The EHR Association’s Privacy & Security Workgroup issued the following statement to mark Cybersecurity Awareness Month (October).
“In healthcare, cybersecurity protects more than data. It protects clinicians’ ability to deliver quality care. When a cyberattack forces a health system to take its records and scheduling systems offline, divert ambulances and delay procedures, the consequences reach the bedside.”
Understanding the scale and nature of that risk is the first step toward reducing it and the dangers it presents to healthcare providers and patients. At its 2026 HIPAA Security conference, OCR reported that in 2025, healthcare organizations reported 650 large data breaches, each affecting 500 or more people and collectively exposing the protected health information (PHI) of over 45 million individuals.
Behind those numbers are consequences. When PHI is stolen or falls into the wrong hands, it frequently exposes sensitive medical conditions and personally identifiable data, putting patients at risk for severe financial fraud, identity theft, and/or extortion. Such incidents erode patient trust in the privacy of their data and may cause individuals to withhold sensitive health information from healthcare providers. Disrupted operations from cybersecurity attacks also lead to treatment delays (potentially resulting in longer hospital stays and increased complications), and compromised system integrity can even contribute to higher patient mortality rates.
The financial stakes are also significant. Healthcare has historically carried the highest average cost of a data breach of any industry, reaching $6.64 million in IBM’s 2026 “Cost of a Data Breach” study. The associated losses inevitably carry over to the cost of care, forcing patients to shoulder at least some of the financial burden.
Ultimately, cyber risk is far from only a technical problem. Protecting health information depends as much on people, processes, and access controls as it does on technology.
“Strengthening healthcare cybersecurity is a shared responsibility among health IT developers, the healthcare organizations that deploy their technology, the individual users of the software, and the policymakers who shape the environment in which both operate. This Cybersecurity Awareness Month, we encourage every organization in the healthcare ecosystem to treat security as a core element of patient safety, investing in workforce awareness and sound access practices alongside technical safeguards.”
