS 62) | Source |
|---|---|---|
| Incidents analysed | 1,492 | Verizon 2026 DBIR |
| Confirmed data disclosures | 1,438 | Verizon 2026 DBIR |
| Top three patterns combined | 81% of breaches | Verizon 2026 DBIR |
| External threat actors | 81% | Verizon 2026 DBIR |
| Internal threat actors | 19% | Verizon 2026 DBIR |
| Financially motivated | 99% | Verizon 2026 DBIR |
| Exploitation of vulnerabilities (initial access) | 20% | Verizon 2026 DBIR |
| Phishing (initial access) | 14% | Verizon 2026 DBIR |
| Credential abuse (initial access) | 11% | Verizon 2026 DBIR |
| Human element present | 54% | Verizon 2026 DBIR |
| Third-party involvement | 32% | Verizon 2026 DBIR |
The pattern shift nobody flagged
System Intrusion accounted for 36% of healthcare breaches in the 2024 DBIR, 53% in 2025, and 61% in 2026 — a 25-percentage-point rise in two cycles. Miscellaneous Errors, the pattern that has dogged healthcare in every DBIR since 2014, fell from 25% to 8% over the same period. Social Engineering re-entered the top three at 17%, displacing the “Everything Else” category.
Where we disagree with the prevailing reading
Several summaries of the 2026 DBIR have reported that third-party breaches in healthcare rose 60% year over year. That is a misattribution. The 60% increase and the 48% share are Verizon’s global, all-industry figures. The healthcare-specific third-party figure in the DBIR’s own healthcare snapshot is 32% of breaches — a third lower than the global rate, not higher.
Healthcare is likewise below the global rate on human element: 54% versus 62%. Verizon attributes part of healthcare’s 32% third-party figure to the Oracle E-Business Suite vulnerability campaign attributed to the Cl0p group, which touched multiple sectors.
This matters because the two framings support opposite budget conclusions. A sector 33% below the global third-party rate has a vendor problem measured by severity, as the concentration analysis above shows, not by frequency. Those require different controls.
Which Critical Infrastructure Sector Reports the Most Cyberattacks?
Healthcare, and it is not close. The FBI’s 2025 Internet Crime Report records 460 ransomware complaints and 182 data breach complaints from the Healthcare and Public Health sector — the highest of all 16 critical infrastructure sectors on both counts combined.
Axis Intelligence Research derived the sector shares below from the IC3 report’s critical-infrastructure complaint chart. Sector totals across all 16 sectors: 2,118 ransomware complaints and 1,119 data breach complaints.
| Measure | Healthcare & Public Health | Axis calculation | Source |
|---|---|---|---|
| Ransomware complaints | 460 | 21.7% of all CI ransomware complaints | FBI IC3 2025 |
| Data breach complaints | 182 | 16.3% of all CI data breach complaints | FBI IC3 2025 |
| Combined CI cyber complaints | 642 | 19.8% of all CI cyber complaints | FBI IC3 2025 |
| Share of all U.S. ransomware complaints (3,611) | 460 | 12.7% | FBI IC3 2025 |
| Lead over next-ranked sector | 460 vs 355 | 1.30× | FBI IC3 2025 |
Formula: healthcare share = 642 ÷ (2,118 + 1,119) = 19.8%. Roughly one in five cyber complaints filed with the FBI by U.S. critical infrastructure operators in 2025 came from healthcare.
Nationally, IC3 logged 3,611 ransomware complaints with reported losses exceeding $32.3 million across all sectors. That loss figure is not a measure of ransomware’s cost: the FBI states explicitly that it excludes lost business, time, wages, files, equipment and third-party remediation, and that entities frequently report no loss amount at all. It is a floor on ransom payments, nothing more.
Two additional details from the IC3 report that are not widely reported:
- IC3 identified 63 new ransomware variants in 2025, an average of 5.25 per month. The top ten variants — led by Akira, Qilin and INC/Lynx/Sinobi — accounted for 56.8% of reported incidents and most affected critical manufacturing, healthcare and public health, and government facilities.
