AI-enabled data breaches cost organizations $6.04 million on average in 2026, about $1 million more than a breach without AI involved, according to IBM's Cost of a Data Breach Report. Healthcare stayed the single costliest industry to breach at $6.64 million per incident, the 13th year running that it has held that spot, even though the figure fell 10.5% from $7.42 million in IBM's 2025 report. For a practice buying an AI scribe or a scheduling bot this year, both numbers apply at once: a high starting cost for the industry, and a new premium tied to how the breach happened.
Why an AI-linked breach costs more
IBM's 2026 study, run by the Ponemon Institute, interviewed staff at more than 600 organizations breached between March 2025 and February 2026. Within that group, about one in four malicious breaches were AI-enabled, a 56.0% jump over the year before. More than 20.0% of the organizations in the study reported a breach that targeted an AI model or application directly, rather than a database or a network server.
The $6.04 million average for an AI-enabled breach sits on top of the cost a practice already pays when any breach happens. IBM's report does not break this AI premium out by industry, so healthcare's $6.64 million baseline and the AI premium describe two different slices of the same data set. Both figures rise whenever AI is part of the breach, whether AI is the attacker's tool or the target.
Shadow AI is the bigger risk
Shadow AI, an employee's use of an AI tool the organization never approved, showed up in 43.0% of security incidents in IBM's 2026 report, more than double the 20.0% share a year earlier. Breaches tied to shadow AI cost $5.39 million on average, and about one in five of them led to a regulatory fine, according to HIPAA Journal's reporting on the same data.
The pattern matters for a practice because staff adoption of AI is already ahead of practice policy. The American Medical Association's 2026 survey of 1,692 physicians found 81.0% now use AI professionally, up from 38.0% in 2023, and 27.0% received no formal AI training from any source. A physician who uses a consumer chatbot to draft a note or summarize a chart, without the practice's knowledge, matches what IBM's shadow AI category measures.
Healthcare's baseline, before AI even enters
Healthcare's $6.64 million average breach cost breaks down by cause: 59.0% of the industry's breaches were malicious or criminal attacks, 26.0% came from IT failures, and 13.0% traced to human error, IBM found. That cost has now fallen for a second straight year, from $9.77 million in IBM's 2024 report to $7.42 million in 2025 and $6.64 million in 2026.
The decline has not moved healthcare out of first place. IBM has ranked healthcare the costliest industry to breach for 13 consecutive years, ahead of financial services and every other sector the report tracks.
How the cost compares across industries
IBM's 2026 report puts a number on the gap between healthcare and other sectors, and between the United States and the rest of the world.
| Measure | Average cost, 2026 | Source |
|---|---|---|
| Healthcare | $6.64 million | IBM |
| Financial services | $6.3 million | IBM |
| Energy | $5.2 million | IBM |
| Global average, all industries | $4.99 million | IBM |
| United States, all industries | $11.5 million | IBM |
| AI-enabled breach, all industries | $6.04 million | IBM |
| Shadow AI-linked breach, all industries | $5.39 million | IBM / HIPAA Journal |
Source: IBM, Cost of a Data Breach Report 2026, and HIPAA Journal's reporting on the same study.
Healthcare's $6.64 million sits well below the $11.5 million U.S. average across all industries, because the U.S. figure blends healthcare with sectors that report even higher breach costs. Against the $4.99 million global average, healthcare's cost runs about 33% higher.
What actually lowers the cost
IBM's report also measured what happens when an organization puts AI and automation to work on defense. Organizations running AI and automation across prevention, detection, investigation, and response paid close to $2 million less per breach and closed breaches about two months faster than organizations that did not, IBM found. Half of the breached organizations in the study had already deployed AI agents inside their security operations centers.
Detection speed still slipped industry-wide despite those gains. The mean time to identify and contain a breach rose to 247 days in 2026, reversing five years of improvement, and breaches that ran past 200 days cost about a third more than those caught sooner, IBM reported.
What this means for AI purchases at your practice
None of IBM's figures name a medical practice specifically. But the AMA's 81.0% adoption figure and its 27.0% training gap describe the workforce a practice is already running, and IBM's shadow AI category describes what happens when that workforce picks its own tools. A written AI-use policy, naming which tools are approved and who signs off before a new one gets added, closes the gap between those two numbers.
The same logic applies to a paid AI product a practice is evaluating, not just a free chatbot a physician found alone. A vendor should be able to say how it logs AI-related activity and how it separates approved use from shadow use. A vendor that cannot answer either question is asking a practice to accept the $6.64 million healthcare average and the 247-day detection window without knowing where its own product falls on either scale.
Sources
- IBM Newsroom, "IBM Study: One in Four Malicious Breaches are AI-Enabled, Costing Companies $6 Million on Average," July 29, 2026
- HIPAA Journal, "Global Data Breach Cost Rises 12% to Almost $5 Million," 2026
- Help Net Security, "Data breach cost 2026 averaged $4.99 million, AI attacks ran higher," July 30, 2026
- eSecurity Planet, "IBM 2026 Cost of a Data Breach Report: Key Findings," 2026
- American Medical Association, "AI usage among doctors doubles as confidence in technology grows," March 12, 2026
Talk to us
Fifteen minutes about your practice and the systems you run.