Healthcare Breach Evidence Review
With the help of AI we have analysed all 7,834 breach filings in the US federal register (HHS OCR, 2009 → July 2026, 1.05 billion records lost) and asked a simple question: how many of those records would still be private if only TWO BASIC CONTROLS had held?
If credentials had been non-phishable: at least 363 million records — 1 in 3 ever lost — could still be private. (Most likely much more since two-thirds of case files name no cause at all.)
If internet-facing servers had been patched: ~47 million traceable records (4.4%).
Unpatched systems are actually the #1 way attackers break in by count (31–32% of intrusions, per Verizon DBIR and Mandiant M-Trends). But they mostly produce mid-size breaches.
The catastrophes — the 100M+ events — happen when someone logs in through a remote-access portal with a phished or stolen credential. Attackers don't hack the big data stores. They log into them.
Two more findings from the register:
▪️ Breach frequency is flat since 2021; the median breach tripled in size. Fewer surprises, bigger blast radius.
▪️ Six of the ten largest breaches ever were vendor incidents. The supply chain is the blast radius.