Between 2024 and 2025 the healthcare sector reported more than 700 breaches exposing over 275 million records, an increase of around 63.5% on 2023.
The Number Exceeds The Population It Describes
275 million records against a US population of roughly 340 million does not mean four in five Americans were affected once. It means many people were affected repeatedly, by different organisations, holding overlapping copies of the same clinical history.
That is the aggregation problem this desk keeps filing, and healthcare is where it is most acute: a single episode of care generates records at a provider, an insurer, a laboratory, a pharmacy benefit manager, a billing processor and a risk-adjustment vendor — six copies, six independent breach exposures.
Which Breaks The Remediation Model Completely
Credit monitoring is offered per incident, by the breached organisation, for a fixed term. A person affected by four healthcare breaches in two years receives four overlapping enrolments from four companies for the same underlying identity.
And for medical data specifically, monitoring is close to useless — there is no equivalent of a credit file for a leaked diagnosis, which is the point this desk made about biometrics at 26-0324 and children at 26-0113.
What A Saturated Dataset Means
At this volume, the practical question stops being whether a given person’s health data has been exposed and becomes how many times and by whom.
That has an uncomfortable implication for how organisations reason about risk. Marginal exposure from one more breach is genuinely lower when the data is already circulating — and that is an argument nobody should be allowed to make out loud, because it is a reason to stop trying.
Built on published sector statistics, listed below. Record counts aggregate filings with differing definitions and include duplicate coverage of the same individuals; they are not a count of distinct people. Corrections: corrections@forensicpost.com.