The healthcare industry is facing unprecedented challenges from existing and emerging cyber risks. Historically, threat actors have targeted the industry due to their vast collection of valuable medical data. However, the risks for the industry have grown more acute in recent years, as hybrid work has become permanent and telehealth has become a routine channel for delivering patient care. The risks have also grown due to the increased interconnectivity of the healthcare ecosystem and the rising reliance on outside vendors and suppliers, as well as a consolidation of those outside vendors and suppliers. All these changes have expanded the attack surface for threat actors to exploit.
According to data reported by the US Department of Health and Human Services (HHS), 2025 saw 772 reported breaches of 500 or more records in the healthcare sector — the highest annual total ever recorded, surpassing the previous record of 746 breaches set in 2023 — exposing the protected health information of approximately 139.7 million individuals. (Alder, Largest Healthcare Data Breaches of 2025 2026) The Change Healthcare ransomware attack remains the largest reported cyberattack in healthcare, and threat actors' focus on exploiting supply chains has only sharpened since. 2026 has brought no relief: healthcare organizations worldwide sustained 410 ransomware attacks in the first half of 2026, up nearly 14% from the 360 recorded in the second half of 2025, with 225 of those attacks in the US. (Comparitech 2026) Measured by affected individuals rather than incident count, 2024 remains the worst year on record at approximately 289.8 million, with 2025 third worst behind 2023.
Ransomware, hacking, vulnerability exploits, supply chain attacks, and phishing attacks against organizations and their third-party vendors continued to rank among the top causes of data breaches in the industry. Not only are the costs of a data breach substantially higher for the healthcare industry compared with other industries, but the industry is also facing significant enforcement activity and class action lawsuits. The healthcare industry's ability to manage these exposures through cyber insurance is also becoming more costly and difficult, driven by greater scrutiny being placed on organizations' cybersecurity controls during the underwriting process.
The Ransomware Threat
One of the main drivers for the increase in data breaches in the healthcare sector over the past year is the continuously growing threat of ransomware. The threat has not receded, but it has changed shape. Sophos' State of Ransomware in Healthcare 2025, based on the frontline experiences of 292 healthcare IT and cybersecurity leaders across 17 countries, found that attackers are shifting away from encryption toward pure data extortion. The share of healthcare victims whose data was stolen and extorted but not encrypted tripled to 12% of attacks in 2025, up from 4% in 2022-2023 — the highest rate of any sector — while the data encryption rate fell to a five-year low of 34%, down from 74% reported in 2024. (Sophos 2025) For the first time in three years, exploited vulnerabilities displaced compromised credentials as the leading technical root cause, accounting for 33% of incidents, and 42% of providers cited a lack of personnel or capacity as the primary reason they fell victim. Sophos identified 88 distinct threat groups targeting healthcare organizations over the year.
Recovery performance has improved sharply, reversing several years of deterioration, even as the sector's overall exposure remains severe. In 2024, only 22% of healthcare organizations surveyed recovered within a week and 37% needed more than a month. In 2025, 58% recovered within a week — more than double the prior year's rate — and the proportion of attacks stopped before encryption reached a five-year high. Ransom economics moved in the same direction: median ransom demands fell 91% to roughly $343,000 from $4 million in 2024, average payments dropped from $1.47 million to $150,000 — the lowest of any sector surveyed — and mean recovery costs excluding ransom fell 60% to $1.02 million. Only 36% of providers paid a ransom, down from 61% in 2022, placing healthcare among the sectors least likely to pay. (Sophos 2025)
As noted above, a key driver for this increase was the expansion of the attack surface, whether through remote working or increased use of vendors and suppliers. Threat actors exploited new vulnerabilities this transition created to launch email phishing attacks, which are a top vector for ransomware attacks. (Coveware n.d.) Ransomware attacks are enormously disruptive to organizations from an operational, legal, financial, and patient care perspective.
The following recent ransomware attacks are among the most severe.
