
Cost of breaches: Healthcare still leads all sectors, and AI is used in more attacks
Key Takeaways
- Healthcare breaches averaged $6.64 million, exceeding the global mean and narrowly outpacing financial services, reinforcing that sector-specific operational fragility and data value drive persistent premium breach costs.
- Declining breach costs correlate with greater refusal to pay ransoms, forcing attackers to reduce demands, and with expanded cybersecurity spend prompted by repeated targeting.
IBM's annual report shows healthcare breaches are the most expensive. Limor Kessem of IBM discusses the threats to healthcare organizations, the rising role of AI, and the progress some organizations are making.
Healthcare data breaches continue to be more expensive than those in any other industry.
IBM released
It’s the 13th consecutive year that healthcare has led all industries in the cost of breaches.
However, healthcare breaches are getting a bit less expensive, with the average cost dropping from $7.42 million in last year’s report.
Limor Kessem, global lead of IBM Consulting’s X Force Cyber Crisis Management, tells Chief Healthcare Executive® that healthcare organizations are making some progress in improving cybersecurity. She notes that the average cost of breaches in all sectors rose 12%, while the cost of the average healthcare data breach dropped by nearly 11%.
Kessem cites one interesting factor in healthcare breaches becoming less costly. Some healthcare organizations aren’t buckling under
“What is changing is that more and more organizations refuse to pay, and as they refuse to pay, the attackers keep dropping the ransom,” Kessem says. “They're like, OK, if we can't get $20 million, we're going to try to get five.’ You know, they just keep dropping it, which makes the overall costs go down.”
Kessem also suggests that healthcare organizations are investing more in cybersecurity as a result of having to deal with attacks.
“I think when healthcare organizations have been targeted more and more and more, they're starting to realize they have to invest more and are starting to do things,” Kessem says. “And that's when you see the cost of the data breach going down a little bit.”
AI, on offense and defense
More health systems are incorporating AI technology into their cybersecurity defenses, she says.
“They're using more AI across also their security stack,” Kessem says.
More healthcare organizations are also investing and putting more time in planning how to respond to attacks.
“They're a lot more ready and prepared with plans and disaster recovery,” she says.
The report also warns that AI is changing cybersecurity, on both offense and defense. More attackers are using AI in their efforts to penetrate organizations.
AI-driven attacks rose by 56% over the past year, according to the report. More than a quarter of organizations reporting attacks said that they were driven by AI.
Kessem says she didn’t expect to see such an uptick in AI-driven cyberattacks.
“I was surprised by the fact that there are already so many AI attacks,” she says. “And I don't know if I was very surprised that companies don't really put enough controls around what they do with AI, and don't really have good identity management, especially for non-human identities. Those are huge things.”
Breaches caused by attackers using AI cost about $6 million, on average, about $1 million more than other breaches, according to the report.
Cybersecurity analysts have warned that
Kessem says AI has changed the economics for ransomware groups. Ransomware groups can spend modest sums, just thousands of dollars, and potentially cause breaches costing organizations millions of dollars.
“For attackers now using AI, everything is so breezy,” she says. “It's a lot faster. They don't need expertise. They could get anything they want from chatbots and from more professional chatbots. So where they used to invest a lot more into an attack, now they invest very little and they don't really actually have to have skills, not much anyway.”
The report warned that the emergence this year of an AI-powered “frontier model” found thousands of vulnerabilities in major operating systems and web browsers, and that needs to be an area of focus for cybersecurity professionals.
Half of organizations reporting breaches say they’re using AI agents to hunt for threats and contain them, but only 18% are using them to search for areas where they may be vulnerable, the report says.
Healthcare is the top target
While cybersecurity analysts say healthcare has typically lagged other sectors when it comes to cybersecurity, the costs in other industries are getting a bit closer. The average breach in the financial sector cost an average of $6.3 million, just a few hundred thousand dollars below the healthcare industry, the report states.
Kessem says there are a lot of good things happening in healthcare organizations when it comes to cybersecurity, which is a welcome change.
“Historically they didn't have great security, and not because they didn't want to have great security,” she says. “It’s because their whole IT environment is so heterogeneous.”
Health systems often require FDA approval for updating devices and software, and some systems use a number of tools that can’t easily be updated, if at all.
Plus, attackers are going to target hospitals and other healthcare providers because they know some are still going to be leery of lengthy outages of key computer systems that could impact patient care.
“The core issue too is that the disruption in healthcare organizations is huge, and they don't want to be stuck with it,” Kessem says. “So the leverage that the attackers have on them is a lot bigger.”
Ransomware groups know hospitals have money, and they are holding onto vast amounts of personal information on patients, which can be lucrative. Kessem says she is seeing more healthcare organizations investing in data encryption, which can help offer more protection if attackers gain access to an organization’s data.
Each year,
Kessem says healthcare organizations need to be conscious of data security, and they also need to keep track of the AI tools that their employees are using.
Organizations must be ready to adapt to emerging threats and AI-enabled attacks.
“Things are fast changing,” Kessem says. “We also have to evolve very quickly.”





















































