Explore our Topics:

Healthcare breaches are still the most expensive of any industry

The average cost of a healthcare data breach is $6.64 million, according to a new report from IBM.
By admin
Aug 10, 2026, 9:33 AM

The global average cost of a data breach is $4.99 million, up 12% compared to last year, according to IBM’s Cost of a Data Breach Report 2026. Healthcare tops the list of most expensive industries for a data-breach, a long-standing trend. Patients’ personally identifiable information (PII) remains a valuable target for attackers. But new trends are emerging as well. 

Attackers are weaponizing AI, and defending organizations are integrating AI into their security operations. IBM’s report offers insight into breach costs for healthcare and the trends shaping cyberattacks and defense.

Healthcare breaches are the most expensive for the 13th year in a row

The average cost of a healthcare data breach is $6.64 million, the most expensive of any industry. The next most expensive type of breach is financial services, at $6.29 million. Healthcare has topped the list as the most expensive industry for breaches for 13 years running, according to the report. 

Yet, there is an indication of progress. The average cost of a healthcare breach was $7.42 million in 2025, 10.5% more than it is this year. 

Malicious attacks are the top cause of healthcare breaches

Malicious attacks are still the main data breach culprit, accounting for 55% of all breaches. In healthcare, 59% of data breaches stem from malicious or criminal attacks. Human error accounts for 21% of breaches, and IT failure accounts for 20% of breaches.

Ransomware attacks continue to rise 

Ransomware accounts for 39% of attacks among breached organizations, but the number of attacks has been on the rise over the past four years. In 2023, ransomware accounted for 24% of attacks.

As ransomware grows, the tactics attackers use are shifting, too. Data encryption followed by a ransom demand remains a hallmark of these attacks, but increasingly, attackers are threatening their victims with brand damage. Nearly half of attacks this year (41%) involved ransomware groups threatening to leak data to the media and publicly shame.

Leveraging employees’ personal data, including Social Security numbers and health records, was the second most common way threat groups weaponized ransomware. This tactic popped up in 35% of attacks.

While ransomware is an ongoing problem in healthcare, it is not the only attack vector to watch for; IBM reports that phishing is the most common avenue of compromise for breached organizations. That attack vector is associated with the highest average breach cost ($5.29 million).

AI-driven attacks are driving up breach costs

AI is a powerful tool for threat actors looking to execute phishing scams and other cyberattacks. It can make it easier to find vulnerabilities and execute attacks at scale. These attacks are not yet the norm; 64% of attacks were not driven by AI compared to 25% that were. But AI-driven attacks increased 56% compared to last year. 

The report notes that IBM researchers have found a growing use of AI-generated malware; it was used in 19% of AI-fueled attacks. 

AI-driven attacks have, thus far, focused on critical infrastructure. Financial services and energy are the top-targeted sectors.

Not only are AI-driven attacks increasing, but they are also pushing up the price for the organizations breached. IBM reports that AI-fueled attacks add an average of $1 million to the total breach cost.

AI in the hands of defenders can save money

The faster organizations are able to identify and respond to breaches, the smaller the impact. Adding AI and automation to security operations is helping organizations on that front. IBM found that organizations that make extensive use of this technology lower breach times by 65 days and capture an average of $1.93 million in cost savings. 

But not every organization is on the forefront of AI adoption. Just 36% of breached organizations told IBM that they have extensive use of AI tools in security operations.

However breach trends evolve in healthcare, and in general, they will undoubtedly be shaped by the ongoing use of AI both in the hands of cyberattackers and the organizations that they target.


Carrie Pallardy, a Chicago-based freelance writer and editor, began her career covering healthcare more than a decade ago. Her work has taken into many different industries, but covering healthcare delivery remains a constant focus. She can be reached at [email protected] or on LinkedIn.


Show Your Support

Subscribe

Newsletter Logo

Subscribe to our topic-centric newsletters to get the latest insights delivered to your inbox weekly.

Enter your information below

By submitting this form, you are agreeing to DHI’s Privacy Policy and Terms of Use.