Healthcare data breaches continue to reach record levels, exposing millions of patient records and costing organizations more than any other industry. In 2024 alone, the U.S. Department of Health and Human Services (HHS) recorded 772 large healthcare data breaches affecting 139.7 million individuals, while IBM reported that the average healthcare data breach cost reached $7.42 million in 2025—the highest among all industries for the 14th consecutive year.
The growing adoption of electronic health records (EHRs), cloud platforms, connected medical devices, and third-party healthcare services has expanded the industry’s attack surface. As a result, ransomware groups, phishing campaigns, and software supply chain attacks continue to target healthcare organizations worldwide.
Below are the latest healthcare data breach statistics covering breach frequency, patient records exposed, financial losses, ransomware attacks, HIPAA compliance, and cybersecurity trends.
Key Healthcare Data Breach Statistics
- The HHS Office for Civil Rights recorded 772 large healthcare data breaches affecting 139.7 million individuals during 2024.
- IBM’s Cost of a Data Breach Report 2025 found the average healthcare data breach cost reached $7.42 million, the highest among all industries.
- Healthcare has remained the most expensive industry for data breaches for 14 consecutive years, according to IBM.
- The HHS Office for Civil Rights reported 66 large healthcare data breaches affecting approximately 8.7 million individuals during March 2026.
- The Change Healthcare cyberattack affected an estimated 190 million individuals, making it the largest healthcare data breach reported in U.S. history.
- IBM reported the global average cost of a data breach across all industries was $4.44 million in 2025, compared with $7.42 million for healthcare.
- Sophos found that 67% of healthcare organizations experienced a ransomware attack during 2024.
- The average healthcare data breach cost was approximately 67% higher than the global cross-industry average in IBM’s 2025 report.
- More than 19 million individuals were affected by healthcare data breaches reported during the first half of 2026.
- Under the HIPAA Breach Notification Rule, healthcare organizations must report breaches affecting 500 or more individuals to the HHS Office for Civil Rights.
Latest Healthcare Data Breach Statistics (2026)
- The HHS Office for Civil Rights received reports of 66 healthcare data breaches affecting 500 or more individuals during March 2026.
- Those March 2026 breaches exposed the protected health information of approximately 8.7 million individuals.
- More than 19 million individuals were affected by healthcare data breaches reported during the first half of 2026.
- As of April 30, 2026, the HHS Office for Civil Rights had 936 large healthcare data breach investigations listed as open or pending.
- In 2025, 772 reportable healthcare data breaches exposed the information of 139,721,832 individuals.
- Between September 2025 and January 2026, the HHS Office for Civil Rights received an average of 46.2 large healthcare breach reports per month.
- During the previous five-month period (April–August 2025), the HHS Office for Civil Rights received an average of 68.6 large healthcare breach reports per month.
Also Read: Data Breach Statistics for 2025–2026
Healthcare Data Breach Cost Statistics
- IBM’s Cost of a Data Breach Report 2025 found the average healthcare data breach cost reached $7.42 million, the highest among all industries.
- Healthcare has remained the costliest industry for data breaches for 14 consecutive years, according to IBM.
- The global average cost of a data breach across all industries was $4.44 million in 2025, making healthcare breaches approximately 67% more expensive.
- Organizations that extensively used AI and automation reduced the average cost of a data breach by approximately $2.2 million compared to organizations with limited AI adoption, according to IBM.
- Healthcare organizations remain the only industry where the average data breach cost exceeds $7 million.
- The Change Healthcare cyberattack disrupted healthcare payment processing across the United States, with some providers reporting revenue losses of up to $100 million per day during the outage.
- The 2024 Change Healthcare cyberattack ultimately affected an estimated 190 million individuals, making it the largest healthcare data breach reported in U.S. history.
- IBM reported that organizations using security AI and automation extensively identified and contained breaches more than 100 days faster than organizations that did not, reducing overall breach costs.
Healthcare Ransomware Statistics
- Sophos reported that 67% of healthcare organizations experienced a ransomware attack during 2024.
- Among healthcare organizations hit by ransomware, 53% paid the ransom to recover their data.
- The median ransomware payment across all industries fell to $1 million in 2024, according to Sophos.
- Healthcare organizations spent an average of $2.57 million recovering from ransomware attacks, excluding ransom payments.
- 98% of healthcare organizations recovered at least some encrypted data after a ransomware attack.
- Only 22% of healthcare organizations recovered all encrypted data using backups alone.
- The Change Healthcare ransomware attack affected approximately 190 million individuals, making it the largest known healthcare ransomware incident to date.
- Healthcare ransomware attacks increased by 32% in 2024 compared with the previous year, according to healthcare cyber insurance claims data.
Healthcare Records Exposed Statistics
- Large healthcare data breaches affected 139.7 million individuals in 2025, according to the latest HHS OCR breach data.
- In 2024, healthcare data breaches exposed the protected health information of 289.2 million individuals, setting a record for the highest annual total.
- The Change Healthcare cyberattack affected approximately 192.7 million individuals, making it the largest healthcare data breach ever reported in the United States.
- The number of individuals affected by healthcare data breaches declined by 51.8% year over year in 2025 compared with 2024.
- The average healthcare data breach size fell from 389,707 individuals in 2024 to 86,699 individuals in 2025.
- The median healthcare data breach size declined from 6,702 individuals in 2024 to 4,011 individuals in 2025.
