-

New Paubox Report Reveals 60% of Healthcare Orgs Admit Email Security Failure

SAN FRANCISCO--(BUSINESS WIRE)--A new Paubox report uncovers significant email security vulnerabilities in healthcare. This report reveals that 60% of healthcare organizations surveyed experienced email-related security incidents last year that exposed sensitive patient data. Despite this, most attacks go unreported. Only 5% of known phishing attacks and 4% of known HIPAA email violations are reported to security teams.

Only 5% of known phishing attacks and 4% of known HIPAA email violations are reported to security teams.

Share

Why this matters: Email remains healthcare’s most vulnerable cyberattack entry point, and IT leaders don’t have a handle on it. Andrea Palm, Deputy Secretary of Health and Human Services, emphasizes: “Cyber attacks directly compromise patient safety, making robust email security essential.”

Report highlights:

  • 60% of healthcare IT leaders reported email security breaches or security incidents last year.
  • Only 5% of known phishing attacks are reported to security teams.
  • Healthcare IT teams aren’t just dealing with spam or hackers—they’re dealing with infrastructure that undermines their mission.
  • IT leaders underestimate the costs of a HIPAA violation by a factor of four.

You might think that the gap between incidents and reporting points to a critical training or culture issue. However, 90% of healthcare organizations conduct regular employee training on email security best practices.

Hoala Greevy, CEO of Paubox, states: “Healthcare doesn’t need more patchwork fixes—it needs a mindset shift. Patients expect secure, convenient communication, and it’s on us to meet that standard. With AI, automation, and built-in encryption, we can proactively defend patient data before threats ever hit the inbox. That’s exactly what we built ExecProtect+ to do—eliminate risk at the source, not after the damage is done.”

Download the full report here: https://hubs.la/Q03hcR7X0

For media inquiries, expert commentary, or interview requests, please contact Dawn Halpin at Paubox at press@paubox.com or 415-795-7396.

About Paubox

Paubox offers HIPAA compliant communication solutions that empower healthcare organizations of any size to simply and securely communicate. Our suite of solutions includes HIPAA compliant encrypted email, inbound email security, HIPAA compliant email marketing, and HIPAA compliant email API for transactional communications. Our customers love our HITRUST certified solutions and we have industry-topping G2 ratings (4.9/5 stars). Learn more at paubox.com

Contacts

Media Contact:
Dawn Halpin
press@paubox.com

Paubox


Release Summary
A new Paubox report reveals that 60% of healthcare organizations surveyed experienced email-related security incidents last year.
Release Versions

Contacts

Media Contact:
Dawn Halpin
press@paubox.com

Social Media Profiles
More News From Paubox

92% of Healthcare IT Leaders Believe They’re Prepared to Prevent Email Breaches. They’re Not.

SAN FRANCISCO--(BUSINESS WIRE)--A new Paubox report shows just how off the mark healthcare IT leaders are about their email security. Based on first-party data from 150 U.S.-based healthcare IT leaders, the report reveals a dangerous confidence gap: leaders think they’re covered, but the data says otherwise. “Healthcare IT is dangerously overconfident about email security,” reveals that 92% of healthcare IT leaders believe they’re prepared to prevent email breaches. They’re not. Most rely on ou...

Cover-Up Culture? 95% of Phishing Attacks Go Unreported in Healthcare, New Paubox Report Reveals

SAN FRANCISCO--(BUSINESS WIRE)--Your personal health information is under attack—and healthcare providers may not even know it. A new Paubox report exposes a shocking reality: 95% of phishing attacks in healthcare go unreported to security teams. Not flagged. Not investigated. Just ignored. Email is still the number one way cybercriminals get inside healthcare systems. Last year, 60% of healthcare organizations experienced an email-related security incident, yet most attacks go unreported. This...

Email Is Healthcare’s Biggest Security Risk–2025 Report Uncovers Alarming Gaps

SAN FRANCISCO,--(BUSINESS WIRE)--A new report analyzing 180 healthcare email breaches from January 1, 2024, to January 31, 2025 reveals widespread cybersecurity issues and escalating regulatory penalties. Paubox’s 2025 Healthcare Email Security Report highlights how email remains the leading attack vector, resulting in financial penalties, compromised patient data, and increased enforcement actions from regulators. Key Findings: 43.3% of breaches involved Microsoft 365. Barracuda, Proofpoint an...
Back to Newsroom