
Healthcare Data Breach Statistics (2026): Records Exposed, Costs & Enforcement Trends
In 2024, healthcare set a grim record: about 289 million records exposed in a single year, with one attack, Change Healthcare, accounting for roughly 192.7 million of them. Healthcare has been the most expensive industry for data breaches for 14 straight years. The pattern behind the numbers is consistent, and it points to a single lesson about where sensitive records should live.
- Between 2009 and early 2026, over 7,400 large healthcare breaches were reported to HHS OCR, affecting more than 935 million records (HIPAA Journal analysis of OCR data).
- 2024 set a record with about 289 million records exposed; the Change Healthcare attack alone affected ~192.7 million (HIPAA Journal; HHS OCR).
- Large breaches have plateaued around 700 to 770 per year, roughly two per day, double the 2018 rate (HIPAA Journal).
- Healthcare breach costs range from about USD 7.42M to USD 9.77M per incident, the highest of any industry for 14 years (IBM; Ponemon).
- Hacking and IT incidents caused over 80% of large healthcare breaches by 2025, up from 49% in 2019 (HIPAA Journal / OCR).
- OCR resolved 21 enforcement actions in 2025 (second-highest ever); inadequate risk analysis appears in roughly 90% of Security Rule enforcement actions (HIPAA Journal).
- The record breaches happened where data concentrates, the case for secure, HIPAA-compliant storage of sensitive records like iSedate's SedationVault handles.
What's in This Guide
1 The Scale of Healthcare Breaches
Healthcare is now the most breached vertical in U.S. history, and the cumulative figures are staggering when stated in one place rather than one incident at a time.

The frequency has plateaued while the severity has climbed. Large breaches, those affecting 500 or more individuals, now run at roughly 700 to 770 per year, about two per day and double the 2018 rate. The 2024 record was not a one-off: it reflects a shift from many small incidents to fewer, catastrophic mega-breaches concentrated at the points where data pools most heavily. Even in 2025, when total exposures fell sharply (largely because there was no second Change Healthcare), 16 separate breaches each still topped one million records.
The 2025 "improvement" is misleading. Reported exposures fell about 79% in 2025, which sounds like progress. It mostly reflects the absence of another single mega-breach on Change Healthcare's scale, not a safer year. With 16 million-plus-record breaches still occurring, the underlying threat did not recede. Reading a single year's total without context is exactly the kind of mistake that leads practices to underestimate their risk.
Source: HIPAA Journal healthcare data breach statistics | HIPAA Journal 2025 breach report
See HIPAA-compliant data protection2 The Cost of a Breach
Healthcare has topped every industry for breach costs for 14 consecutive years, and understanding the range matters more than fixating on a single figure.
The cost estimates differ across reports, roughly USD 7.42 million (IBM 2025) to USD 9.77 million (2024 cross-report) to a USD 10.22 million U.S. figure, because they cover different years and different scopes (U.S. versus global). What every report agrees on is the ranking: healthcare is the costliest, every year, by a wide margin. A key driver of the U.S. premium is regulatory: IBM explicitly identifies higher regulatory fines as a primary reason U.S. breach costs surged, meaning OCR penalties and class-action exposure are now a major component of the total, not an afterthought.
iSedate Analysis: Why the 279-day detection gap matters most for small practices
The single most actionable statistic here is 279 days to detect and contain. A breach that goes unnoticed for nine months is not a technology failure alone, it is a monitoring and logging failure, and small practices are the least equipped to run continuous monitoring in-house. This is precisely where concentrating sensitive records in a monitored, HIPAA-compliant cloud platform outperforms a local server: the platform provides the audit logging, access monitoring, and detection capability that a two-operatory practice cannot staff on its own. The detection gap is an argument for where you store data, not just how you lock it.
Calculation and interpretation original to iSedate.
Source: Cobalt on healthcare breach costs | DeepStrike on the U.S. breach-cost surge
See iSedate's SedationVault3 What Causes Breaches
The cause profile of healthcare breaches has shifted dramatically over the past decade, and the direction is unambiguous.

