Healthcare has been the most expensive industry in the world to breach for 13 straight years, and the numbers behind that record are staggering: more than 700 large breaches reported every year, a single 2024 attack that exposed 190 million people, and an average breach cost of $7.42 million. This roundup pulls together the healthcare data breach statistics that matter, from records exposed and breach costs to how attackers get in and what a breach does to patient care, with every figure traced to a primary source.
The clearest window into healthcare breaches is the federal government’s own. Under the HIPAA Breach Notification Rule, any breach affecting 500 or more individuals must be reported to the HHS Office for Civil Rights, which publishes every one on a public portal often called the “Wall of Shame.” That portal turns healthcare into one of the few industries with a near-complete, primary-source record of its breaches. What it shows is a sector under relentless, sustained pressure.

Two numbers in that list explain the whole story of healthcare breach data. The breach count barely moved between 2024 and 2025, from 725 to 710. Yet the number of people affected collapsed by nearly 80%, from 289 million to 61.6 million. Breach volume and breach damage do not move together, because a single catastrophic attack can dwarf hundreds of ordinary ones. That is exactly what happened in 2024, and it is the single most important thing to understand before reading any healthcare breach headline.
| HHS OCR breach portal | 2024 | 2025 |
|---|---|---|
| Large breaches reported (500+ individuals) | 725 | 710 |
| Individuals affected | 289.2 million | 61.6 million |
| Average large breaches per day | ~2.0 | ~1.9 |
| Mean breach size (individuals) | 379,633 | 86,699 |
| Median breach size (individuals) | 4,335 | 4,011 |
In 2025 the average (mean) breach affected 86,699 people, but the typical (median) breach affected just 4,011. That 20-fold gap is the fingerprint of a skewed distribution: a handful of enormous breaches pull the average far above what most organizations actually experience. For a mid-size clinic or practice, the median is the more honest planning number. Most healthcare breaches are not headline events; they are quieter incidents at organizations without a dedicated security team.
That quieter middle of the market, practices and mid-size providers without in-house security staff, is precisely who CNiC protects with IT and security built for healthcare organizations. The public portal makes healthcare’s risk measurable in a way few industries can match, and the measurement is unambiguous.
See Managed IT & Security for Healthcare
Source: HHS Office for Civil Rights Breach Portal
No single event has shaped healthcare breach statistics like the ransomware attack on Change Healthcare. In February 2024, attackers compromised the UnitedHealth Group subsidiary that processes a large share of U.S. medical claims. After revising its estimate upward twice, UnitedHealth confirmed the breach exposed the protected health information of about 190 million people, more than half the U.S. population and the largest healthcare data breach ever recorded.
The attack did more than break a record. It exposed how fragile a hyper-consolidated healthcare supply chain has become. Because Change Healthcare sits between providers, pharmacies and payers, the outage stalled claims and prescriptions nationwide for weeks. UnitedHealth reportedly paid a ransom of around $22 million to the ALPHV/BlackCat group, yet stolen data still surfaced on dark-web leak sites after the attackers regrouped under a new banner. Paying did not deliver the outcome the payment was supposed to buy.

Set the single event against the year and the distortion is impossible to miss. Of the roughly 289 million records exposed across all 725 breaches in 2024, about 190 million came from Change Healthcare alone. Strip out that one incident and the remaining 724 breaches account for closer to 99 million people, a figure much nearer to 2025’s 61.6 million. One attack, in other words, more than doubled an entire year’s apparent damage.
| Largest reported healthcare breaches | Individuals | Year |
|---|---|---|
| Change Healthcare (UnitedHealth Group) | 190,000,000 | 2024 |
| Anthem Inc. | 78,800,000 | 2015 |
| Kaiser Foundation Health Plan | 13,400,000 | 2024 |
| Aflac | 13,924,906 | 2025 |
| Ascension Health | 5,600,000 | 2024 |
| Yale New Haven Health System | 5,556,702 | 2025 |
| Episource, LLC | 5,418,866 | 2025 |
| Blue Shield of California | 4,700,000 | 2025 |
Change Healthcare was not most victims’ vendor of choice; it was a processor buried deep in the claims chain that few patients had heard of. That is the modern healthcare risk: your own defenses can be excellent, and a breach at a business associate three steps away still exposes your patients. It is why HIPAA extends liability to business associates, and why vetting and monitoring third parties now matters as much as securing your own network.
Recovering from a ransomware event without paying depends entirely on having isolated, tested backups ready before the attack, the single most reliable path back to operation.
Explore Backup & Disaster Recovery
For the cross-industry picture behind these figures, see our roundup of the average cost of a data breach across all industries and the latest ransomware attack trends.
Source: HHS Office for Civil Rights Breach Portal
When a healthcare breach is fully accounted for, it lands at the top of every industry ranking, and it has for well over a decade. IBM’s Cost of a Data Breach Report puts the average healthcare breach at $7.42 million, the highest of any sector for the 13th consecutive year. That figure actually fell from the prior year’s $9.77 million, thanks largely to faster detection driven by security automation, but healthcare still runs far ahead of every other industry and roughly 1.7 times the global cross-industry average.
