Healthcare Email Breaches Surge: 43% Tied to Microsoft 365 Misconfigurations

A new analysis of 180 healthcare email breaches between January 1, 2024, and January 31, 2025, reveals widespread cybersecurity vulnerabilities and mounting regulatory penalties. The 2025 Healthcare Email Security Report from Paubox confirms that email remains the top attack vector, exposing patient data, driving up breach costs, and attracting heightened attention from regulators.

Key Findings:

  • 43.3% of breaches involved Microsoft 365, primarily due to misconfigured email security settings.
  • Ransomware attacks on healthcare increased 264% since 2018, with email as the leading delivery method.
  • Only 1.1% of reviewed organizations had a low-risk email security posture.
  • HIPAA violations led to over $9 million in fines, including a $9.76 million settlement with Solara Medical Supplies.
  • The average cost per healthcare email breach is now estimated at $9.8 million, according to IBM.

Email Security Remains a Critical Weakness

Even with a 50% rise in healthcare cybersecurity spending since 2018, many organizations still lack essential email protections. According to the report, 98.9% of breached entities were missing MTA-STS safeguards, leaving communications open to interception. Moreover, 37.2% of Microsoft 365 users had DMARC policies set to ‘monitor-only,’ failing to block phishing attacks.

OCR Director Melanie Fontes Rainer emphasized the urgency: “HIPAA-regulated entities need to be proactive in ensuring their compliance with the HIPAA Rules, and not wait for OCR to reveal long-standing HIPAA deficiencies.” The data suggests that many organizations only discover these lapses after experiencing a breach.

Stricter Regulatory Enforcement on the Rise

The HHS Office for Civil Rights (OCR) has ramped up HIPAA enforcement, levying record fines against organizations failing to implement adequate email security and conduct proper risk assessments. Notable recent cases include:

  • Solara Medical Supplies: $9.76 million settlement after a phishing incident affected 114,000 patients.
  • L.A. Care: $1.3 million fine due to systemic email security gaps.

Access the Full Report

The 2025 Healthcare Email Security Report offers in-depth breach analysis, industry benchmarks, and practical recommendations to help IT and compliance teams strengthen their security posture. Request your early access to the full report before it becomes publicly available.

For expert commentary or interviews, contact Dawn Halpin at press@paubox.com or call 415-795-7396.