The Change Healthcare Ransomware Attack
The largest attack in the history of US healthcare remains the February 2024 Change Healthcare mega-attack. Change Healthcare, a unit of Optum and a subsidiary of UnitedHealth Group, provides a wide range of critical IT applications to healthcare sector organizations, from claims processing and pharmacy benefits to eligibility checks and prior authorization. The company says its technology is used to process 15 billion healthcare transactions annually, and its clinical connectivity solutions touch one out of three patient records in the US. (McGee 2024) Millions of Americans use Change Healthcare's platform, either directly or indirectly, as it serves as a backend service provider for various healthcare insurance providers in the US. On February 21, 2024, Change Healthcare publicly disclosed it was hit with a ransomware attack by the BlackCat/ALPHV ransomware gang, which gained entry through a remote-access Citrix portal that was not protected by multifactor authentication.
The impact has been devastating for the healthcare industry and the hundreds of millions of Americans who rely on services powered by victimized providers. Physicians and hospitals have been impacted in their ability to bill, manage, and issue prescriptions and healthcare procedures. Pharmacies were unable to properly fill prescriptions, and many providers and individuals experienced financial hardship. On July 31, 2025, after an 18-month review, UnitedHealth Group notified OCR that the breach ultimately affected approximately 192.7 million individuals — nearly two-thirds of the US population — confirming it as the largest healthcare data breach ever recorded. UnitedHealth reported roughly $3.1 billion in cyberattack-related impacts for the full year of 2024, making it the most expensive healthcare cyber incident on record. The company paid a ransom of approximately $22 million to ALPHV, which took the funds without deleting the stolen data; an affiliate then attempted a second extortion round through RansomHub, which UnitedHealth refused to pay. Stolen data includes medical records, Social Security numbers, and information on active military personnel. The American Hospital Association has called it "the most significant cyberattack on the US healthcare system in American history." (Pollack 2024)
The Yale New Haven Health Data Breach
The largest healthcare data breach reported in 2025 struck Yale New Haven Health System, the largest health system in Connecticut. Hackers breached its network on March 8, 2025, and exfiltrated the sensitive data of 5,556,702 individuals, including names, dates of birth, contact and demographic information, medical record numbers, and Social Security numbers. The electronic medical record system itself was not accessed, and patient care was not interrupted, which illustrates an important point: a breach need not disrupt clinical operations to generate catastrophic notification and litigation exposure. Yale New Haven faced multiple class action lawsuits, and just seven months after the incident it agreed to an $18 million settlement resolving a consolidated action that amalgamated 18 separate complaints. (Alder, Largest Healthcare Data Breaches of 2025 2026)
The DaVita Ransomware Attack
The April 2025 attack on DaVita, which provides kidney dialysis services at more than 2,600 outpatient centers in the US and 367 centers in 11 other countries, demonstrates the operational profile of a modern healthcare ransomware event. The Interlock ransomware group encrypted elements of DaVita's network; the incident began on March 24, 2025 and was not contained until April 12, when responders finally blocked the threat actors from DaVita's servers. Data from the company's dialysis labs database was compromised, affecting 2,689,826 individuals, including names, addresses, Social Security numbers, health insurance information, dates of birth, health conditions, and dialysis lab test results. DaVita reported approximately $13.5 million in costs associated with the attack
The Ardent Ransomware Attack
Before Change Healthcare, one of the most significant attacks was the 2023 attack on Ardent Health Services, which oversees 30 hospitals across the US. One report noted that Ardent's hospitals in three states had to divert patients from their emergency rooms as a result of the ransomware attack. Ardent had to shut down a significant number of its computerized services, "including clinical programs and its use of Epic Systems, a program that tracks patients' healthcare records." (Collier 2023)
Patient care can also be impacted at nearby facilities that accept the diverted patients. A research paper published in May 2023 concluded that nearby hospitals that need to deal with the additional patients may experience "resource constraints affecting time-sensitive care for conditions such as acute stroke. These findings suggest that targeted hospital cyberattacks may be associated with disruptions of healthcare delivery at non-targeted hospitals within a community and should be considered a regional disaster." (Dameff, et al. 2023) More recent work has quantified the mortality effect directly: Medicare-claims research published in the American Economic Journal: Economic Policy in February 2026 found that in-hospital mortality among patients already admitted when a ransomware attack begins increases by 34% to 38%.