A decade ago, lost laptops, improper disposal, and insider errors drove a large share of breaches. Today it is overwhelmingly deliberate cyberattack. Ransomware was present in a large share of confirmed breaches, phishing is a leading access vector, and financial gain motivates about 90% of healthcare security breaches. The through-line is that healthcare data is deliberately hunted because it is uniquely valuable, and the attack surface that matters most is where large volumes of that data sit accessible.
Source: HIPAA Journal analysis on breach causes | The Relay Co. healthcare compliance statistics
Book a SedationVault demo4 The Vendor & Concentration Problem
The single most important structural insight in the breach data is that the biggest exposures happen where data concentrates, at vendors, clearinghouses, and business associates that hold data for many organizations at once.
The Change Healthcare attack is the defining example: a single clearinghouse that processes roughly 40% of U.S. medical and dental claims was compromised, and roughly 192.7 million people were affected, with claims processing disrupted nationwide for weeks. A vendor breach is a force multiplier. When data pools in one place, one intrusion reaches everyone connected to it. This is why supply-chain and business-associate security is repeatedly named as healthcare's biggest cybersecurity challenge.
iSedate Analysis: Concentration cuts both ways, and vetting is the deciding factor
The vendor-concentration data can be read two ways, and the distinction is what matters for a practice choosing software. Concentrating data in a single vendor is dangerous when that vendor is under-secured, the Change Healthcare lesson. But concentrating a specific record type in a purpose-built, well-secured, HIPAA-compliant platform is safer than scattering it across email inboxes and local drives, the pattern behind most small-practice breaches. The deciding variable is not centralized versus distributed; it is secured versus unsecured. A practice's job is to vet where its most sensitive records live and choose platforms built for that security, rather than leaving records in the least-defended places by default.
Calculation and interpretation original to iSedate.
Source: Sprinto on business-associate breach exposure | Bright Defense on vendor breach trends
See how SedationVault handles your data5 Enforcement Trends
Alongside the breaches runs a tightening enforcement environment. The high-level trend is what matters here; the year-by-year fine detail and violation-type breakdowns are covered in dedicated companion reports on HIPAA violations and HIPAA fines.
Two enforcement themes define the current environment. First, OCR's Risk Analysis Initiative has made a single failure, not conducting a thorough security risk assessment, the most commonly cited violation, appearing in the large majority of Security Rule actions. Second, proposed 2025 changes to the HIPAA Security Rule would remove the distinction between "required" and "addressable" controls, effectively making encryption and multi-factor authentication mandatory rather than optional. The regulatory direction is toward fewer loopholes and stricter baseline controls, and small practices are explicitly in scope, one analysis found 55% of OCR financial penalties in 2022 were imposed on small medical practices.
Small practices are not too small to be fined. A persistent myth is that regulators only pursue large systems. The data says otherwise: in 2022, 55% of OCR financial penalties landed on small medical practices, and the most-cited failure, inadequate risk analysis, is one small offices commonly skip. Size is not a shield; a documented risk analysis and defensible controls are.
Source: HIPAA Journal on 2025 OCR enforcement | DeepStrike on proposed HIPAA Security Rule changes
See sedation compliance documentation6 What It Means for Practices
The healthcare-wide data lands on a practical, local conclusion for any office that holds patient data, including dental and oral surgery practices running sedation.
The record breaches happened where data concentrates and where detection was slow. The costliest failures took the better part of a year to find. Enforcement increasingly punishes the practices that never did a proper risk analysis or left controls optional. Every one of these points to the same defensive priority: get sensitive records into secure, monitored, HIPAA-compliant systems, and out of the exposed places, email, unmonitored local servers, loose files, where small-practice breaches actually begin.
iSedate Analysis: Applying the breach lesson to the sedation record
Sedation and anesthesia documentation is among the most sensitive data a practice holds, and the healthcare breach record argues it deserves the strongest available protection. iSedate's SedationVault stores sedation records in HIPAA-compliant cloud infrastructure with the access monitoring and audit logging that the 279-day detection problem demands, capturing vitals from compatible monitors such as Edan, MindRay, and Criticare, then exporting a clean PDF into whatever chart the practice already keeps, whether Dentrix, Eaglesoft, or Open Dental, rather than leaving records in an inbox. It is not a substitute for a full practice security program, no single tool is, but it ensures the highest-sensitivity record sits in a system built for the exact threats this data describes. Reference figures for the founders' own practice reflect thousands of documented sedation procedures, a practice-level dataset, not a nationwide claim.