- The IC3 Recovery Asset Team’s Financial Fraud Kill Chain achieved a 60% fund-freeze success rate for healthcare in 2025, against a 56% average across all critical infrastructure sectors.
HHS’s own rulemaking notes that Healthcare and Public Health has been the most-targeted critical infrastructure sector since at least 2015.
Marcus Chen writes: Twelve point seven percent of every ransomware complaint filed with the FBI last year came from one sector, and the reason is operational, not technical. Hospitals cannot divert. A manufacturer with a just-in-time line and a hospital with a full emergency department share the same negotiating weakness: downtime tolerance measured in hours. Attackers price that. What the IC3 data does not show, and what people keep reading into it, is a sophistication story. There is no zero-day at the front of most of these. Verizon puts exploitation of known vulnerabilities at 20% of healthcare initial access and phishing at 14%, and the global median for fully remediating a CISA Known Exploited Vulnerability is now 43 days, up from 32. Forty-three days is the whole game.
What Is the Real Regulatory Cost of a Healthcare Breach?
Far less than the breach. This is the Axis Intelligence Research original metric for this dataset.
The Axis Healthcare Breach Accountability Ratio (HBAR) — methodology v1.0, baseline reading
Definition: HBAR measures the ratio of estimated aggregate annual healthcare breach exposure to federal HIPAA enforcement penalties resolved in the same calendar year.
Formula:
HBAR = (large breaches reported to OCR in year Y × IBM healthcare average breach cost, report year Y)
÷ (total OCR settlements and civil monetary penalties resolved in year Y)
Baseline reading — calendar year 2025:
- Large breaches reported to OCR: 772 (HHS OCR breach portal)
- IBM healthcare average breach cost, 2025 report: $7,420,000 (IBM Cost of a Data Breach 2025)
- Estimated aggregate exposure: 772 × $7,420,000 = $5,728,240,000
- OCR settlements and civil monetary penalties resolved in 2025: $8,330,066 across 21 actions
- HBAR (2025 baseline) = $5,728,240,000 ÷ $8,330,066 = 687.7 : 1
Federal penalties equal 0.145% of estimated aggregate breach exposure. Expressed per person: $0.0601 — about six cents for every individual whose protected health information was breached in 2025. One enforcement action was resolved for every 36.8 large breaches reported, or 2.72% of them.
Comparison point. Applying the same formula to 2023 (746 breaches × $10.93M IBM 2023 healthcare average ÷ $4,176,500 in OCR penalties) yields 1,952:1. The gap narrowed substantially, driven by both a lower per-incident cost input and a near-doubling of penalty volume.
Stated limitations. HBAR is an estimate, not an observation, and Axis Intelligence Research labels it as such:
- IBM’s average is drawn from a global 602-organisation sample and is applied here to the U.S. OCR breach population. The two populations are not identical. HBAR is therefore an order-of-magnitude indicator, not a precise dollar figure.
- OCR penalties resolved in a given year relate to breaches from earlier years — often several years earlier. HBAR compares contemporaneous flows, not matched cohorts.
- HBAR excludes state attorney-general penalties, FTC Health Breach Notification Rule actions, and private class-action settlements, all of which now exceed OCR penalties in aggregate. It measures federal HIPAA enforcement specifically.
- Breach counts revise upward for months after year-end (see the 125% revision documented above). HBAR carries an as-of date for this reason.
- HBAR does not measure deterrence. Enforcement value is not confined to the penalty amount; corrective action plans carry costs OCR does not publish.
What HBAR does not claim: that penalties should equal exposure. It quantifies a gap that healthcare compliance leaders describe qualitatively and that is otherwise absent from the public record.
HHS OCR enforcement, 2023–2026
| Year | Enforcement actions | Total penalties | Source |
|---|---|---|---|
| 2023 | 13 | $4,176,500 | HHS OCR enforcement record |
| 2024 | 16 | $9,264,046 | HHS OCR enforcement record |
| 2025 | 21 | $8,330,066 | HHS OCR enforcement record |
| 2026 (to date) | 7 | $1,728,000 | HHS OCR enforcement record |
OCR’s largest single 2025 action was a $3,000,000 settlement with Solara Medical Supplies; the largest 2026 action to date is a $450,000 settlement with the Spencer Gifts LLC flexible benefits and welfare benefit plans, resolving a ransomware investigation opened after a January 2022 breach report affecting 10,023 individuals.