Source: IBM Cost of a Data Breach Report.
Healthcare stays the most expensive sector for structural reasons. Medical records are the richest identity dossiers in existence, bundling Social Security numbers, insurance details, diagnoses and payment data that cannot be reset like a password. That makes them lucrative on the dark web and slow to remediate. Add the longest breach lifecycle of any industry, 279 days on average to find and contain an intrusion, and every breach has more time to spread and more data to expose before it is stopped.
Two Tier 1 sources, read together, reveal why a single average is a poor planning number for any one organization. IBM reports a $7.42 million mean healthcare breach cost. HHS OCR portal data shows that in 2025 the mean breach affected 86,699 people while the median affected just 4,011, a roughly 20-to-1 gap. Because cost scales with the number of records exposed, that same skew applies to dollars: a typical small-practice breach costs a small fraction of $7.42 million, while a mega-breach costs many multiples of it. Formula: IBM mean cost ($7.42M) interpreted against OCR breach-size skew (86,699 mean vs 4,011 median) shows the mean is inflated by a few catastrophic events. The practical takeaway is that most providers should plan around a smaller, more frequent breach, not the headline average. Calculation and interpretation original to CNiC Solutions.
Turning that risk into a budget, a roadmap and a defensible security posture is exactly the work of a fractional technology leader.
Source: IBM Cost of a Data Breach Report
The public portal records not just how many breaches happen but how. Two data sources, the HHS OCR portal and the Verizon Data Breach Investigations Report, agree on the shape of the threat: healthcare breaches are overwhelmingly deliberate attacks by outsiders, they start with hacking rather than lost laptops, and they increasingly aim at the systems where records live in bulk.
The Verizon data captures a clear shift in tactics. System intrusion, the multi-step pattern that includes hacking, malware and ransomware, surged from 36% to 53% of healthcare breaches to become the leading category, while the old top cause, simple staff errors like misdelivered records, receded. Attackers are working harder and reaching deeper. The move of records onto network servers means a single successful intrusion now exposes far more people than a lost device ever could, which is why 61.5% of all breached PHI now sits on servers.
| How healthcare breaches happen | Figure | Source |
|---|---|---|
| Breaches from hacking / IT incidents (2024) | 81.2% | HHS OCR |
| Breaches from unauthorized access / disclosure (2024) | 15.7% | HHS OCR |
| Breached PHI located on network servers (2025) | 61.5% | HHS OCR |
| Breached PHI located in email accounts (2025) | 24.9% | HHS OCR |
| Breaches by external actors | 67% | Verizon DBIR |
| Breaches involving insiders | 30% | Verizon DBIR |
| System intrusion as the top attack pattern | 53% (up from 36%) | Verizon DBIR |
| Breaches with an espionage motive | 16% (up from 1%) | Verizon DBIR |
The OCR data says otherwise. The median breach affects about 4,000 people, which is the size of a small clinic’s patient list, not a hospital system’s. Attackers automate their way into small providers precisely because those organizations combine valuable medical records with thin or nonexistent security staffing. Ransomware crews in particular favor targets that cannot absorb downtime and lack tested backups, a profile that describes most small practices. Being small is not camouflage; it is often the reason you were chosen.
The controls that break this chain are the disciplined basics applied consistently: multi-factor authentication on every account, phishing-resistant email defenses, patched servers, network segmentation and continuous monitoring. Running them day and night across a clinical environment is the core of managed security.
Explore Cybersecurity Services
For a closer look at the entry point behind most intrusions, our phishing attack data and our manufacturing cybersecurity data show how the same patterns play out across sectors.
Source: HHS Office for Civil Rights Breach Portal | Verizon Data Breach Investigations Report
In most industries a data breach is a financial and reputational event. In healthcare it can become a clinical one. When ransomware locks the systems that run a hospital, clinicians lose access to records, imaging, medication systems and scheduling, and care slows or stops. The Ponemon Institute and Proofpoint measured this directly in their study of U.S. healthcare providers, and the findings move the conversation from dollars to patient outcomes.

The survey detail shows exactly how a breach turns into a clinical risk. Among organizations hit by ransomware, the most common consequences were operational delays that compound into patient harm: longer hospital stays, delayed procedures and tests, complications and diversions to other facilities. Each of these is a documented pathway from a locked server to a worse outcome for a real patient.
Source: Ponemon Institute and Proofpoint, Cyber Insecurity in Healthcare.
In a hospital, the line between an IT problem and a patient-safety problem is thin. A ransomware event that takes an electronic health record offline for days forces a return to paper, slows every clinical decision, and pushes ambulances to other hospitals. That is why resilient, monitored infrastructure and a rehearsed recovery plan are not just IT hygiene in healthcare; they are part of the standard of care. The goal is to turn a potential multi-day outage into a contained incident measured in hours.