The Episource Ransomware Attack
In February 2025, Episource — a UnitedHealth-owned provider of risk adjustment and medical coding services to health plans and providers — detected that a ransomware group had accessed its cloud environment between January 27 and February 6, 2025, and copied data before encrypting files. The breach was initially reported as affecting 5,418,866 individuals and was later revised upward to 6,725,572, spanning multiple downstream provider and health plan clients, including Sharp HealthCare and Sharp Community Medical Group. As is common, a breach of this magnitude will almost certainly result in a slew of class action lawsuits, some of which have already been filed. Episource was the second-largest healthcare breach reported in 2025 and, like Change Healthcare, demonstrates how a single vendor compromise propagates across the ecosystem — the affected covered entities, not just the vendor, bear the notification and litigation burden. (Alder, Largest Healthcare Data Breaches of 2025 2026)
The MOVEit Transfer Ransomware Attack
Threat actors are continuing to evolve their ransomware attacks to maximize payouts. Most notable in 2023 was the Clop ransomware group's exploitation of Progress Software's MOVEit Transfer product. In the attack, the threat actors exploited a bug in the product, which thousands of organizations, including healthcare organizations, use to transfer sensitive files. More than 2,300 organizations are known to have been affected, with more than 60 million records stolen. (Alder, October 2023 Healthcare Data Breach Report 2023) The MOVEit attack demonstrates the devastating downstream effects when threat actors target a commonly used product.
As more organizations become savvier about backing up data for business resilience, threat actors are now using what is known as the double extortion method; instead of simply encrypting files and hoping the victim cannot recover their data, they're also stealing data before encrypting it. Thus, a ransom must be paid for the decryption tool and the deletion of the stolen data. If backups are viable, then the cybercriminal can at least demand ransom for the deletion of the stolen (and presumably sensitive) data. Threat actors know healthcare data is particularly valuable.
What Happens Immediately After a Ransomware Incident?
One of the first questions that must be addressed following a ransomware incident is whether the organization should pay the ransom. This question requires thoughtful consideration of a number of factors. For example:
- Whether it has viable backups from which it can restore its data if it doesn't pay the ransom. Even if it does have viable backups, it could still take weeks, or months, to fully restore an organization's data. Under such circumstances, paying a ransom might be the most expedient solution.
- Whether the criminal organization behind the incident has a history of living up to its promises.
- Whether the threat actors may have exfiltrated data off the victim's network and are threatening to publish it if payment isn't made, which is increasingly the case.
Most recently, threat actors have been using the double extortion method of demanding ransom for both the decryption and deletion of exfiltrated data. If an organization does decide to make a ransom payment, before the payment is made, it must confirm that the threat actor isn't a sanctioned group under the US Department of the Treasury's Office of Foreign Assets Control. Otherwise, it may face sanctions.
Cybersecurity vendors who specialize in negotiating and responding to ransomware incidents can provide critical assistance to organizations in dealing with a ransomware incident. One of the many benefits of cyber insurance is having immediate access to the cyber insurance carrier's panel of experienced and vetted cybersecurity vendors, including breach counsel, forensics, and ransom negotiators. These vendors can help organizations assess and effectively respond to ransomware incidents. The breach counsel is instrumental in protecting the attorney-client privilege of the investigation and advising on regulatory notification and consumer notification requirements and the timing of such requirements. Counsel will also work with victims on notifying law enforcement, such as the Federal Bureau of Investigation's (FBI's) Internet Crime Complaint Center (IC3), since reporting such incidents provides law enforcement with a greater understanding of the threat.
Other Cyber Risks Affecting Healthcare Organizations
Aside from ransomware incidents, healthcare organizations need to manage and guard against numerous other types of cyber threats. While this article won't detail all of the cyber threats impacting the healthcare sector, we focus on several of the most significant risks below.