OCR’s constraint is arithmetic. Its budget has been effectively flat since 2009 while its caseload more than doubled between 2018 and 2021. As of April 30, 2026, 936 breach investigations were open or awaiting assignment, up from 882 when the same count was taken in 2024 — 12.2% of every large breach ever reported to the agency. OCR’s current hacking investigations concentrate on a single provision, the Security Rule risk analysis requirement, precisely because narrower investigations close faster.
What Is Happening With the HIPAA Security Rule Update?
It has slipped to at least July 2027.
HHS published the HIPAA Security Rule NPRM in the Federal Register on January 6, 2025 (90 FR 898, RIN 0945-AA22) — the first substantive overhaul since 2013. The comment period closed March 7, 2025, drawing 4,747 comments. A final rule was targeted for May 2026. The OMB Unified Agenda now lists final action for July 2027, and the current Security Rule remains in effect in the meantime.
The proposal would eliminate the “addressable” designation that has let entities document why a safeguard was not reasonable and appropriate, making nearly all implementation specifications mandatory — including encryption of ePHI at rest and in transit, multi-factor authentication, asset inventory, network segmentation, annual penetration testing and written documentation of every policy.
Cost, per HHS’s own Regulatory Impact Analysis: approximately $9 billion in year one, with roughly $6 billion annually in years two through five — about $33 billion over five years.
An Axis cross-source comparison, with its own caveat
HHS’s estimated year-one compliance cost of $9 billion is 1.57× the $5.73 billion in estimated aggregate 2025 breach exposure calculated above.
Axis Intelligence Research states plainly what this comparison does and does not support. It does not show that the rule costs more than it saves. Compliance cost is a certain outlay across all regulated entities; breach exposure as estimated here captures only disclosed incidents at the entities that were actually breached, and excludes patient-safety harm, downtime, class-action liability and the cascading regional effects HHS documents in the NPRM itself. The two figures are built on incompatible bases and Axis Intelligence Research declines to merge them into a single net-benefit number. What the comparison does establish is the order of magnitude of the affordability argument that CHIME and more than a hundred hospital systems made when they petitioned HHS to withdraw the proposal.
The evidence base HHS built for the rule
The NPRM is itself a primary source on healthcare cyber trends, and its figures are under-cited:
| Metric | Value | Period | Source |
|---|---|---|---|
| Increase in large breaches reported | +100% | 2018–2023 | HHS HIPAA Security Rule NPRM |
| Increase in individuals affected | +950% | 2018–2023 | HHS HIPAA Security Rule NPRM |
| Increase in hacking-related breaches | +260% | 2018–2023 | HHS HIPAA Security Rule NPRM |
| Increase in ransomware breaches | +264% | 2018–2023 | HHS HIPAA Security Rule NPRM |
| Increase in ransomware vs U.S. healthcare | +128% | 2022–2023 | HHS HIPAA Security Rule NPRM |
| Healthcare orgs experiencing a cyberattack in prior year | 92% | survey cited in NPRM | HHS HIPAA Security Rule NPRM |
| Share of those reporting negative effects on patient care | ~75% | survey cited in NPRM | HHS HIPAA Security Rule NPRM |
| Hospitals with certified EHRs | 96% | 2021 | HHS HIPAA Security Rule NPRM |
| Estimated dark-web value per stolen medical record | up to $1,000 | cited in NPRM | HHS HIPAA Security Rule NPRM |
| Average cost to an individual of recovering from medical identity theft | $13,500 | cited in NPRM | HHS HIPAA Security Rule NPRM |
The NPRM also documents two incident case studies with hard operational numbers: a 2020 attack on a large integrated academic health system that affected more than 5,000 end-user devices across 1,300 servers, produced 39 days of outpatient imaging downtime and over $63 million in revenue losses; and a ransomware attack on an academic Level 1 trauma centre that left it without EHR access for 25 days.
