Healthcare data breach costs have hit $6.64 million in 2026, the highest of any industry studied and 33% above the global average of $4.99 million. There’s a sliver of good news buried in that. Costs are down 11% compared to 2025. But healthcare has held the top spot for over a decade, and being a quarter above everyone else while “improving” tells you something about how far there is to go.
Why healthcare data breach costs keep climbing
Three things drive the number up. The data itself is dense and hard to compartmentalise, patient records, insurance details, clinical histories, often sitting across ageing systems that were never built with today’s threats in mind. Regulatory exposure adds another layer, healthcare breaches trigger compliance and notification obligations that other sectors don’t carry to the same degree. And the operational side matters too, a breach in a hospital system isn’t just a data problem, it can affect patient care directly, which changes the cost calculus entirely.
The response gap: 220 days to spot it, 72 days to fix it
Healthcare organisations take 220 days on average to identify a breach and a further 72 days to contain it. That’s nearly ten months, start to finish, before an incident is fully dealt with.
Every day a breach goes undetected is a day it can spread further, touch more systems, and expose more data. In a sector already paying the highest costs per breach, that lag is expensive in a very literal sense.
What’s actually causing the breaches
Understanding root cause matters more than most security conversations give it credit for. In healthcare:
- Malicious attack: 59% of breaches
- Human error: 21%
- IT failure: 20%
That’s a clear majority driven by deliberate attackers, but four in ten breaches still come down to mistakes and system failures, both of which are addressable without a single new piece of attacker-facing technology.
How attackers are getting in
The top three initial attack vectors in healthcare, as a share of all breaches, are:
- Phishing: 17%
- Supply chain compromise: 15%
- Social engineering: 13%
Together that’s 45% of breaches starting with someone being tricked, or a third party being the weak link. Not exotic exploits. Not zero-days. People, process, and partners.
What this means in practice
None of this is abstract for a healthcare IT or security lead. It points to three practical priorities, faster detection so the 220-day identification window starts closing, stronger supply chain oversight given how often third parties are the entry point, and continued investment in the human side of security, since phishing and social engineering together outweigh supply chain as an attack route.
The organisations narrowing that 220-day gap and cutting into the phishing numbers are the ones that will start pulling their average cost down from $6.64 million, not just by 11% year on year, but meaningfully.
The Northdoor view
“Healthcare has topped this list for years, so $6.64 million on its own isn’t the surprising part,” says AJ Thompson, Chief Commercial Officer at Northdoor. “What stands out is the 220 days to identify a breach. That’s the same problem we see across a lot of healthcare IT estates, older infrastructure, disconnected systems, and nobody with a full picture of where the data actually sits. You can’t detect fast in an environment you can’t see clearly.
“The attack vector numbers back that up too. Phishing and social engineering together outweigh supply chain compromise, which tells you attackers are still finding it easier to go through people than through code. That’s not a reason to ease off on technical controls, it’s a reason to treat detection speed and staff awareness as seriously as the perimeter.”
If you want to talk through where your organisation sits against these numbers, get in touch with the Northdoor team.
Get the full report on healthcare data breach costs
This is a summary of the healthcare-specific findings behind this year’s healthcare data breach costs.
Download the full Healthcare Edition PDF from our resource library for the complete sector breakdown and IBM’s recommendations.
For the global data and industry comparisons, download the Cost of a Data Breach Report 2026 direct from IBM.