▾ G11 Media Network: | ChannelCity | ImpresaCity | SecurityOpenLab | Italian Channel Awards | Italian Project Awards | Italian Security Awards | ...
InnovationOpenLab

Email Is Healthcare’s Biggest Security Risk–2025 Report Uncovers Alarming Gaps

A new report analyzing 180 healthcare email breaches from January 1, 2024, to January 31, 2025 reveals widespread cybersecurity issues and escalating regulatory penalties. Paubox’s 2025 Healthcare E...

Business Wire

SAN FRANCISCO,: A new report analyzing 180 healthcare email breaches from January 1, 2024, to January 31, 2025 reveals widespread cybersecurity issues and escalating regulatory penalties. Paubox’s 2025 Healthcare Email Security Report highlights how email remains the leading attack vector, resulting in financial penalties, compromised patient data, and increased enforcement actions from regulators.

Key Findings:

  • 43.3% of breaches involved Microsoft 365.
  • Barracuda, Proofpoint and Mimecast accounted for 26.7% of breaches
  • 264% increase in ransomware attacks on healthcare since 2018.
  • Only 1.1% of analyzed healthcare organizations had a low-risk email security posture, highlighting systemic vulnerabilities.
  • HIPAA fines exceeding $9 million were issued due to email security failures, including Solara Medical Supplies’ $9.76 million settlement.
  • $9.8 million – The average cost per healthcare email breach, according to IBM.

Email security remains healthcare’s biggest weakness

Despite a 50% increase in healthcare cybersecurity spending since 2018, many healthcare organizations still fail to implement fundamental email security protocols. 37.2% of Microsoft 365 users had DMARC in ‘monitor-only’ mode, leaving phishing attempts undetected. According to a Paubox survey, “only 27% of IT leaders feel confident about avoiding a breach in 2025.”

According to OCR Director Melanie Fontes Rainer, “HIPAA-regulated entities need to be proactive in ensuring their compliance with the HIPAA Rules, and not wait for OCR to reveal long-standing HIPAA deficiencies.” The prevalence of email-related breaches in 2024 underscores this warning, as many healthcare organizations only realize their security gaps after a serious incident occurs.

Regulators are increasing enforcement

The HHS Office for Civil Rights (OCR) has intensified HIPAA enforcement, issuing record fines for email security failures and insufficient risk assessments. Recent high-profile cases include:

  • Solara Medical Supplies - $9.76 million settlement due to a phishing-related breach affecting 114,000 patient records.
  • L.A. Care - $1.3 million fine for systemic security lapses that led to a breach.

Get the full report

The 2025 Healthcare Email Security Report, created by Paubox and sourced from HHS Office for Civil Rights (OCR) breach data, provides an in-depth analysis of real-world breaches, industry trends, and actionable security recommendations to help healthcare IT leaders strengthen their defenses.

Access the report here: https://hubs.la/Q03c8Npb0

For media inquiries, expert commentary, or interview requests, please contact Dawn Halpin at Paubox at press@paubox.com or 415-795-7396.

About Paubox

Paubox offers HIPAA compliant communication solutions that empower healthcare organizations of any size to simply and securely communicate. Our suite of solutions includes HIPAA compliant encrypted email, inbound email security, HIPAA compliant email marketing, and HIPAA compliant email API for transactional communications. Our customers love our HITRUST certified solutions and we have industry-topping G2 ratings (4.9/5 stars). Learn more at paubox.com

Fonte: Business Wire

If you liked this article and want to stay up to date with news from InnovationOpenLab.com subscribe to ours Free newsletter.

Related news

Last News

RSA at Cybertech Europe 2024

Alaa Abdul Nabi, Vice President, Sales International at RSA presents the innovations the vendor brings to Cybertech as part of a passwordless vision for…

Italian Security Awards 2024: G11 Media honours the best of Italian cybersecurity

G11 Media's SecurityOpenLab magazine rewards excellence in cybersecurity: the best vendors based on user votes

How Austria is making its AI ecosystem grow

Always keeping an European perspective, Austria has developed a thriving AI ecosystem that now can attract talents and companies from other countries

Sparkle and Telsy test Quantum Key Distribution in practice

Successfully completing a Proof of Concept implementation in Athens, the two Italian companies prove that QKD can be easily implemented also in pre-existing…

Most read

Alibaba Group Announces March Quarter 2025 and Fiscal Year 2025 Results

$BABA #alibaba--Alibaba Group Holding Limited (NYSE: BABA and HKEX: 9988 (HKD Counter) and 89988 (RMB Counter), “Alibaba”, “Alibaba Group” or the “company”)…

U.S. Data Center Construction Market Outlook Report 2025-2030 Featuring…

The "U.S. Data Center Construction Market - Industry Outlook & Forecast 2025-2030" report has been added to ResearchAndMarkets.com's offering. The…

J.D. Power Names Joshua Peirez New CEO

J.D. Power today announced that Joshua Peirez will assume the role of President and CEO of J.D. Power, guiding the company in its next phase of growth…

IMVARIA Reports Multi-Site Clinical Experience With FDA-Authorized AI…

#ATS--IMVARIA Inc., a health tech company pioneering AI-driven digital biomarker solutions, today reported results from multi-site clinical experiences…

Newsletter signup

Join our mailing list to get weekly updates delivered to your inbox.

Sign me up!