Skip to main content
HomeTopicsHealthcare

Healthcare

We've curated 322 cybersecurity statistics about Healthcare to help you understand how data breaches, ransomware attacks, and the adoption of telehealth technologies are reshaping patient privacy and security practices in 2025.

Showing 141-160 of 322 results

37% of healthcare organizations resolve critical findings in business-critical assets within four to seven days.

Cobalt9/3/2025
Pen testVulnerabilities

Nearly 40% of healthcare SLAs require serious findings in business-critical assets to be fixed within three days. Another 40% require resolution within four to 14 days.

Cobalt9/3/2025
Pen testSLA

14% of healthcare organizations resolve critical findings in business-critical within eight to 14 days.

Cobalt9/3/2025
Pen testVulnerabilities

71% of healthcare leaders cited GenAI as the top risk.

Cobalt9/3/2025
GenAI

Just 13.3% of healthcare pentest findings qualify as “serious”. This ranks healthcare 6th-best out of 13 industries.

Cobalt9/3/2025
Pen testVulnerabilities

Healthcare’s median time to resolve serious pen test findings was 58 days. This ranks healthcare 10th of 13 industries. Hospitality led with 20 days.

Cobalt9/3/2025
Pen testVulnerabilities

68% of healthcare leaders cited third-party software as the top risk.

Cobalt9/3/2025
Third-party risk

Healthcare’s half-life for serious pen test findings was 244 days. This ranks healthcare 11th of 13 industries. Transportation had a half-life of 43 days.

Cobalt9/3/2025
Pen testVulnerabilities

Healthcare expects a 53% rise in insider threats.

Exabeam8/21/2025
Insider threat

43% of small healthcare organisations reported experiencing a phishing or spoofing incident in the past year.

Paubox8/19/2025
PhishingSpoofing

Nearly half of healthcare email breaches stem from Microsoft 365 alone.

Paubox8/19/2025
EmailEmail breaches

"Small" violations can cost healthcare practices anywhere from $25,000 to $9.76 million per incident.

Paubox8/19/2025
Compliance

64% of small healthcare practices believe patient portals are required for HIPAA compliance.

Paubox8/19/2025
ComplianceHIPAA

Over 90% of U.S. healthcare providers operate as small organisations.

Paubox8/19/2025

About 50% of small healthcare organisations lack anti-phishing controls beyond default spam filters.

Paubox8/19/2025
PhishingSpam

One-third of small healthcare practices report not having enough time for compliance tasks.

Paubox8/19/2025
Compliance

Salud Family Health had a phishing attack exposing 80,000+ records.

Paubox8/19/2025
Phishing

Solara Medical faced a $9.76 million class-action settlement following a phishing attack.

Paubox8/19/2025
Phishing

98% of small healthcare practices claim their platforms "encrypt emails by default".

Paubox8/19/2025
EmailEmail encryption

Sunrise Community Health experienced an email compromise affecting 54,000+ patients.

Paubox8/19/2025
Email compromise