Skip to main content

CNiC Solutions

Hospital server room beside a clinical ward, illustrating healthcare data breach risk and its link to patient care

Healthcare has been the most expensive industry in the world to breach for 13 straight years, and the numbers behind that record are staggering: more than 700 large breaches reported every year, a single 2024 attack that exposed 190 million people, and an average breach cost of $7.42 million. This roundup pulls together the healthcare data breach statistics that matter, from records exposed and breach costs to how attackers get in and what a breach does to patient care, with every figure traced to a primary source.

Key takeaways

  • U.S. healthcare reported 725 large breaches in 2024 and 710 in 2025 to HHS OCR, roughly two every day for years running.
  • The 2024 Change Healthcare attack exposed about 190 million people, the largest healthcare breach ever and about two thirds of all records breached that year.
  • Total individuals affected swung from 289 million in 2024 to 61.6 million in 2025, a 78.7% drop that shows how one mega-breach distorts a whole year.
  • Healthcare is the costliest industry to breach at $7.42 million on average (IBM), for the 13th consecutive year, versus a $4.44 million global average.
  • In the Verizon DBIR, 67% of healthcare breaches came from external actors and espionage motives jumped from 1% to 16% in a single year.
  • 69% of breached healthcare organizations reported disrupted patient care, and 28% reported increased patient mortality (Ponemon and Proofpoint).
  • HHS OCR resolved 21 HIPAA enforcement actions in 2025 collecting more than $8.3 million, with most citing risk-analysis failures.

What’s in This Guide

1How Many Breaches and How Many Records

The clearest window into healthcare breaches is the federal government’s own. Under the HIPAA Breach Notification Rule, any breach affecting 500 or more individuals must be reported to the HHS Office for Civil Rights, which publishes every one on a public portal often called the “Wall of Shame.” That portal turns healthcare into one of the few industries with a near-complete, primary-source record of its breaches. What it shows is a sector under relentless, sustained pressure.

725
Large healthcare data breaches, each affecting 500 or more individuals, reported to HHS OCR in 2024, the third straight year above 700.HHS OCR Breach Portal
710
Large healthcare data breaches reported to HHS OCR in 2025, holding the sector above two reported breaches per day.HHS OCR Breach Portal
289M
Individuals whose records were exposed in 2024, an all-time high driven by a single mega-breach.HHS OCR Breach Portal
61.6M
Individuals affected in 2025, a 78.7% drop from 2024 even though the number of breaches barely changed.HHS OCR Breach Portal

 

 

Infographic of key healthcare data breach stats: 190M exposed, 700+ breaches a year, $7.42M cost, 67% external, 69% care disrupted
The headline healthcare data breach figures, compiled from HHS OCR, IBM, Verizon and the Ponemon Institute.

 

 

Two numbers in that list explain the whole story of healthcare breach data. The breach count barely moved between 2024 and 2025, from 725 to 710. Yet the number of people affected collapsed by nearly 80%, from 289 million to 61.6 million. Breach volume and breach damage do not move together, because a single catastrophic attack can dwarf hundreds of ordinary ones. That is exactly what happened in 2024, and it is the single most important thing to understand before reading any healthcare breach headline.

HHS OCR breach portal 2024 2025
Large breaches reported (500+ individuals) 725 710
Individuals affected 289.2 million 61.6 million
Average large breaches per day ~2.0 ~1.9
Mean breach size (individuals) 379,633 86,699
Median breach size (individuals) 4,335 4,011

That quieter middle of the market, practices and mid-size providers without in-house security staff, is precisely who CNiC protects with IT and security built for healthcare organizations. The public portal makes healthcare’s risk measurable in a way few industries can match, and the measurement is unambiguous.

See Managed IT & Security for Healthcare

Source: HHS Office for Civil Rights Breach Portal

2The Change Healthcare Effect: When One Breach Rewrites the Year

No single event has shaped healthcare breach statistics like the ransomware attack on Change Healthcare. In February 2024, attackers compromised the UnitedHealth Group subsidiary that processes a large share of U.S. medical claims. After revising its estimate upward twice, UnitedHealth confirmed the breach exposed the protected health information of about 190 million people, more than half the U.S. population and the largest healthcare data breach ever recorded.

