IBM's annual study put the average cost in healthcare at $6.6 million, while AI-enabled attacks pushed the global figure to a record high.

 

What happened

Globally, healthcare recorded the highest average data breach cost of any industry for the thirteenth year running at $6.6 million, to the 2026 IBM Cost of a Data Breach Report, released July 29. The global average across all sectors climbed 12% to $4.99 million, the highest figure in the study's 21-year history. Ponemon Institute conducted the research for IBM, drawing on 602 organizations between March 2025 and February 2026 across 17 industries and 16 countries. US organizations fared worst, averaging more than double the global figure. Detection, escalation, and lost business costs drove most of the increase.

 

Going deeper

The report's central finding concerns who is doing the breaching and how. One in four malicious breaches were AI-enabled, a 56% increase over the previous year, and those breaches averaged $6 million, roughly $1 million above the global average, IBM said in announcing the results. Deepfake impersonation and AI-generated malware accounted for most of that activity. Defenders using AI and automation in their security operations cut breach costs by nearly $2 million on average, though one in four organizations has yet to deploy either. IBM framed the resulting imbalance in blunt terms, noting that attacks can now be launched for thousands of dollars while the breaches they cause cost millions.

 

What was said

"Attackers continue to value and target the industry's patient PII, which can be used for identity theft, insurance fraud and other financial crimes," the report stated in explaining healthcare's position at the top of the cost table, as quoted by Infosecurity Magazine on July 29, 2026. Suja Viswesan, Vice President of IBM Security Software, tied the cost increase to response speed rather than attack volume alone, stating, "AI is making attacks faster and cheaper, while breaches keep getting more expensive. When organizations have an extended gap between discovery and remediation, that imbalance shows up directly in breach costs."

 

In the know

Impersonation is where the federal data and the IBM findings converge. Business email compromise, which relies on the same deception techniques IBM found driving AI-enabled breaches, produced $3.046 billion in reported losses during 2025 and ranked second only to investment fraud among all loss categories, according to the FBI Internet Crime Complaint Center's annual report. The bureau's figures cover only complaints filed, so the real total runs higher. Voice and SMS phishing were the most common initial access routes in IBM's dataset, appearing in 17% of breaches, with social engineering, such as help desk impersonation, close behind.

 

The big picture

Healthcare's average fell year over year even while every other sector's climbed, which reads less as improvement than as a shift in where the costliest breaches landed. The sector's position at the top for thirteen straight years has held through changes in attacker tooling, regulatory pressure, and security spending. Paubox's Hidden Cost of Inaction report found 73% of healthcare IT leaders expecting more email-related breaches ahead, an expectation the IBM data on phishing as the leading entry point supports. Organizations weighing where to spend should note the gap IBM identified between discovery and remediation, since the cost is attached to the delay rather than the intrusion itself. Preventing the initial message through HIPAA compliant email filtering removes the step that everything downstream depends on.

 

FAQs

How does the Cost of a Data Breach study calculate its figures?

Ponemon Institute conducts structured interviews with staff at breached organizations and applies activity-based costing, assigning values to detection and escalation, notification, post-breach response, and lost business. The method captures indirect costs such as customer turnover and diverted staff time, which is why the totals exceed what appears on an incident invoice.

 

Why does the study exclude the largest breaches?

The 2026 edition covered breaches ranging from 2,590 to 115,380 records, deliberately leaving out mega-breaches involving millions of records because their outlier costs would distort the averages. Organizations should read the figures as typical rather than worst case.

 

Does a lower average mean healthcare breaches became less damaging?

Not necessarily. Averages move with the composition of the sample, so a year with fewer catastrophic incidents among the studied organizations lowers the mean without any change in underlying risk. Healthcare still recorded the highest figure of any sector.

 

What does an extended gap between discovery and remediation cost in practice?

Every additional day of unremediated access widens the volume of data an attacker can take and the number of systems they can reach, which drives up forensic scope, notification volume, and regulatory exposure. IBM's framing of breach cost as an hourly figure reflects that time, not incident count, is the variable organizations can most directly control.

 

Are AI-enabled attacks a separate category for HIPAA risk analysis purposes?

The Security Rule does not name specific attack techniques, so a risk analysis addresses the threat by its effect rather than its tooling. A deepfake voice call that convinces a help desk to reset credentials creates the same unauthorized access finding as a conventional phishing email, though organizations should document that identity verification procedures account for synthetic audio and video.