- Research Article
- 10.2147/jmdh.s609209
Cybersecurity in Healthcare: Ensuring Patient Safety and Data Privacy
- May 14, 2026
- Journal of Multidisciplinary Healthcare
- Diane Dolezel + 2 more +2
ObjectiveHealthcare data breaches have increased in both frequency and severity, yet limited empirical evidence exists on the factors associated with large-scale breach events. To address this gap, this study analyzed breaches reported to the US Department of Health and Human Services Office of Civil Rights between 2010 and 2025 to determine predictors of large breaches.MethodsA total of 7327 breach reports from the Office for Civil Rights were analyzed. Logistic regression assessed predictors of high‑severity incidents (≥ 100,000 individuals affected). Differences in breach size between incident types were assessed using Wilcoxon rank‑sum tests. Negative binomial regression modelled factors associated with breach magnitude and temporal trends in Hacking/IT classifications over time, adjusting for covariates.ResultsBreach sizes were highly right-skewed; the median breach affected 3892 individuals (IQR: 1255–19,471), and roughly 10% of the incidents accounted for the majority of individuals affected. Hacking/IT events were associated with severe breaches (OR = 2.6) and increased from 4% in 2010 to 80% in 2025. Network server incidents resulted in significantly larger breaches than device theft events. Business associate involvement was independently associated with a larger breach magnitude (IRR = 2.0).ConclusionHacking/IT mechanisms, network server involvement, and business associate participation were the strongest factors associated with breach severity and magnitude. These findings highlight persistent vulnerabilities in healthcare organizations and reinforce the need for targeted cybersecurity strategies.
Read more