- Healthcare organizations reported 9 data breaches affecting more than 1 million individuals in 2025, compared with 18 mega breaches in 2024.
- During 2024, an average of 792,226 individuals per day were affected by large healthcare data breaches.
Healthcare Data Breach Cause Statistics
- Hacking and IT incidents accounted for 74.5% of all large healthcare data breaches reported in 2025 (575 of 772 breaches).
- Unauthorized access and disclosure incidents represented 17.6% of healthcare data breaches in 2025 (136 breaches).
- Network servers were involved in 61.5% of healthcare data breaches reported in 2025.
- Compromised email accounts accounted for 24.9% of healthcare data breaches in 2025.
- Paper records and films were involved in 5.6% of reported healthcare data breaches in 2025.
- Unauthorized access to electronic medical records accounted for 4.6% of healthcare data breaches in 2025.
- In 2025, 523 healthcare data breaches were reported by healthcare providers, compared with 128 reported by business associates and 56 by health plans.
Healthcare HIPAA Statistics
- The HIPAA Breach Notification Rule requires covered entities to notify the HHS Office for Civil Rights when a breach affects 500 or more individuals.
- Covered entities must notify affected individuals without unreasonable delay and no later than 60 days after discovering a reportable breach.
- The HHS Office for Civil Rights may impose civil monetary penalties of up to $2,134,831 per violation category per year (2025 adjusted amount), depending on the level of culpability.
- HIPAA requires covered entities to retain breach notification documentation for 6 years.
- The HIPAA Privacy Rule was first issued in 2000, while the Security Rule became effective in 2005.
- The HITECH Act of 2009 introduced the HIPAA Breach Notification Rule, requiring notification for unsecured protected health information (PHI) breaches.
- Under HIPAA, covered entities must notify prominent media outlets when a breach affects more than 500 residents of a state or jurisdiction.
- Business associates must notify covered entities of a reportable breach without unreasonable delay and no later than 60 days after discovery.
Healthcare Cybersecurity Investment Statistics
- Healthcare organizations allocated an average of 10.7% of their IT budgets to cybersecurity in 2025, according to HIMSS Cybersecurity Survey findings.
- IBM reported that organizations extensively using AI and automation reduced breach costs by approximately $2.2 million compared with organizations with limited AI adoption.
- Organizations with extensive AI and automation identified and contained data breaches more than 100 days faster than organizations without these capabilities, according to IBM.
- Multi-factor authentication (MFA) adoption exceeded 90% among surveyed healthcare organizations in recent HIMSS cybersecurity studies.
- More than 80% of healthcare organizations reported increasing cybersecurity spending during 2025 to address ransomware and regulatory risks.
- Healthcare continues to rank among the top five most targeted critical infrastructure sectors for cyberattacks reported by U.S. government agencies.
Also Read: Cybersecurity Statistics & Trends Reshaping Enterprise Security 2026
Future Healthcare Data Breach Trends
- Gartner projects that by 2027, 75% of the global population will have its personal data covered by modern privacy regulations.
- IDC forecasts worldwide spending on cybersecurity solutions to exceed $300 billion annually by 2028.
- AI-assisted cyberattacks are expected to increase in frequency through 2026, driving additional investment in AI-powered threat detection and automated incident response across healthcare.
- The global cybersecurity workforce gap remained above 4 million professionals in 2025, according to ISC².
- Cyber insurance adoption among healthcare organizations continued to increase during 2025 as ransomware and third-party risks grew.
Conclusion
Healthcare data breaches continue to affect millions of patients and cost organizations billions of dollars each year. The latest statistics show that ransomware, third-party compromises, cloud security risks, and phishing attacks remain the primary drivers of large-scale healthcare incidents, while breach costs continue to outpace every other industry.
Organizations are responding by increasing investments in AI-powered security, zero-trust architectures, identity protection, employee training, and regulatory compliance. As cyber threats evolve, tracking healthcare data breach statistics helps security leaders, healthcare providers, researchers, and policymakers understand emerging risks and benchmark cybersecurity strategies.
This article compiles healthcare data breach statistics from trusted sources, including the U.S. Department of Health and Human Services (HHS), IBM, HIPAA Journal, Sophos, Verizon, FBI IC3, HIMSS, Gartner, IDC, and other reputable industry research. Wherever possible, we prioritize the latest available 2026 data, followed by recent annual reports and verified long-term industry studies.
FAQs
1. How many healthcare data breaches have been reported in 2026?
More than 19 million individuals were affected by healthcare data breaches during the first half of 2026. The HHS Office for Civil Rights (OCR) continues to receive reports of breaches affecting 500 or more individuals, with hacking and IT incidents remaining the leading cause of reported healthcare data breaches.
2. What is the average cost of a healthcare data breach?
According to IBM’s Cost of a Data Breach Report 2025, the average healthcare data breach cost was $7.42 million, the highest among all industries.
3. What is the largest healthcare data breach in U.S. history?
The Change Healthcare cyberattack is the largest reported healthcare data breach, affecting approximately 190–193 million individuals.
4. What is the biggest cause of healthcare data breaches?
Hacking and IT incidents accounted for 74.5% of large healthcare data breaches reported in 2025, making them the leading cause of healthcare data breaches.
5. Where do these statistics come from?
The statistics in this article are compiled from authoritative sources, including HHS OCR, IBM, HIPAA Journal, Sophos, Verizon, FBI IC3, HIMSS, Gartner, and other recognized cybersecurity research organizations.