190M
Individuals whose data was compromised in the 2024 Change Healthcare ransomware attack, the largest healthcare breach ever reported.HHS OCR Breach Portal / UnitedHealth Group
~66%
Share of all 2024 healthcare records exposed that came from Change Healthcare alone, about 190 million of 289 million.CNiC analysis of HHS OCR Breach Portal data
13.9M
Individuals affected by the Aflac breach, the largest single healthcare breach of 2025, a fraction of Change Healthcare’s scale.HHS OCR Breach Portal

The attack did more than break a record. It exposed how fragile a hyper-consolidated healthcare supply chain has become. Because Change Healthcare sits between providers, pharmacies and payers, the outage stalled claims and prescriptions nationwide for weeks. UnitedHealth reportedly paid a ransom of around $22 million to the ALPHV/BlackCat group, yet stolen data still surfaced on dark-web leak sites after the attackers regrouped under a new banner. Paying did not deliver the outcome the payment was supposed to buy.

 

 

Infographic showing Change Healthcare's 190 million records as about two thirds of all 289 million healthcare records exposed in 2024
How a single mega-breach distorts a year: Change Healthcare was about two thirds of all 2024 healthcare records exposed (HHS OCR).

 

 

Set the single event against the year and the distortion is impossible to miss. Of the roughly 289 million records exposed across all 725 breaches in 2024, about 190 million came from Change Healthcare alone. Strip out that one incident and the remaining 724 breaches account for closer to 99 million people, a figure much nearer to 2025’s 61.6 million. One attack, in other words, more than doubled an entire year’s apparent damage.

Largest reported healthcare breaches Individuals Year
Change Healthcare (UnitedHealth Group) 190,000,000 2024
Anthem Inc. 78,800,000 2015
Kaiser Foundation Health Plan 13,400,000 2024
Aflac 13,924,906 2025
Ascension Health 5,600,000 2024
Yale New Haven Health System 5,556,702 2025
Episource, LLC 5,418,866 2025
Blue Shield of California 4,700,000 2025

Recovering from a ransomware event without paying depends entirely on having isolated, tested backups ready before the attack, the single most reliable path back to operation.

Explore Backup & Disaster Recovery

For the cross-industry picture behind these figures, see our roundup of the average cost of a data breach across all industries and the latest ransomware attack trends.

Source: HHS Office for Civil Rights Breach Portal

3Why Healthcare Is the Costliest Industry to Breach

When a healthcare breach is fully accounted for, it lands at the top of every industry ranking, and it has for well over a decade. IBM’s Cost of a Data Breach Report puts the average healthcare breach at $7.42 million, the highest of any sector for the 13th consecutive year. That figure actually fell from the prior year’s $9.77 million, thanks largely to faster detection driven by security automation, but healthcare still runs far ahead of every other industry and roughly 1.7 times the global cross-industry average.

$7.42M
Average cost of a healthcare data breach, the highest of any industry, down from $9.77 million the year before.IBM Cost of a Data Breach Report
13 yrs
Consecutive years healthcare has been the most expensive industry in the world to breach.IBM Cost of a Data Breach Report
$4.44M
Global average breach cost across all industries, meaning a healthcare breach runs about 1.7 times higher.IBM Cost of a Data Breach Report
279 days
Average time to identify and contain a healthcare breach, the longest lifecycle of any industry, versus a 241-day global average.IBM Cost of a Data Breach Report
Average Data Breach Cost: Healthcare vs. Global

Healthcare (prior year)
$9.77M
Healthcare (latest)
$7.42M
Global, all industries
$4.44M

Source: IBM Cost of a Data Breach Report.

Healthcare stays the most expensive sector for structural reasons. Medical records are the richest identity dossiers in existence, bundling Social Security numbers, insurance details, diagnoses and payment data that cannot be reset like a password. That makes them lucrative on the dark web and slow to remediate. Add the longest breach lifecycle of any industry, 279 days on average to find and contain an intrusion, and every breach has more time to spread and more data to expose before it is stopped.