Third-Party Vendors and Supply Chain Attacks
According to The HIPAA Journal, cyberattacks on vendors and business associates of healthcare organizations have "increased to the point where attacks on business associates now outnumber attacks on healthcare providers." (Alder, Healthcare Organizations Most Common Victims in 3rd Party Data Breaches 2023) In 2023, Black Kite, a vendor risk management company, analyzed 63 third-party breaches that affected at least 298 companies and reported a doubling of the impact and destruction those breaches caused. In 2021, an average of 2.46 companies were affected by each third-party breach, with the number of affected companies increasing to an average of 4.73 per breach in 2022. (Alder, Healthcare Organizations Most Common Victims in 3rd Party Data Breaches 2023)
Supply chain compromise was the second most common initial access vector across all industries in IBM's 2025 study, at 15% of breaches. The pattern held through 2025 and into 2026: the Episource ransomware attack discussed above exposed the data of more than 6.7 million individuals across multiple provider and health plan clients, and in March 2026 NYC Health + Hospitals disclosed that a breach at an unnamed third-party vendor with network access exposed the records of at least 1.8 million patients and employees — including government IDs, geolocation data, and fingerprint and palm-print biometrics. In addition to the Change Healthcare ransomware attack, the MOVEit incident in 2023 also highlighted the risks to the healthcare industry in relation to third-party vendors. MOVEit, a popular managed file transfer tool owned by Progress Software, contained a vulnerability that the Clop ransomware gang exploited for monetary gain, impacting thousands of companies and approximately 78 million people globally. (Kaur 2023) Clop threatened to identify these victim companies and publish stolen data if a ransom wasn't paid. Several healthcare organizations were affected, and sensitive data was exposed, including patient medical histories and personal information. Progress Software is now facing regulatory investigations, as well as more than 20 lawsuits for breach of contract, negligence, and invasion of privacy. Several healthcare organizations were also named in class action lawsuits arising out of the MOVEit incident.
Hacking Incidents
Hacking and other IT incidents remain the dominant category of large healthcare data breaches. In 2025, hacking and other IT incidents were responsible for 76% of all large healthcare breaches, and network servers remained the most common location of compromised PHI, followed by email accounts. Hacking also accounts for nearly all the records exposed: in July 2025, for example, hacking/IT incidents accounted for 99.7% of breached healthcare records (4,384,794 individuals), compared with just 13,638 individuals affected by unauthorized access and disclosure incidents that month. (Alder, July 2025 Healthcare Data Breach Report 2025)
Hacking incidents can often be traced to leaked credentials. One reason why data breaches are more costly in healthcare than in other industries is that the average time to identify and contain a data breach in healthcare is longer — 279 days, roughly five weeks longer than the 241-day global average across all industries, and the longest lifecycle of any sector. (IBM 2025) In general, the length of a hacking incident correlates with the cost of resolving the incident.
Phishing
Hackers are also continuing to rely on email phishing as a key strategy to target victims in healthcare organizations. Phishing emails are frequently used to spoof a trusted sender and trick unsuspecting victims into entering their credentials on a fake login page. In addition, phishing campaigns frequently deliver malware, including ransomware. Other malware variants can allow hackers to steal data, capture keystrokes, take screenshots, and launch malicious code.
Phishing was the leading initial access vector across all industries in IBM's 2025 study, accounting for nearly 16% of breaches and displacing stolen credentials, which fell to third place. IBM's healthcare lead identified phishing as the top vector by which attackers successfully breached healthcare organizations specifically. By IBM's 2026 report, voice and SMS phishing had become the most common initial access routes overall, appearing in 17% of breaches, with help-desk impersonation and other social engineering close behind — a shift that matters for healthcare, where high-turnover clinical and administrative staff field constant inbound contact. An illustrative earlier case involved AllCare Plus Pharmacy. In that attack, nearly 6,000 individuals potentially had their protected health information (PHI) exposed due to an email phishing attack that led to unauthorized access to the email accounts of several AllCare Plus Pharmacy employees. (Rodriguez 2023)
Insider Threats
While high-profile data breaches by threat actors generally capture news headlines, a significant percentage of breaches are the result of basic employee negligence, including unauthorized access or disclosure incidents. This negligence includes employees bringing PHI home or sending PHI to a personal account or device, viewing data without the proper authorization, and making email errors, such as sending PHI to incorrect recipients.
Healthcare organizations have made significant strides in tightening their administrative, physical, and technical controls; only one improper disposal incident was reported by a HIPAA-regulated entity in all of 2025. Unauthorized access and disclosure incidents, however, increased in 2025 and remain a persistent source of reportable breaches, even though they account for a small fraction of the records exposed relative to hacking.
Artificial Intelligence
Many healthcare organizations are adopting artificial intelligence (AI) to assist medical professionals and staff, provide 24/7 patient services, deliver quicker diagnoses and treatment, reduce costs, and provide better scalability across all business functions.