What Did the Change Healthcare Attack Actually Cost?
It remains the reference point for sector-wide risk, and its numbers come from SEC filings rather than estimates.
In its FY2024 Form 10-K, UnitedHealth Group disclosed $2.2 billion in direct response costs for the year ended December 31, 2024 — interest-free provider loans, network restoration, elevated medical care expenditures and notification of affected individuals — plus $867 million in estimated business disruption impacts at Optum Insight from lost revenue while maintaining readiness of affected Change Healthcare services. UnitedHealth determined the estimated total number of individuals impacted to be approximately 190 million.
The OCR breach portal figure of 192,700,000 remains the largest healthcare breach ever recorded, and accounted for roughly two-thirds of every individual affected by a U.S. healthcare breach in 2024.
Are Healthcare Breaches Getting Better or Worse in 2026?
The honest answer is that the data does not yet permit a conclusion, and anyone offering one is reading a backlog as a trend.
What can be stated from the current record:
- Volume: flat at record levels. 2026 is tracking at 2.10–2.11 large breaches per day, annualising to roughly 766–771 against 2025’s record 772.
- Cause: consolidating around hacking. 173 of the 189 breaches recorded on the portal for the first half of 2026 were attributed to hacking or IT incidents. Across 2025, hacking and other IT incidents accounted for more than 80% of large breaches. One theft and one loss incident were recorded in the first half of 2026.
- Cost per incident: down. $6.64M, −10.5% year over year.
- Enforcement: slowing in 2026. Seven actions totalling $1,728,000 to date, against 21 actions totalling $8,330,066 in all of 2025.
- Regulation: postponed. Final Security Rule action moved to at least July 2027.
- Reporting infrastructure: degraded. The OCR portal ran roughly three months behind through mid-2026, and 936 investigations sat open.
Marcus Chen writes: The single most useful control in this dataset costs nothing to name and everything to execute: close known exploited vulnerabilities faster than 43 days. Verizon’s global median for full remediation of a CISA KEV entry went the wrong way this year — 43 days, up from 32 — while organisations faced 50% more critical vulnerabilities to patch and only 26% of them got fully remediated, down from 38%. Exploitation of vulnerabilities is now the leading initial access vector globally at 31%, and it is 20% in healthcare specifically. Everything else in this article — the $6.64 million, the 688:1 ratio, the 936-case backlog — is downstream accounting of that window.
Methodology
Data collection. Every figure in this dataset was retrieved from a named source document during the production session on August 3, 2026. No figure was taken from prior knowledge. Sources fetched and read in full during production: the FBI IC3 2025 Internet Crime Report (PDF), the Verizon 2026 DBIR Healthcare Snapshot (PDF), the HHS HIPAA Security Rule NPRM at 90 FR 898 (Federal Register), the IBM Cost of a Data Breach Report 2026 landing page and IBM’s July 29, 2026 newsroom release, and the HHS OCR breach portal and enforcement record.
Source hierarchy. Federal government sources (HHS OCR, FBI IC3, Federal Register, SEC EDGAR) take precedence. Named research organisations publishing original instruments (IBM/Ponemon, Verizon) are used for figures no government source produces. Secondary aggregators are used only to locate primary documents and are named in plain text, never hyperlinked.
Two figures require explicit disclosure of their retrieval path:
- IBM healthcare sector figures. IBM publishes global headline figures on its public report page; the healthcare sector breakdown ($6.64M, thirteenth consecutive year, −10.5%, and the malicious/IT-failure/human-error split of 59%/26%/13%) sits inside the gated report. Axis Intelligence Research confirmed these values across four independent outlets reporting from the report itself, all in agreement, and attributes them to IBM Cost of a Data Breach Report 2026.
