Sector profile
Healthcare data breaches cost $6.64M on average. The highest of any sector, again.
IBM's 2026 healthcare figure is $6.64M, down 10.5% from the 2025 figure of $7.42M but still 33% above the global $4.99M average and the highest of any sector. Healthcare has held rank #1 for 13 consecutive years, the longest unbroken streak in the dataset. In IBM's 2025 report, healthcare breaches took the longest of any sector to identify and contain, at 279 days; IBM's 2026 global mean rose to 247 days.
Avg total cost
$6.64M
IBM CODB 2026, healthcare
Breach lifecycle
279 days
Longest sector, IBM 2025
YoY change
-11%
Down from 2025 $7.42M
Years at #1
13
Consecutive, per IBM 2026
Section HC.1
Why healthcare costs nearly twice what retail costs
The structural answer is that healthcare records carry a much richer payload than the data classes other sectors hold. A complete patient record contains name, address, date of birth, social security number, insurance ID, payer information, prescription history, diagnosis codes, provider notes, and frequently next-of-kin information. On underground markets that combination has historically priced at $250 to over $1,000 per record, against roughly $5 for a stolen credit card. The economic asymmetry is the foundation of every other cost driver.
The regulatory regime amplifies the underlying data sensitivity. The HIPAA Security Rule and Breach Notification Rule require covered entities to notify each affected individual, notify the Department of Health and Human Services Office for Civil Rights, and (for breaches affecting 500 or more individuals) notify prominent local media. The notification obligation alone produces a per-record letter cost of around $1 to $3 plus call-centre support of $20 to $80 per call handled. For a breach affecting 100,000 patients, baseline notification cost runs $200K to $400K before any regulator engagement.
Patient-care disruption is the most expensive line item that does not appear on a balance sheet until weeks later. When ransomware encrypts an electronic health record system, every patient appointment scheduled in that EHR has to be triaged manually, every prescription verified by paper chart, every insurance authorization rebuilt by phone. The ripple cost shows up across multiple cost categories: lost business (procedures rescheduled to competitors), post-breach response (overtime clinical staff), and detection-escalation (forensic and compliance investigation that has to run in parallel with the recovery operation). The Change Healthcare incident in 2024 illustrated this with brutal clarity, as the inability to process pharmacy claims left independent pharmacies and small medical practices unable to operate for weeks.
Section HC.2
Per-record economics: what a PHI record costs to lose
IBM publishes per-record cost by data type, not by industry: in its 2026 report, $196 for intellectual property (the costliest type) and $192 for customer PII, the most commonly compromised type (present in 52% of breaches). There is no IBM-published healthcare per-record figure. Scaling the $192 customer-PII baseline by healthcare's cost ratio against the global average (6.64 / 4.99) produces a modeled estimate of roughly $256 per PHI record, an estimate, not IBM data. Whatever unit figure is used, it aggregates detection, notification, post-breach response, and lost business; it is not a market price for stolen data, and it is not the cost paid by the affected patient.
The premium over other sectors reflects the long-tail liability of PHI exposure rather than transient market conditions. Stolen credit-card numbers can be replaced within days of detection. A stolen genome or HIV diagnosis cannot be retracted, and HIPAA's notification and credit-monitoring obligations bind regardless of whether the data is ever monetised.
For practical estimation, any per-record figure is most reliable when applied to mid-volume breaches of roughly 10,000 to 100,000 records, the range IBM actually studies. Below 10,000 records the fixed cost of forensics and legal counsel dominates, pushing effective per-record cost into the thousands. Above roughly 100,000 records, fixed-cost amortisation takes over; mega-breaches at the 100 million record scale typically show per-record cost in the $5 to $25 range, even though the totals are immense. Use the homepage calculator to model your specific record count instead of applying a unit figure as a flat multiplier.
Section HC.3
OCR HIPAA enforcement: the regulator side of the bill
The HHS Office for Civil Rights is the principal federal enforcer of HIPAA. OCR maintains a public breach portal, frequently called the "Wall of Shame", listing every healthcare breach of 500 or more individuals. The OCR Breach Portal is the single most useful public dataset for benchmarking healthcare breach scale against your peer cohort. Resolution agreements that include monetary penalties are published as enforcement highlights on the OCR website.
HIPAA penalties operate on a four-tier civil monetary penalty structure introduced under the HITECH Act and adjusted annually for inflation. The tier structure effective 28 January 2026 is: Tier 1 (lack of knowledge, $145 minimum to $73,011 per violation), Tier 2 (reasonable cause, $1,461 to $73,011), Tier 3 (willful neglect, corrected, $14,602 to $73,011), and Tier 4 (willful neglect, not corrected, $73,011 to $2,190,294 per violation). Under OCR's 2019 enforcement discretion (still in effect), the per-calendar-year cap differs by tier ($36,506, $146,053, $365,052 and $2,190,294) rather than applying a single $2.19M cap to all four. Multiple distinct violations from a single incident can stack, which is how OCR settlements regularly reach mid-eight-figure totals.
Beyond OCR civil penalties, healthcare entities face state attorney-general actions that frequently exceed the federal penalty by an order of magnitude. The Anthem 2015 breach attracted a $39.5M multistate AG settlement on top of OCR's $16M HIPAA penalty (then a record) and $115M class-action settlement, for a total cost north of $260M. State AGs have grown more aggressive each year, with California, New York, and Texas leading volume.