However, threat actors are similarly adopting the use of AI in cyberattacks. Threat actors can use AI to:
- Accelerate malware development, vulnerability discovery, and efforts to evade detection.
- Create more sophisticated, original, and targeted phishing attacks and draft phishing emails in multiple languages to appear more credible.
- Quickly analyze exfiltrated data to locate valuable personally identifiable information (PII) and PHI to make more credible threats and extort more money.
- Target AI models or their inputs, creating the potential for manipulated or unreliable outputs in clinical applications.
These are no longer theoretical concerns. IBM's 2026 report found that one in four malicious breaches were AI-enabled — a 56% increase over the prior year — and that AI-enabled breaches cost approximately $6 million on average, roughly $1 million above the global average. IBM's 2025 study also identified shadow AI, meaning unsanctioned AI tools adopted without IT approval, as a factor in 20% of breaches, almost all of them at organizations lacking AI access controls or governance. Healthcare organizations should therefore govern their own AI adoption — inventorying AI tools, restricting what data may be entered into them, and validating model outputs used in clinical decision-making — as a distinct workstream alongside defending against AI-enabled attacks.
Duty to Notify Patients, Regulators, and Business Partners
Following a cyber incident — including a data breach — organizations may have a legal duty to report the incident, depending on the nature of the incident and/or the type of data that was potentially compromised. This duty may be based on contractual requirements, state law, or federal law.
Healthcare organizations that are considered a "covered entity" under the Health Insurance Portability and Accountability Act (HIPAA), as well as their "business associates," are required to report certain cyber incidents to the Office for Civil Rights (OCR) pursuant to HIPAA. Under the HIPAA Security Rule, a ransomware attack is considered a "security incident." Once the ransomware is detected, the covered entity or business associate must initiate its security incident and response and reporting procedures.
For organizations governed by the Securities and Exchange Commission (SEC), a rule that took effect on December 15, 2023 and remains in force requires that domestic public companies report material cybersecurity incidents through a Form 8-K within four business days of discovery (with limited exceptions).
Organizations may also have a duty under state law to notify affected individuals and/or regulatory authorities of a breach of PII and PHI. Organizations must comply with the notification laws of the states in which the affected individuals reside, which may have different definitions of what constitutes PII, as well as different notification requirements. Organizations may also have contractual obligations to notify certain business partners in the event of a data breach.
The decision of whether to notify, who to notify, and how to notify often requires complex legal analysis. Therefore, it's strongly recommended that organizations consult with legal counsel before sending notifications. Improper notification could have negative consequences for an organization, including an increased likelihood of class actions, regulatory actions, and regulatory fines.
Furthermore, consulting with legal counsel experienced in handling data breach matters can help organizations better respond to the numerous inquiries they're likely to receive following the breach notification.
Finally, having the proper incident response plan in place, including breach counsel and other incident response vendors, can help the affected organization become more resilient.
Post-Breach Regulatory Investigations and Class Action Litigation
Unfortunately, completing an investigation and notifying of a breach doesn't necessarily signify the end of a cyber incident. In many cases, it merely marks the beginning of class action lawsuits and regulatory proceedings against the organization, both of which can result in multimillion-dollar settlements.
The US Department of HHS' OCR has the responsibility to enforce the Privacy and Security Rules of HIPAA, the standards for the protection of certain PHI through voluntary compliance activities, and the imposition of civil monetary penalties. OCR enforcement has accelerated sharply. In 2025, OCR resolved 21 settlements and civil monetary penalties — its second-highest annual total on record — collecting $8,330,066, and an incomplete or missing risk analysis remained the most frequently cited deficiency. Every action brought under OCR's Risk Analysis Initiative since October 2024 has included a finding under 45 CFR 164.308(a)(1)(ii)(A), making it the single most frequently cited provision in HIPAA enforcement. OCR also confirmed in March 2025 that the third phase of its HIPAA compliance audits is underway, beginning with 50 covered entities and business associates and focused specifically on the risk analysis and risk management requirements of the Security Rule.
