A healthcare data breach cost organizations an average of $7.42 million in 2025, according to IBM's Cost of a Data Breach Report. That is down $2.35 million from the 2024 average of $9.77 million, but healthcare has held the title of the costliest industry to breach for 14 straight years, IBM found.
For an independent practice, the number that matters more than the industry average is who actually gets breached. Of the 804 large healthcare data breaches reported to the HHS Office for Civil Rights in 2025, 604 came from healthcare providers rather than health plans, business associates, or clearinghouses, according to HIPAA Journal's tracking of the OCR breach portal, last updated September 8, 2026.
How the cost breaks down
IBM's 2025 report splits the average healthcare breach cost into pieces a practice can weigh against its own exposure. Detection and escalation ran $1.47 million on average, lost business cost $1.38 million, and post-breach response added $1.2 million. Those three categories made up most of the $7.42 million total, ahead of notification and legal costs.
Ransomware carried its own price tag. The average ransom demand reached $5.08 million in 2025, IBM found, and 63.0% of organizations refused to pay, up from 59.0% in 2024. Only 40.0% of ransomware victims brought in law enforcement, down from 52.0% the year before, even as IBM's data shows breaches resolved faster and at lower cost when law enforcement gets involved.
Detection takes longer in healthcare than anywhere else
Healthcare breaches took an average of 279 days to identify and contain in 2025, IBM reported, five weeks longer than the 241-day average across all industries, itself a nine-year low. IBM's 2023 report had put the healthcare figure at 213 days against a 194-day all-industry average that year, and found that only one in three breaches was caught by an organization's own security team rather than by a customer, a law enforcement tip, or the attacker.
The gap between industries widened elsewhere too. The average U.S. breach cost across all sectors hit $10.22 million in 2025, up 9.2% from $9.36 million in 2024, while the global average fell to $4.44 million from $4.88 million over the same period, IBM found.
Who actually gets breached
The HHS Office for Civil Rights sorts every large breach report by the type of organization that filed it. In 2025, healthcare providers filed three out of every four reports.
| Entity type | Large breaches reported, 2025 |
|---|---|
| Healthcare providers | 604 |
| Business associates | 139 |
| Health plans | 59 |
| Healthcare clearinghouses | 2 |
| Total | 804 |
Source: HIPAA Journal, Healthcare Data Breach Statistics, updated September 8, 2026, citing HHS Office for Civil Rights breach portal data.
Healthcare providers accounted for 75.1% of 2025's large breaches, more than health plans, business associates, and clearinghouses combined, HIPAA Journal's data shows. Business associates, the vendors that host a practice's billing, scheduling, or analytics data, filed 139 of the year's 804 reports, a reminder that a practice's own security controls are only part of its exposure.
Breaches affecting fewer than 500 people, the size most likely to trace back to an independent practice rather than a hospital system, rose to 74,299 in 2024, up from 68,315 in 2023 and 63,966 in 2022, a 12.0% increase over four years, per HIPAA Journal. Large-breach reporting slowed in early 2026: HIPAA Journal counted 252 large breaches between January 1 and April 30, 2026, a 9.5% drop from the same period in 2025.
What's actually driving the breaches
Hacking or another IT incident caused more than 80.0% of 2025's large healthcare breaches, HIPAA Journal's annual report found, and unauthorized access or disclosure incidents, which include employees viewing records without a work reason, rose 17.4% year over year. Healthcare accounted for 22.0% of all ransomware attacks across the industries the report tracked.
Where the data lived mattered too, per the same HIPAA Journal report. Network servers were compromised in 61.5% of 2025's breaches, email accounts in 24.9%, paper or film records in 5.6%, and electronic medical records through unauthorized access in 4.6%. A practice storing patient data with a cloud-based billing or analytics vendor is, by these numbers, storing it in the location breached most often.
Enforcement is rising too
The HHS Office for Civil Rights imposed 21 financial penalties for HIPAA violations in 2025, up from 16 in 2024, HIPAA Journal reported. One of the year's settlements, HIPAA Journal reported, was with Solara Medical Supplies, which paid $3 million. Since mandatory breach reporting began in 2009, OCR has logged 7,419 large healthcare data breaches affecting more than 935 million individuals, as of January 31, 2026.
What actually lowers the cost
IBM's 2025 report credited two practices with the largest cost reductions: organizations using DevSecOps saved an average of $227,000 per breach, and those using AI or machine learning tools in security operations saved $223,000. IBM's broader 2023 analysis, which measured AI and automation adoption across a wider set of security functions, found savings of $1.76 million and a breach lifecycle 108 days shorter.
A practice buying an analytics or billing platform is buying into that vendor's detection time along with its dashboard. Asking a vendor for its most recent SOC 2 report, its breach notification timeline, and a stated average time to detect an intrusion puts a number next to a decision that otherwise gets made on price and features alone.
Sources
- HIPAA Journal, "Average Cost of a Healthcare Data Breach Falls to $7.42 Million," 2025
- IBM, "Cost of a data breach: The healthcare industry"
- HIPAA Journal, "Healthcare Data Breach Statistics – Updated for 2026," updated September 8, 2026
- HIPAA Journal, "2025 Healthcare Data Breach Report"
Talk to us
Fifteen minutes about your practice and the systems you run.