- HHS Regulatory Impact Analysis cost estimates. The $9 billion year-one and $6 billion recurring figures appear in the RIA section of the NPRM at 90 FR 898. Axis Intelligence Research confirmed them across five independent readings of that section rather than extracting the RIA cost table directly, and flags them accordingly in the dataset.
Multi-year OCR series. The year-by-year breach counts, reporting-entity breakdown and enforcement record derive from the HHS OCR breach portal. Because the portal does not expose historical aggregates through its public interface, the multi-year series was taken from a published compilation of portal data (The HIPAA Journal, retrieved 2026-08-03, data current to May 19, 2026). Axis Intelligence Research independently verified the 2025 enforcement total by summing the 21 individual OCR actions listed for that year: $8,330,066. That sum matches an independently published figure for the same year to the dollar.
Axis calculations. Formulas for HBAR, the premium-compression ratio, the concentration ratio and the IC3 sector shares are disclosed inline at the point of use. All arithmetic was independently recomputed before publication. Every Axis-derived figure is marked axis_calculated = yes in the accompanying dataset with a method note.
IC3 sector figures. The 460 and 182 healthcare complaint counts and the 16-sector totals were transcribed from the accessibility description of the critical-infrastructure chart on page 16 of the IC3 2025 Annual Report. The derived sector totals (2,118 ransomware; 1,119 data breach) reconcile with independent reporting of “more than 2,100” and “roughly 1,100” for the same chart.
Excluded figures. Sector-level healthcare cybersecurity spending is excluded. No primary issuing organisation publishes a comprehensive healthcare cybersecurity spend figure, and the commonly circulated estimates trace to vendor surveys with undisclosed sampling. Estimates of healthcare cyberattack mortality are also excluded; the studies HHS cites in the NPRM are directional and the agency itself declines to quantify deaths.
Known limitations.
- The OCR portal captures only breaches affecting 500 or more individuals. Approximately 74,299 smaller breaches were reported in 2024 alone.
- 2025 and 2026 individual-affected totals will continue to revise upward.
- IBM’s sample is global and skews toward larger organisations; breaches in its 2026 dataset ranged from 2,590 to 115,380 compromised records, which excludes both the smallest and the mega-breaches that dominate OCR volume.
- Verizon’s DBIR reflects contributed caseload, not a census.
- IC3 figures reflect voluntary complaints and materially understate incident volume.
About This Dataset
Title: Healthcare Cybersecurity Statistics 2026
Publisher: Axis Intelligence Research
License: Creative Commons Attribution 4.0 International (CC BY 4.0)
Temporal coverage: 2009-10-21 / 2026-08-03
Spatial coverage: United States (primary); global comparators from IBM and Verizon
Rows: 191 observations, each with full provenance columns
Format: UTF-8, comma-separated, tidy long format
Every number in this article exists as a row in the dataset, at the same value and the same as-of date, with source organisation, source document, source URL, retrieval date, primary-source flag, Axis-calculated flag and method note.
Citation formats
APA: Axis Intelligence Research. (2026). Healthcare cybersecurity statistics 2026: Breaches, costs, ransomware and the enforcement gap. Axis Intelligence. https://axis-intelligence.com/healthcare-cybersecurity-statistics/
MLA: Axis Intelligence Research. “Healthcare Cybersecurity Statistics 2026: Breaches, Costs, Ransomware and the Enforcement Gap.” Axis Intelligence, 3 Aug. 2026, axis-intelligence.com/healthcare-cybersecurity-statistics/.
Chicago: Axis Intelligence Research. “Healthcare Cybersecurity Statistics 2026: Breaches, Costs, Ransomware and the Enforcement Gap.” Axis Intelligence, August 3, 2026. https://axis-intelligence.com/healthcare-cybersecurity-statistics/.
Attribution requirement: cite as Axis Intelligence Research, Healthcare Cybersecurity Statistics 2026. The HBAR methodology may be reproduced and recomputed; we ask that derived readings be labelled as such.
Frequently Asked Questions
How much does a healthcare data breach cost in 2026?