Section HC.4
Notable healthcare breaches and what they cost
Change Healthcare (UnitedHealth), 2024
190M records / ALPHV/BlackCat ransomware / Citrix portal credential
$2.45B+
Change Healthcare processes 15 billion healthcare transactions a year for UnitedHealth. In February 2024 the BlackCat ransomware affiliate gained access through a Citrix portal that lacked MFA, then exfiltrated 190 million patient records and encrypted core claims-processing systems. UnitedHealth paid a $22 million ransom that did not prevent later extortion by an affiliate. The cost figure of $2.45 billion comes directly from UnitedHealth Q2 2024 disclosure and was reaffirmed in subsequent 10-Q filings. The remediation, third-party assistance, customer support, and direct response costs continue accruing into 2026.
Primary source: UnitedHealth Group Q2 2024 earnings release and 10-Q filings, 2024-2025.
Anthem (Elevance Health), 2015
78.8M records / Spear-phishing / No encryption at rest
$260M+
Anthem disclosed the largest healthcare breach of its era in February 2015 after a state-sponsored intrusion (later attributed by the FBI to China) accessed names, SSNs, dates of birth, employment, and income data for 78.8 million members and former members. Anthem agreed to a $16M OCR HIPAA settlement in 2018, a $115M class-action settlement in 2017, and a $39.5M multistate AG settlement in 2020. Total disclosed cost reached approximately $260M, with internal remediation costs adding tens of millions more.
Primary source: OCR press release 15 October 2018; class-action settlement order, In re Anthem Inc. Data Breach Litigation; California AG announcement 30 September 2020.
Premera Blue Cross, 2014
11M records / Custom malware / 9-month dwell time
$74M
Premera disclosed in March 2015 that custom malware deployed on its network in May 2014 had accessed PHI for 11 million members. Detection took 9 months. Premera resolved OCR's investigation with a $6.85M HIPAA settlement and paid $74M in class-action and multistate AG settlements over the subsequent five years.
Primary source: OCR HIPAA enforcement settlement 25 September 2020; multistate AG announcement 11 July 2019.
23andMe, 2023
6.9M records / Credential stuffing / DNA Relatives exposure
$400M+
23andMe combines healthcare cost dynamics with the unrecoverability of genetic data. The October 2023 breach used credential stuffing against accounts that lacked MFA, then chained the DNA Relatives feature to enumerate linked profiles, ultimately exposing 6.9M users. A $30M class-action settlement was approved in 2024, but the brand damage was unrecoverable. 23andMe filed for Chapter 11 bankruptcy in 2025, attributing operating losses in part to the breach. The total economic impact, including market-cap erasure from peak valuation, exceeded $400M.
Primary source: 23andMe SEC 8-K filings, Q4 2023; class-action settlement order Northern District of California, 2024; Chapter 11 filing 2025.
Section HC.5
What healthcare-specific controls actually move the cost
Across IBM's 2025 dataset, the capability with the largest verified cost difference is security AI and automation deployed extensively: $3.62M average breach cost versus $5.52M without, a $1.9M gap. The top factors in IBM's 2025 cost-factor analysis follow: DevSecOps approach (-$227K), AI/ML-driven security insights (-$224K), SIEM (-$212K), threat intelligence (-$212K), encryption (-$208K), and employee security training covering phishing recognition and data-handling discipline (-$192K). IAM, including MFA enforcement on every account, especially clinical-staff and contractor accounts (-$190K), remains the highest-return control on a dollar-per-dollar basis because the implementation cost is so low and compromised credentials remain a top-four initial vector.
Healthcare-specific overlays that compound the generic controls: network segmentation between clinical and corporate networks limits ransomware blast radius; encryption at rest with documented key-management practice insulates against safe-harbor exposure under most state breach notification laws; tabletop exercises that include the clinical leadership team (not only IT and security) materially reduce the response time for the patient-care components of the incident.
On the prevention pricing side, see PenetrationTestingCost.com for healthcare pen-test pricing benchmarks, PCIComplianceCost.com for the card-data side of healthcare billing operations, and EDRCost.com for endpoint detection pricing in clinical environments.
Cross-references
Case / Change Healthcare 2024
→$2.45B cost analysis with attack-vector breakdown and timeline.
Case / Anthem 2015
→$260M total: $115M class action, $39.5M state AG, $16M OCR.
Regulation / HIPAA penalties
→Four-tier penalty structure, OCR enforcement, $2.19M Tier 4 cap (2026).
Cost / Per record
→$178 IP to $115 anonymized by data type, plus modeled sector estimates.
Cost / Credit monitoring
→$10-$30 per affected person per year, settlement-driven enrollment.
Index / All industries
→All 17 IBM sectors ranked from healthcare to public sector.
Schedule F / Reference Q&A
Frequently Asked Questions
Primary source:Healthcare sector cost figures from IBM Cost of a Data Breach Report 2026. HIPAA enforcement data from HHS OCR. Notable breach totals from publicly disclosed SEC filings, OCR resolution agreements, and class-action settlement orders.