In a March 2026 Paubox survey of 170 U.S. healthcare IT leaders, 58% said their organization had been breached through email in the past 24 months. Email runs through most of the numbers below. Phishing, business email compromise, and AI-written attacks all reach staff through the inbox.

These are the headline numbers for 2026:

  • 58% of healthcare organizations were breached through email in the past 24 months (Paubox, 2026)
  • 804 breaches of 500 or more records were reported to the HHS Office for Civil Rights (OCR) for 2025, the most of any year (HIPAA Journal, 2026)
  • 64% have been hit by an AI-generated email attack, and only 38% have AI-based defenses fully deployed (Paubox, 2026)
  • Healthcare and public health filed 460 ransomware complaints with the FBI in 2025, more than any other critical infrastructure sector (FBI IC3, 2025)
  • The average healthcare breach costs $6.64 million, the highest of any industry (IBM, 2026)

Healthcare data breach statistics

Repeat breaches are common: 23% of the healthcare organizations Paubox surveyed were breached through email more than once in 24 months (Paubox Email Security Maturity Index, 2026).

  • More than 140 million individuals were affected by large healthcare breaches reported for 2025 (HIPAA Journal, 2026)
  • 397 large breaches were reported in the first half of 2026, exposing the protected health information (PHI) of 33.77 million people (HIPAA Journal, 2026)
  • Hacking and IT incidents accounted for more than 80% of large healthcare breaches in 2025 (HIPAA Journal, 2026)
  • Verizon counted 1,492 healthcare security incidents in its 2026 report, 1,438 with confirmed data disclosure (Verizon DBIR, 2026)

Look back: OCR reports 242 million records exposed in 2024

Healthcare ransomware statistics

Ransomware reaches patient care: in-hospital mortality rises 34% to 38% for patients already admitted when an attack begins, according to a University of Minnesota study (University of Minnesota, 2026).

  • Hospital volume drops 17% to 24% in the first week of a ransomware attack (University of Minnesota, 2026)
  • HHS reported a 264% increase since 2018 in large breaches involving ransomware reported to OCR (HHS, October 2024)
  • System intrusion, largely driven by ransomware, was the top pattern in healthcare breaches for the second year in a row (Verizon DBIR, 2026)

Go deeper: FBI names healthcare the most targeted sector for ransomware in 2025

Phishing and email security statistics

Email-related breaches dipped to 170 in 2025 from 180 in 2024 (Paubox, 2026), yet 74% of breached healthcare domains still had ineffective DMARC protection, up from 65% (Paubox, 2026).

  • 2.5 million people were affected by email-related healthcare breaches in 2025 (Paubox, 2026)
  • 28% of email-related breaches in 2025 came from vendor and business associate email (Paubox, 2026)
  • Phishing-driven mailbox takeovers caused 17% of email-related breaches (Paubox, 2026) and exposed 630,000 people, more than any other email attack type (Paubox executive summary, 2026)
  • Phishing emails rose 17%, and attacks that evade native defenses rose 47%, according to KnowBe4's 2025 Phishing By Industry Benchmark Report, as cited in Paubox's 2026 Healthcare Email Security Report (Paubox, 2026)
  • 53% of email-related healthcare breaches in 2025 occurred on Microsoft 365, up from 43% in 2024 (Paubox 2026 Healthcare Email Security Report)
  • 68% of healthcare leaders surveyed by Paubox experienced a phishing attack in the past year (Paubox data brief, 2025)
  • Only 5% of known phishing attacks are reported by employees, according to a 2025 Paubox survey of 151 healthcare IT leaders (Paubox data brief, 2025)
  • Business email compromise (BEC) cost victims who reported to the FBI's IC3 $3.05 billion across 24,768 complaints in 2025 (FBI IC3, 2025)

The DMARC and Microsoft 365 figures come from Paubox's review of public DNS records for organizations on the OCR breach list. For what HIPAA requires of email, see our HIPAA compliant email guide.

Go deeper: Business email compromise tactics used against healthcare staff in 2026

Cost of a healthcare data breach

In a Paubox survey, 44% of healthcare IT leaders put the cost of a breach at $1 million to $5 million, below IBM's 2026 healthcare average (Paubox data brief, 2025).

  • Healthcare's average breach cost fell 10.5% from $7.42 million a year earlier and remains the highest of any industry (IBM Cost of a Data Breach, 2026)
  • The average U.S. breach across industries reached a record $11.5 million (IBM Cost of a Data Breach, 2026)
  • The global average breach cost reached a record $4.99 million, up 12% (IBM Cost of a Data Breach, 2026)
  • Healthcare breaches took 279 days to identify and contain in 2025, more than five weeks longer than that year's global average of 241 days (IBM, 2025)

Go deeper: IBM reports healthcare data breach costs hit record high $9.77 million (2024 data)

AI and cybersecurity in healthcare

Staff adoption is ahead of oversight: 95% of healthcare IT and compliance leaders say staff already use AI tools in email, and only 41% feel confident they could catch improper use before it led to a HIPAA violation (Paubox Shadow AI report, 2025).

The AI Build Benchmark surveyed 151 healthcare leaders whose organizations already use AI coding assistants, so its figures describe that group rather than healthcare as a whole.

Go deeper: Most healthcare IT leaders suspect shadow AI in their organization

What the numbers mean for your organization

Phishing, BEC, and mailbox takeovers all start in the inbox, and the breached organizations Paubox reviewed often had the same gaps in email authentication.

Start with the controls the data points to: enforced DMARC, encryption on every outbound message, and inbound filtering that can catch AI-written phishing. Paubox Inbound Email Security uses generative AI to detect phishing, spoofing, and BEC before they reach staff.

FAQs

How many healthcare data breaches were there in 2025?

804 breaches of 500 or more records were reported to OCR for 2025, the most of any year (HIPAA Journal, 2026). Paubox tracks new reports each month in its HIPAA Breach Reports.

What is the most common cause of healthcare data breaches?

Hacking and IT incidents cause more than 80% of large healthcare breaches, including ransomware and phishing-driven account takeovers. Paubox's 2024 phishing statistics cover the earlier phishing trend.

How much does a healthcare data breach cost?

The average healthcare breach costs $6.64 million, the highest of any industry, though it fell from $7.42 million in 2025 (IBM, 2026). Our healthcare data breach insights and statistics post covers how costs have changed since 2024.

Is email still a major source of healthcare breaches?

Yes. Phishing-driven mailbox takeovers exposed more people in 2025 than any other email attack type, and vendor email accounted for more than a quarter of email-related breaches.

Does HIPAA require a business associate agreement for email providers?

Yes. Any vendor that stores or transmits PHI for you, including your email provider, must sign a business associate agreement (BAA).