Calculation and interpretation original to iSedate.
Treated as a secure, monitored Sedation Intelligence System, the sedation record moves out of the exposed category and into the protected one, which, read against 935 million breached records, is exactly where it belongs.
Source: HIPAA Journal on breach concentration | HIPAA Compliant Hosting on infrastructure as defense
See SedationVault for oral surgeons7 Summary Table: Every Statistic at a Glance
| Statistic | Figure | Source | Year |
|---|---|---|---|
| Cumulative large healthcare breaches (2009-2026) | 7,400+ | HIPAA Journal / OCR | 2026 |
| Cumulative records affected (2009-2026) | 935M+ | HIPAA Journal / OCR | 2026 |
| Records exposed in 2024 (record year) | ~289M | HIPAA Journal / OCR | 2024 |
| Change Healthcare breach (largest ever) | ~192.7M | HHS OCR | 2024 |
| Large breaches per year (plateau) | ~700-770 | HIPAA Journal | 2024-2025 |
| Million-plus-record breaches in 2025 | 16 | HIPAA Journal | 2025 |
| Average healthcare breach cost | $7.42M-$9.77M | IBM; Ponemon | 2024-2025 |
| U.S.-specific breach cost | ~$10.22M | IBM (US) | 2025 |
| Cost per exposed record | ~$398 | IBM / Cobalt | 2025 |
| Days to identify and contain | ~279 | IBM / Ponemon | 2025 |
| Large breaches from hacking/IT incidents | 80%+ | HIPAA Journal / OCR | 2025 |
| Hacking share in 2019 (for comparison) | 49% | HIPAA Journal / OCR | 2019 |
| Ransomware incident growth (2018-2023) | +278% | HIPAA Journal / OCR | 2023 |
| Records in business-associate breaches | 93M+ | HIPAA / HIPAA Journal | analyzed period |
| OCR enforcement actions in 2025 | 21 | HIPAA Journal | 2025 |
| Enforcement actions involving risk-analysis failure | ~90% | HIPAA Journal | 2025 |
| 2022 penalties on small practices | 55% | HIPAA Journal | 2022 |
Frequently Asked Questions
How many healthcare records have been breached?
How much does a healthcare data breach cost?
What causes most healthcare data breaches?
Is healthcare data breach enforcement increasing?
How can small practices reduce breach risk?
Methodology & Sources
Primary and institutional sources: U.S. Department of Health and Human Services Office for Civil Rights (OCR) breach portal, analyzed and compiled by the HIPAA Journal; IBM Cost of a Data Breach Report and Ponemon Institute (breach cost and detection time). Additional industry analysis: Cobalt, Sprinto, Bright Defense, DeepStrike, The Relay Co., and HIPAA Compliant Hosting.
Note on figure variance and scope: healthcare breach-cost estimates differ across reports (roughly USD 7.42 million to USD 10.22 million) because they cover different years and different geographic scopes (U.S. versus global); ranges are shown rather than a single figure. Records-exposed and enforcement figures trace to the OCR breach portal via HIPAA Journal analysis and are broadly consistent across sources. This article covers the broad healthcare data breach landscape; for dental-practice-specific breaches see the companion report on dental cybersecurity, and for granular HIPAA fines, settlements by year, and violation-type breakdowns see the dedicated HIPAA violation and HIPAA fine reports in this series. Statistics reflect the most recent available data as of 2026 and will be refreshed annually. This is a sensitive topic and general information only, not legal or security advice; practices should consult qualified compliance and IT professionals.
Media & press usage: Journalists and researchers are welcome to cite these statistics with attribution to iSedate and a link to this page. The iSedate Analysis boxes contain original interpretation unique to this article.
