Keeping clinical systems available, monitored and quick to restore is the everyday job of a managed IT partner that understands healthcare’s stakes.
Source: Ponemon Institute and Proofpoint, Cyber Insecurity in Healthcare
A breach cost does not stop at recovery and downtime. Healthcare is uniquely regulated, and a breach can trigger an HHS Office for Civil Rights investigation, financial penalties and years of corrective-action oversight. OCR enforcement has sharpened in recent years, with a particular focus on the failure that precedes most breaches: not knowing where your risks are in the first place.
The pattern in the enforcement data is a gift to any provider willing to read it: the single most-cited violation is the failure to perform a thorough, organization-wide risk analysis, the foundational requirement of the HIPAA Security Rule. OCR has also run a dedicated Risk Analysis Initiative and a ransomware enforcement push, signaling that “we did not know we had that gap” is no longer a defense. The organizations penalized were not always breached by sophisticated attackers; many simply could not show they had assessed their risks.
| Notable 2025 HHS OCR HIPAA settlement | Penalty |
|---|---|
| Solara Medical Supplies (phishing / risk analysis) | $3,000,000 |
| Warby Parker (risk analysis) | $1,500,000 |
| Total across all 21 resolved actions | more than $8.3 million |
A HIPAA Security Rule risk analysis is both the most-cited enforcement gap and one of the least expensive controls to put in place. Documenting where protected health information lives, how it is protected and where the weaknesses are does two things at once: it satisfies the regulation OCR checks first, and it produces the exact roadmap needed to prevent the breach in the first place. For most providers it is the highest-return first move in any security program.
Source: HHS Office for Civil Rights HIPAA Enforcement
| Statistic | Figure | Source |
|---|---|---|
| Large healthcare breaches reported (2024) | 725 | HHS OCR |
| Large healthcare breaches reported (2025) | 710 | HHS OCR |
| Individuals affected (2024) | 289.2 million | HHS OCR |
| Individuals affected (2025) | 61.6 million (down 78.7%) | HHS OCR |
| Average large breaches per day | ~2 | HHS OCR |
| Mean breach size (2025) | 86,699 individuals | HHS OCR |
| Median breach size (2025) | 4,011 individuals | HHS OCR |
| Largest healthcare breach ever (Change Healthcare) | 190 million | HHS OCR / UnitedHealth |
| Share of 2024 records from Change Healthcare alone | ~66% | CNiC analysis of HHS OCR data |
| Largest 2025 breach (Aflac) | 13.9 million | HHS OCR |
| Average healthcare breach cost | $7.42 million | IBM |
| Prior-year healthcare breach cost | $9.77 million | IBM |
| Consecutive years healthcare is costliest | 13 | IBM |
| Global average breach cost (all industries) | $4.44 million | IBM |
| Healthcare breach lifecycle (identify + contain) | 279 days | IBM |
| Breaches from hacking / IT incidents (2024) | 81.2% | HHS OCR |
| Breached PHI located on network servers (2025) | 61.5% | HHS OCR |
| Healthcare breaches by external actors | 67% | Verizon DBIR |
| System intrusion as top attack pattern | 53% (up from 36%) | Verizon DBIR |
| Espionage-motivated breaches | 16% (up from 1%) | Verizon DBIR |
| Organizations reporting disrupted patient care | 69% | Ponemon / Proofpoint |
| Organizations reporting increased mortality | 28% | Ponemon / Proofpoint |
| Organizations that suffered ransomware | 59% | Ponemon / Proofpoint |
| HHS OCR HIPAA enforcement actions (2025) | 21 | HHS OCR |
| Total HIPAA penalties collected (2025) | more than $8.3 million | HHS OCR |
| Enforcement actions citing risk-analysis failures | 76% | HHS OCR |
Every figure in this article is drawn directly from a Tier 1 primary source: the U.S. government’s public breach portal, IBM’s and Verizon’s annual reports, and the Ponemon Institute’s independent healthcare study. No statistic is sourced from a blog citing another blog, and no figure has been invented, estimated or rounded beyond the source’s own reporting. Breach counts, records exposed, causes and locations come from the HHS OCR breach portal, which categorizes every reported breach of 500 or more individuals. Where a report’s most recent edition covers the prior calendar year, we cite it as the latest available data. The CNiC Solutions Analysis box combines two independent Tier 1 sources and is clearly labeled as original interpretation.
Primary sources:
You are welcome to cite the statistics in this article with attribution to CNiC Solutions and a link back to this page. The CNiC Solutions Analysis figure is original interpretation combining IBM and HHS OCR data and should be attributed to CNiC Solutions. Please cite the underlying primary sources listed above for their respective figures.
To change where Windows 11 saves your screenshots, open File Explorer, go to Pictures, right-click the…
A cybersecurity incident response plan is the difference between a bad day and a business-ending one.…
Google Workspace and Microsoft 365 are the two dominant productivity suites for business, and there is…
A text lands on your phone: "FedEx: your package is held pending a small unpaid delivery…