Turning that risk into a budget, a roadmap and a defensible security posture is exactly the work of a fractional technology leader.

Explore Virtual CIO Services

Source: IBM Cost of a Data Breach Report

 

CNiC Solutions — Cybersecurity

 

4How Healthcare Networks Actually Get Breached

The public portal records not just how many breaches happen but how. Two data sources, the HHS OCR portal and the Verizon Data Breach Investigations Report, agree on the shape of the threat: healthcare breaches are overwhelmingly deliberate attacks by outsiders, they start with hacking rather than lost laptops, and they increasingly aim at the systems where records live in bulk.

81.2%
Share of 2024 large healthcare breaches caused by hacking and other IT incidents, 589 of 725 breaches, versus 15.7% from unauthorized access or disclosure.HHS OCR Breach Portal
61.5%
Share of breached protected health information located on network servers in 2025, with email accounts a distant second at 24.9%.HHS OCR Breach Portal
67%
Healthcare breaches carried out by external actors in the Verizon DBIR, with 30% involving insiders and 4% business partners.Verizon Data Breach Investigations Report
16%
Healthcare breaches with an espionage motive, up from just 1% two years earlier, though 90% remain financially motivated.Verizon Data Breach Investigations Report

The Verizon data captures a clear shift in tactics. System intrusion, the multi-step pattern that includes hacking, malware and ransomware, surged from 36% to 53% of healthcare breaches to become the leading category, while the old top cause, simple staff errors like misdelivered records, receded. Attackers are working harder and reaching deeper. The move of records onto network servers means a single successful intrusion now exposes far more people than a lost device ever could, which is why 61.5% of all breached PHI now sits on servers.

How healthcare breaches happen Figure Source
Breaches from hacking / IT incidents (2024) 81.2% HHS OCR
Breaches from unauthorized access / disclosure (2024) 15.7% HHS OCR
Breached PHI located on network servers (2025) 61.5% HHS OCR
Breached PHI located in email accounts (2025) 24.9% HHS OCR
Breaches by external actors 67% Verizon DBIR
Breaches involving insiders 30% Verizon DBIR
System intrusion as the top attack pattern 53% (up from 36%) Verizon DBIR
Breaches with an espionage motive 16% (up from 1%) Verizon DBIR
Myth: “We are a small practice, too small for hackers to bother with.”

The OCR data says otherwise. The median breach affects about 4,000 people, which is the size of a small clinic’s patient list, not a hospital system’s. Attackers automate their way into small providers precisely because those organizations combine valuable medical records with thin or nonexistent security staffing. Ransomware crews in particular favor targets that cannot absorb downtime and lack tested backups, a profile that describes most small practices. Being small is not camouflage; it is often the reason you were chosen.

The controls that break this chain are the disciplined basics applied consistently: multi-factor authentication on every account, phishing-resistant email defenses, patched servers, network segmentation and continuous monitoring. Running them day and night across a clinical environment is the core of managed security.

Explore Cybersecurity Services

For a closer look at the entry point behind most intrusions, our phishing attack data and our manufacturing cybersecurity data show how the same patterns play out across sectors.

Source: HHS Office for Civil Rights Breach Portal | Verizon Data Breach Investigations Report

5When a Breach Reaches the Bedside

In most industries a data breach is a financial and reputational event. In healthcare it can become a clinical one. When ransomware locks the systems that run a hospital, clinicians lose access to records, imaging, medication systems and scheduling, and care slows or stops. The Ponemon Institute and Proofpoint measured this directly in their study of U.S. healthcare providers, and the findings move the conversation from dollars to patient outcomes.

