Healthcare Suffered More Data Breaches Than Finance in 2024

Finance and healthcare have long been the two industries most targeted by cybercriminals; however, healthcare overtook healthcare last year for data breaches according to the financial and risk advisory firm Kroll. Last year, 23% of data breaches tracked by the company were conducted on healthcare organizations, with the industry taking a narrow lead on finance which accounted for 22% of data breaches. In 2023 those positions were reversed, with 26% of data breaches in finance and 18% in healthcare.

The increased focus on healthcare is understandable, as healthcare records are much more valuable to cybercriminals than financial information, which can only be misused for a short period of time. In contrast, healthcare records can be misused for longer and for a much wider range of nefarious purposes. Healthcare providers are also reliant on access to data, so ransomware attacks that encrypt that data have an impact on patient care, increasing the likelihood of the ransom being paid. Further, healthcare organizations have complex IT environments that are challenging to secure, making attacks relatively easy. Kroll also notes that compared to other industry sectors, incident response practices at healthcare organizations were fairly immature, with data breaches forcing healthcare executives to think deeply about the risk to their businesses.

The report provides insights into the level of concern of consumers about data breaches in different industries. Kroll is a provider of credit monitoring and identity theft protection services, and its data shows that consumers are more likely to take advantage of credit monitoring services after a healthcare data breach than data breaches in other industries, highlighting their level of concern about having their healthcare data compromised.

The take-up rate for those services, when offered, was 45% in healthcare, up 85% on the previous year. The increase in consumers signing up for credit monitoring services after healthcare data breaches could be due to highly publicized data breaches in 2024, such as the data breach at Change Healthcare. Credit monitoring services were offered in advance of notification letters being mailed, with state attorneys general advising state residents to ensure they take advantage of those services due to the risk of misuse of their information. That message appears to have hit home. By comparison, data breaches at technology companies had the second highest take-up rate, although only 25% of victims of those breaches chose to avail of the offered services.

Interestingly, concern about data breaches was higher at technology firms, based on calls to Kroll’s helpline. Consumers were more likely to sign up for credit monitoring services after a healthcare data breach, but Kroll received a higher percentage of calls about technology data breaches (33%) than healthcare data breaches (30%), with call volume in response to breaches at technology firms increasing by 69% year-over-year while calls related to healthcare data breaches fell by 21% year-over-year.  Kroll attributes the increase in concern about technology breaches to the continued prevalence of third-party risk. A breach at a technology company can have far-reaching implications due to the interconnectedness of businesses, as was demonstrated by the outages caused by faulty software updates at CrowdStrike.

About Liam Johnson

Liam Johnson has produced articles about HIPAA for several years. He has extensive experience in healthcare privacy and security. With a deep understanding of the complex legal and regulatory landscape surrounding patient data protection, Liam has dedicated his career to helping organizations navigate the intricacies of HIPAA compliance. Liam focusses on the challenges faced by healthcare providers, insurance companies, and business associates in complying with HIPAA regulations. Liam has been published in leading healthcare publications, including The HIPAA Journal. Liam was appointed Editor-in-Chief of The HIPAA Guide in 2023. Contact Liam via LinkedIn: https://www.linkedin.com/in/liamhipaa/