$6.64 million on average, per the IBM Cost of a Data Breach Report 2026 published July 29, 2026. That is the highest of any industry for the thirteenth consecutive year, though it fell 10.5% from $7.42 million in the 2025 edition. The global all-industry average rose 12% to a record $4.99 million over the same period.
How many healthcare data breaches happened in 2025?
772 breaches affecting 500 or more individuals were reported to the HHS Office for Civil Rights — an all-time record, exceeding the previous high of 746 set in 2023. Those breaches exposed the protected health information of approximately 138.5 million people. Smaller breaches are reported to OCR but not individually published; roughly 74,299 were reported in 2024.
Why do healthcare breach statistics keep changing?
Because entities must notify OCR within 60 days of discovering a breach, often before the file review is complete. Many file using a placeholder figure of 500 or 501 individuals and amend months later. Axis Intelligence Research documented a 125% upward revision to the 2025 total between February and June 2026 — from 61,556,256 to approximately 138.5 million individuals — with Conduent’s completed review accounting for about 81% of the change. Always check the retrieval date on any healthcare breach statistic.
Is healthcare the most attacked critical infrastructure sector?
Yes, by complaint volume to the FBI. The Healthcare and Public Health sector filed 460 ransomware complaints and 182 data breach complaints with the FBI Internet Crime Complaint Center in 2025 — 19.8% of all critical-infrastructure cyber complaints and 1.30× the next-ranked sector on ransomware. HHS states the sector has been the most-targeted critical infrastructure sector since at least 2015.
How do hackers get into hospitals?
Exploitation of known software vulnerabilities is the leading initial access vector in healthcare at 20% of breaches, followed by phishing at 14% and credential abuse at 11%, per the Verizon 2026 DBIR healthcare snapshot. System Intrusion, largely ransomware-driven, accounts for 61% of healthcare breaches — up from 36% two report cycles ago. 81% of healthcare breaches involve external actors and 99% are financially motivated.
How much does HHS fine healthcare organisations for breaches?
Less than most people assume. OCR resolved 21 enforcement actions totalling $8,330,066 in 2025, against 772 reported large breaches. Axis Intelligence Research calculates that as one action per 36.8 breaches, and roughly six cents per individual affected. The Axis Healthcare Breach Accountability Ratio puts estimated aggregate breach exposure at 688 times federal penalties for that year. State attorneys general, the FTC and private class actions now impose larger aggregate sums than OCR does.
When does the new HIPAA Security Rule take effect?
Not before 2027, and possibly later. The NPRM published January 6, 2025 at 90 FR 898 targeted a May 2026 final rule; the OMB Unified Agenda now lists final action for July 2027. Once published, the rule would take effect 60 days later with compliance required a further 180 days after that — roughly 240 days total. The current Security Rule remains fully enforceable in the meantime, and OCR continues to bring actions under it.
What will the HIPAA Security Rule update cost?
HHS’s own Regulatory Impact Analysis estimates approximately $9 billion in year one and roughly $6 billion annually in years two through five — about $33 billion over five years. The proposal would make nearly all implementation specifications mandatory, including encryption at rest and in transit, multi-factor authentication and annual penetration testing. CHIME and more than one hundred hospital systems petitioned HHS to withdraw it, arguing small and rural providers cannot absorb the cost.
Are business associates or covered entities the bigger risk?
Business associates are the bigger risk by severity, not frequency. They filed 17.6% of 2025 breach reports but accounted for 71.4% of the exposure volume in the year’s nine largest incidents, per Axis Intelligence Research analysis of OCR portal data. That figure is a floor: business-associate breaches may be reported by the business associate or separately by each affected covered entity, which systematically undercounts them in reporting-entity tables.
What was the largest healthcare data breach ever?
The Change Healthcare ransomware attack, reported in 2024, affecting 192,700,000 individuals per the OCR breach portal. UnitedHealth Group disclosed approximately 190 million impacted individuals in its FY2024 Form 10-K, along with $2.2 billion in direct response costs and $867 million in business disruption impacts at Optum Insight for that year. The second largest is Anthem (78.8 million, 2015); the third is Conduent Business Services (62,224,658, 2025).
