Check-In on Industry Predictions: Healthcare Breaches

by Guest Contributor 3 min read November 2, 2016

Late last year, our Third Annual Data Breach Industry Forecast predicted cybercriminals would continue to focus their attacks on healthcare institutions, inspired by the knowledge that the black market value of medical records continues to surpass the value of credit card numbers. Industry experts we interviewed also predicted employee missteps would be a source of healthcare breaches.

Entering the final quarter of 2016, our prediction is playing out in the numbers; nearly half of all consumers affected by a data breach so far this year had their personal information exposed through a healthcare-related incident, according toinformation compiled by the Identity Theft Resource Center.

In the first three quarters of the year, 256 medical and healthcare data breaches exposed more than 13.5 million records, the highest number of any sector the ITRC tracks. Records compromised in a healthcare breach accounted for 47.2 percent of all affected records in 2016.

The healthcare sector has been a hotbed of attacks throughout the year, largely due to the continued value of medical records sold on the dark web. These records can be used for far more than just filing fraudulent medical claims. One lucrative use is filing fraudulent tax returns.CNBC reportedthe IRS expects, and has been bracing for, an increase in tax fraud linked to the high number of medical breaches this year.

It’s easy to understand why medical records can be so profitable for hackers. While financial accounts such as credit cards may contain a limited amount of personal information, medical records are much more comprehensive. Typically, they contain a wealth of information far beyond mere account numbers. In addition to names, addresses and birth dates, medical records often contain Social Security numbers, which healthcare providers may use as patient identifiers.

The employee factor

Many of the mega-breaches of 2015 occurred through digital routes that the average consumer would find downright arcane. In 2016, we’ve seen an increase in smaller attacks with mundane origins such as stolen hardware, poorly secured employee email accounts or phishing attacks. Consider these examples reported in the HIPAA Journal:

For healthcare institutions, the takeaway from 2016 should be the need to remain vigilant and proactive regarding the many ways in which data breaches can occur. While 2015 was the year of healthcare mega-breaches, 2016 has seen the emergence of smaller breaches that still have the potential to cause significant harm to organizations and patients.

Related Posts

2026-2027 Data Breach Response Guide

Our Data Breach Response Guide provides guidance to help your organization prepare, respond and recover while protecting your customers.

September 30, 2026 by Laura Burrows
2027 Data Breach Forecast: Why Trust Is Becoming the Next Cybersecurity Battleground

AI, digital doppelgängers and growing consumer skepticism could reshape the data breach landscape in 2027. Here’s what to prepare for.

September 29, 2026 by Laura Burrows
2026 Fintech Identity and Fraud Report

Explore the Fintech Identity and Fraud Report for insights on AI-driven fraud threats, identity protection and the evolving fraud landscape.

September 28, 2026 by Laura Davis

Subscribe to our Newsletter

Enter your name and email for the latest updates.

This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.

Subscribe to our Newsletter

Don't miss out on the latest industry trends and insights!
Subscribe