69%
Of healthcare organizations hit by a cyberattack reported a disruption to patient care as a direct result.Ponemon Institute / Proofpoint, Cyber Insecurity in Healthcare
28%
Of organizations that suffered an attack reported an increase in patient mortality rates, up five points year over year.Ponemon Institute / Proofpoint, Cyber Insecurity in Healthcare
59%
Of surveyed healthcare organizations had experienced a ransomware attack, the threat most associated with care disruption.Ponemon Institute / Proofpoint, Cyber Insecurity in Healthcare

 

 

Funnel infographic: 69% patient care disruption narrowing to 28% increased mortality after a healthcare cyberattack
How a healthcare cyberattack becomes a clinical risk, from 69% care disruption down to 28% increased mortality (Ponemon and Proofpoint).

 

 

The survey detail shows exactly how a breach turns into a clinical risk. Among organizations hit by ransomware, the most common consequences were operational delays that compound into patient harm: longer hospital stays, delayed procedures and tests, complications and diversions to other facilities. Each of these is a documented pathway from a locked server to a worse outcome for a real patient.

Effects of Ransomware on Patient Care (share of affected organizations)

Longer length of stay
58%
Poor outcomes from delays
56%
More procedure complications
53%
More patient diversions/transfers
52%

Source: Ponemon Institute and Proofpoint, Cyber Insecurity in Healthcare.

Keeping clinical systems available, monitored and quick to restore is the everyday job of a managed IT partner that understands healthcare’s stakes.

Explore Managed IT Services

Source: Ponemon Institute and Proofpoint, Cyber Insecurity in Healthcare

6The Regulatory Bill: HIPAA Enforcement and Penalties

A breach cost does not stop at recovery and downtime. Healthcare is uniquely regulated, and a breach can trigger an HHS Office for Civil Rights investigation, financial penalties and years of corrective-action oversight. OCR enforcement has sharpened in recent years, with a particular focus on the failure that precedes most breaches: not knowing where your risks are in the first place.

21
HIPAA enforcement actions resolved by HHS OCR in 2025 through settlements and civil monetary penalties.HHS OCR Enforcement
$8.3M+
Total collected through HHS OCR HIPAA settlements and penalties in 2025.HHS OCR Enforcement
76%
Share of 2025 HHS OCR enforcement actions that cited a failure to conduct an adequate security risk analysis.HHS OCR Enforcement

The pattern in the enforcement data is a gift to any provider willing to read it: the single most-cited violation is the failure to perform a thorough, organization-wide risk analysis, the foundational requirement of the HIPAA Security Rule. OCR has also run a dedicated Risk Analysis Initiative and a ransomware enforcement push, signaling that “we did not know we had that gap” is no longer a defense. The organizations penalized were not always breached by sophisticated attackers; many simply could not show they had assessed their risks.

Notable 2025 HHS OCR HIPAA settlement Penalty
Solara Medical Supplies (phishing / risk analysis) $3,000,000
Warby Parker (risk analysis) $1,500,000
Total across all 21 resolved actions more than $8.3 million

Source: HHS Office for Civil Rights HIPAA Enforcement

Summary Table: Every Statistic at a Glance

Statistic Figure Source
Large healthcare breaches reported (2024) 725 HHS OCR
Large healthcare breaches reported (2025) 710 HHS OCR
Individuals affected (2024) 289.2 million HHS OCR
Individuals affected (2025) 61.6 million (down 78.7%) HHS OCR
Average large breaches per day ~2 HHS OCR
Mean breach size (2025) 86,699 individuals HHS OCR
Median breach size (2025) 4,011 individuals HHS OCR
Largest healthcare breach ever (Change Healthcare) 190 million HHS OCR / UnitedHealth
Share of 2024 records from Change Healthcare alone ~66% CNiC analysis of HHS OCR data
Largest 2025 breach (Aflac) 13.9 million HHS OCR
Average healthcare breach cost $7.42 million IBM
Prior-year healthcare breach cost $9.77 million IBM
Consecutive years healthcare is costliest 13 IBM
Global average breach cost (all industries) $4.44 million IBM
Healthcare breach lifecycle (identify + contain) 279 days IBM
Breaches from hacking / IT incidents (2024) 81.2% HHS OCR
Breached PHI located on network servers (2025) 61.5% HHS OCR
Healthcare breaches by external actors 67% Verizon DBIR
System intrusion as top attack pattern 53% (up from 36%) Verizon DBIR
Espionage-motivated breaches 16% (up from 1%) Verizon DBIR
Organizations reporting disrupted patient care 69% Ponemon / Proofpoint
Organizations reporting increased mortality 28% Ponemon / Proofpoint
Organizations that suffered ransomware 59% Ponemon / Proofpoint
HHS OCR HIPAA enforcement actions (2025) 21 HHS OCR
Total HIPAA penalties collected (2025) more than $8.3 million HHS OCR
Enforcement actions citing risk-analysis failures 76% HHS OCR