In an earlier development, Blackbaud, a company that provides donor relationship management software, resolved claims arising from a 2020 breach. Blackbaud agreed to a $49.5 million settlement with 49 state attorneys general and the District of Columbia in October 2023 — not with OCR — resolving alleged violations of state consumer protection laws, state breach notification laws, and HIPAA arising from a 2020 ransomware attack, along with substantial corrective action governing its data security and breach notification practices. Inmediata, a healthcare clearinghouse, followed a similar pattern: it paid $1.4 million to a coalition of state attorneys general in October 2023 after a coding error left the PHI of approximately 1.56 million individuals exposed to search engines for nearly three years. OCR's own settlement in that matter was $250,000, imposed without a corrective action plan because the multistate action had already required Inmediata to overhaul its information security program. The distinction matters for risk modeling: state attorneys general, acting in coalition, have imposed materially larger financial penalties for HIPAA-adjacent failures than OCR has in the same matters. OCR's investigation into Change Healthcare, opened proactively in March 2024 before the breach had even been reported, remained open with no penalty announced as of mid-2026, as did its investigation into the 2024 Ascension attack. State attorneys general are also active: in 2025 the New York attorney general imposed a $500,000 penalty on Orthopedics NY LLP for cybersecurity failures that led to a breach affecting 656,086 individuals.
The regulatory bar is also set to rise. On January 6, 2025, OCR published a Notice of Proposed Rulemaking that would deliver the first substantive overhaul of the HIPAA Security Rule since 2013. (90 Fed. Reg. 898) The proposal would eliminate the longstanding "addressable" implementation specification category — making every specification mandatory, with no documented pathway to defer a control — and would require a written asset inventory and network map reviewed annually, an enhanced risk analysis assigning likelihood, impact, and risk level to each threat-vulnerability pair, multifactor authentication, encryption of ePHI at rest and in transit, and defined patching cadences. HHS estimated first-year compliance costs of approximately $9 billion across the regulated population. Critically, the rule is not law. The comment period closed on March 7, 2025 with roughly 4,745 comments, and no final rule had been issued as of August 2026. A coalition of more than 100 hospital and provider organizations led by the College of Healthcare Information Management Executives urged HHS to withdraw the proposal outright in a December 8, 2025 letter, and OMB's Unified Agenda (RIN 0945-AA22) now targets July 2027 for final action, pushed back from an earlier spring 2026 target. If finalized as proposed, the rule would take effect 60 days after publication with compliance required 180 days after that — a 240-day runway — plus a further transition period to amend business associate agreements. The existing Security Rule remains in force in the meantime, and OCR's enforcement pattern is the clearest available signal of what the agency expects. Organizations that build toward the proposed controls now — particularly a documented, current risk analysis — will be better positioned regardless of the rule's final form, and will reduce their exposure under the rule that is being enforced today.
Healthcare organizations also face significant potential risk of state and federal class action lawsuits following a data breach. Such lawsuits will typically assert common law causes of action, including negligence, breach of contract, and fraud, as well as statutory claims. The California Consumer Privacy Act and the Illinois Biometric Information Privacy Act are some statutes that have become a recent focus for plaintiffs' counsel in data breach litigation. Many healthcare organizations are facing legal scrutiny over alleged improper gathering and disclosure of PHI and other sensitive information via a web browser tracker called Meta Pixel and other session replay technologies, which are used to share and analyze data.
That expectation has been borne out, and settlements are arriving faster than they used to. Yale New Haven Health agreed to an $18 million settlement resolving a consolidated class action that amalgamated 18 separate complaints just seven months after its March 2025 breach. UnitedHealth's motion to dismiss the consolidated Change Healthcare litigation was denied, and that litigation remains pending. Ascension faced more than 30 consolidated class actions arising from its 2024 attack, alongside congressional inquiries. Healthcare organizations should assume that a breach of any material size will generate litigation within weeks of notification, and should plan notification strategy accordingly.
Cyber Insurance Coverage for Healthcare Organizations
Cyber liability insurance policies provide first- and third-party protection to businesses if sensitive information is compromised. They cover the first-party costs (expenses that an organization incurs directly due to a cyber incident), such as the cost to investigate and respond to a breach. They also provide first-party coverage for other types of loss resulting from a cyber incident, such as business interruption loss, data recovery costs, reputational harm, and extortion demands. A cyber insurance policy also provides access to the carrier's panel of experienced and vetted cybersecurity providers who can quickly assist policyholders with investigating and responding to a data security incident.
