Verizon's 2026 Data Breach Investigations Report (DBIR), published in May 2026, records 1,492 healthcare incidents and 1,438 confirmed data disclosures over the reporting window. Across all sectors the report covers 31,000+ incidents and 22,000 confirmed breaches in 145 countries; the healthcare cut is one of the report's longest-running industry breakdowns.
The leading initial-access vectors in healthcare are vulnerability exploitation (20%), phishing (14%), stolen credentials (11%), and employee errors (11%). Ransomware drove 48% of breaches across all sectors, up from 44% in the 2025 report. The median ransom paid fell to $139,875 from $150,000, and 69% of victims did not pay.
Third parties now feature in 32% of healthcare breaches, against 48% across all industries combined. The human element (phishing, misdelivery, misconfiguration, loss) was involved in 54% of healthcare incidents, with misdelivery the largest single component at 40%.
Vulnerability remediation remains the weakest link. Only 26% of critical vulnerabilities were fully remediated in 2025, with a median time to resolution of 43 days. For a sector in which ransomware operators routinely exploit known unpatched vulnerabilities, the gap between disclosure and remediation is the operational problem underlying the headline incident count.
Sources
Sources: 2026 Data Breach Investigations Report (Verizon, May 2026); Verizon: Healthcare Sector Facing Sustained, Multi-vector Attacks (HIPAA Journal, 20 May 2026); Lessons for organizations from the Verizon 2026 Data Breach Investigations Report (Help Net Security, 25 May 2026).
