Skip Navigation

The 2026 Privacy Trends Report

0

In 2025, approximately 710 large healthcare data breaches were reported to HHS OCR, affecting at least 61.6 million individuals.

0

In 2025, US healthcare breaches took an average of 279 days to identify and contain, which is five weeks longer than the global average.

0

AI governance committees are forming, and some compliance leaders have opted out of AI adoption entirely, citing data privacy concerns, accuracy limitations, and organizational policy.

Healthcare breach costs remain the highest of any industry for the 12th consecutive year.

At $7.42M per incident, healthcare runs 67% above the global average — and the three largest cost drivers hit every organization regardless of size.

  • $7.42M average cost per healthcare breach in 2025
  • 67% above the global all-industry average of $4.44M
  • $1.47M in detection and escalation costs alone

The breach threat is closer than most organizations think.

The threat isn’t always malicious. Family member access, self-access, and coworker snooping collectively represent the majority of reviewed cases — violations that often go undetected for months because manual auditing can’t keep pace. The average hospital generates 60 million auditable events every month and reviews roughly 1,000 of them.

  • 55% of healthcare organizations experienced a patient data breach in the last 12 months.
  • 25% traced their most significant breach directly to an insider, whether intentional or accidental.
  • $28.8M average annualized cost of insider security incidents per healthcare organization in 2025.
Privacy Trends Report 2026
Medical team interacting using digital tablet at modern hospital. Mature doctor and african surgeon working on digital tablet with nurse. Head physician working with his medical team at clinic.

The true scale of healthcare breaches is larger than federal data suggests.

HHS OCR’s 500-record threshold for public disclosure means the official breach numbers consistently undercount the real impact. What gets reported is only part of the story — and in 2025, the gap between reported and actual exposure was stark.

  • 710 large healthcare data breaches were reported to HHS OCR in 2025.
  • At least 61.6 million individuals were affected.
  • Attackers are increasingly targeting business associates and large insurers, high-value targets where a single breach reaches millions.

See Past Privacy Reports Here

Browse previous reports to see historical trends and shifts.

Breach Barometer 2025

2025 Breach Barometer Report