< Back to all clusters
[HEALTH] · United States · 2 sources

started · updated

Healthcare data breaches reach record costs amid proposed HIPAA security updates

Healthcare data breaches reached a record average cost of $7.42 million in 2025, marking the 12th consecutive year that the healthcare sector has led all industries in breach-related costs, according to IBM.

Concurrently, the U.S. Department of Health and Human Services (HHS) has proposed significant updates to the HIPAA Security Rule to address evolving cybersecurity risks. Data from HHS shows that between 2018 and 2023, large-scale healthcare breaches increased by 102%, while the number of individuals affected rose by 1,002%, driven largely by hacking and ransomware.

The proposed rule changes aim to strengthen protections for electronic protected health information (ePHI) by mandating more explicit administrative and technological safeguards. These include enhanced requirements for risk analysis, incident response, encryption, multi-factor authentication, and vulnerability identification. While the proposal is not yet final, organizations are encouraged to bolster their security measures and employee training to mitigate existing threats like phishing and compromised credentials.

Entities

HIPAA · IBM · U.S. Department of Health and Human Services