Cyber insurance policies further provide liability coverage to policyholders for third-party lawsuits or regulatory proceedings against them arising from cyber incidents. Third-party liability coverage helps pay for damages (settlements and judgments) the policyholder is legally obligated to pay, as well as claim expenses (attorney's fees and court costs) to defend the policyholder against the claims.
Finally, many cyber insurance policies now also include some limited eCrime coverage. This coverage may include certain coverages typically found under a crime policy, such as social engineering, funds transfer fraud, or invoice manipulation coverage. It's evident that the costs of a cyber incident can be devastating to a business. Research has shown that healthcare has the most expensive data breach costs of any industry — a distinction it has held for 14 consecutive years — averaging $7.42 million per US incident in IBM's 2025 report, down from $9.77 million the prior year and $10.93 million in 2023. (IBM 2025) That decline should not be read as relief: IBM's 2026 report kept healthcare at the top globally for the thirteenth consecutive year even as the all-industry global average climbed 12% to a record $4.99 million, and the US all-industry average reached $10.22 million, the highest of any country.
Cyber insurance remains an important mechanism for transferring a portion of the financial risk associated with cyber incidents. Market conditions have shifted markedly since the hard market of 2021-2022. Capacity is abundant, new carriers and managing general agents have entered the segment, and rates have been falling: Marsh reported that global cyber insurance rates declined 5% in the first quarter of 2026, and Lockton put the median Q1 2026 decrease at 0.5%. The global cyber market reached roughly $16 billion in premium in 2025 and is widely projected to exceed $40 billion by 2030. Softening is not uniform, however, and healthcare is among the sectors seeing the least of it. Underwriters are actively differentiating on privacy exposure and control maturity rather than competing on retention, several major carriers are pushing for flat primary renewals in healthcare specifically, and reinsurers are applying heightened scrutiny to healthcare portfolio concentrations. Buyers with rapid growth, adverse loss experience, or weaker controls should still expect upward pricing pressure, tighter sublimits for specific perils, and more restrictive coverage wordings. Notably, the NAIC reported that claim frequency rose nearly 40% in 2024 even as US premiums fell — lower rates reflect competition and improved loss ratios, not a reduction in underlying risk.
Carriers are also becoming increasingly disciplined in the risk selection process, requiring more data from applicants and scrutinizing their data protection controls and regulatory compliance. Supplemental applications addressing ransomware risks specifically are also becoming more common. Carriers are increasingly relying on security scans and attack surface monitoring to gain a better understanding of the organization's cybersecurity vulnerabilities. Some carriers also have non-renewed policies, where the organization cannot show that multifactor authentication has been implemented across the organization. The emphasis in 2026 is on proof rather than attestation: underwriters increasingly require evidence of verifiable immutable backups, tested recovery time objectives, endpoint detection and response coverage, and patching discipline. Lower premiums have not translated into lighter underwriting — in this market, price and scrutiny are moving in opposite directions.
Conclusion
Healthcare organizations face growing and evolving cyber risks that threaten not only their bottom line and reputation but also critical services and patients' health and safety. There's no indication that these risks will abate at any time in the foreseeable future, and the patient-safety consequences are now measurable rather than theoretical.
Healthcare organizations should invest in layered cybersecurity controls, such as endpoint monitoring and detection, as well as segmented, encrypted, and offline or immutable backups to reduce the average time to identify and respond to a breach and the potential cost of a breach. Employee training, particularly in relation to avoiding phishing emails, can be very effective in reducing the risk of a ransomware attack and in protecting PHI. The HHS Cybersecurity Performance Goals, together with the controls set out in the proposed 2025 HIPAA Security Rule update — asset inventory, network mapping, current risk analysis, multifactor authentication, encryption, and tested recovery — offer the clearest available roadmap for where to focus organizational efforts and resources for high-impact results, whether or not that rule is finalized in its current form.
Finally, cyber insurance, though it may be more costly and difficult to acquire than in previous years, is still an effective mechanism for managing an organization's cyber risk exposure and helping an organization respond more quickly and effectively to a data breach.
Author
Make Gallagher Bassett your dependable partner
When making the right decision at the right time is critical to minimize risk for your business, count on Gallagher Bassett's extensive experience and global network to deliver.