Healthcare Breach Evidence Review

When investigators can name the attack vector, 88% of breached healthcare records trace to a phished or stolen credential.(PDF)

With the help of AI we have analysed all 7,834 breach filings in the US federal register (HHS OCR, 2009 → July 2026, 1.05 billion records lost) and asked a simple question: how many of those records would still be private if only TWO BASIC CONTROLS had held?

  1. If credentials had been non-phishable: at least 363 million records — 1 in 3 ever lost — could still be private. (Most likely much more since two-thirds of case files name no cause at all.)

  2. If internet-facing servers had been patched: ~47 million traceable records (4.4%).

Unpatched systems are actually the #1 way attackers break in by count (31–32% of intrusions, per Verizon DBIR and Mandiant M-Trends). But they mostly produce mid-size breaches.

The catastrophes — the 100M+ events — happen when someone logs in through a remote-access portal with a phished or stolen credential. Attackers don't hack the big data stores. They log into them.

Two more findings from the register:

▪️ Breach frequency is flat since 2021; the median breach tripled in size. Fewer surprises, bigger blast radius.

▪️ Six of the ten largest breaches ever were vendor incidents. The supply chain is the blast radius.