Frequently Asked Questions

How many healthcare data breaches happen each year?

More than 700 large healthcare data breaches, each affecting 500 or more individuals, have been reported to the U.S. Department of Health and Human Services Office for Civil Rights (HHS OCR) every year for the past several years. There were 725 large breaches in 2024 and 710 in 2025, an average of roughly two reported large breaches every day. On top of these, thousands of smaller breaches affecting fewer than 500 people are reported each year.

What is the largest healthcare data breach ever recorded?

The February 2024 ransomware attack on Change Healthcare, a UnitedHealth Group subsidiary, is the largest healthcare data breach ever recorded. UnitedHealth confirmed that the protected health information of roughly 190 million people was compromised, meaning the breach touched more than half of the entire U.S. population. It single-handedly accounted for about two thirds of all healthcare records exposed in 2024.

How much does a healthcare data breach cost?

According to IBM’s Cost of a Data Breach Report, the average healthcare data breach cost $7.42 million, down from $9.77 million the prior year but still the highest of any industry. Healthcare has been the costliest sector for a data breach for 13 consecutive years, running roughly 1.7 times higher than the global cross-industry average of $4.44 million. Healthcare also has the longest breach lifecycle of any industry at about 279 days to identify and contain.

What causes most healthcare data breaches?

Hacking and IT incidents cause the large majority of healthcare breaches, accounting for about 81% of large breaches reported to HHS OCR and roughly 61% of exposed records sitting on network servers. In the Verizon Data Breach Investigations Report, 67% of healthcare breaches were carried out by external actors, system intrusion became the top attack pattern at 53%, and espionage-motivated breaches jumped from 1% to 16% in a single year. Phishing and stolen credentials remain the most common entry points.

Can a data breach affect patient safety?

Yes. In the Ponemon Institute and Proofpoint study of U.S. healthcare providers, 69% of organizations that suffered a cyberattack reported disruption to patient care, and 28% of those hit reported an increase in patient mortality. Ransomware attacks in particular led to longer lengths of stay (58%), poor outcomes from delayed procedures and tests (56%), more procedure complications (53%) and more patients diverted to other facilities (52%). A healthcare breach is not only a data problem; it can become a clinical one.

Methodology and Sources

How this roundup was compiled

Every figure in this article is drawn directly from a Tier 1 primary source: the U.S. government’s public breach portal, IBM’s and Verizon’s annual reports, and the Ponemon Institute’s independent healthcare study. No statistic is sourced from a blog citing another blog, and no figure has been invented, estimated or rounded beyond the source’s own reporting. Breach counts, records exposed, causes and locations come from the HHS OCR breach portal, which categorizes every reported breach of 500 or more individuals. Where a report’s most recent edition covers the prior calendar year, we cite it as the latest available data. The CNiC Solutions Analysis box combines two independent Tier 1 sources and is clearly labeled as original interpretation.

Primary sources:

 

author avatar
David McFarlene Founder & CEO
David McFarlene is the owner and founder of CNiC Solutions, a trusted IT services and cybersecurity company serving the Houston, TX area. With over 20 years of experience in managed IT, infrastructure design, cloud solutions, and data security, David helps businesses and homeowners stay protected and productive through dependable, personalized technology support. He leads the CNiC Solutions team with a focus on reliability, transparency, and long-term relationships, ensuring clients always have a knowledgeable expert they can trust.
back to blog