2025 Healthcare Data Breach Report: Trends and Insights

The 2025 Velocity Healthcare Data Breach Report

Includes Incidents Affecting 500 or More Records Containing Protected Health Information (PHI)

Explore a comprehensive analysis of breach patterns, financial impacts, and emerging cybersecurity risks within the healthcare sector.

2025 Healthcare Data Breaches Report Cover Page

This report shares healthcare breach data to provide context and insight that may assist cybersecurity leaders in ongoing decision-making efforts.

ACCESS THE REPORT

Why this report matters

Healthcare remains one of the most targeted industries, yet the drivers behind breaches continue to evolve rapidly. This report provides clear, data-backed insights that help security leaders understand current trends and make informed decisions with confidence.

What you’ll learn

Built on real data

Every insight is powered by Stern Security’s Healthcare Data Breaches platform bringing clarity to complex data.

Who it’s for

CISOs, CIOs, compliance teams, MSPs, security analysts, and any leader who needs clean, actionable intelligence to guide cybersecurity decisions.

After you submit

You’ll get instant access to the full 2025 Healthcare Data Breach Trends & Insights Report.

Key Report Highlights

Discover the essential insights and trends that are shaping the future of healthcare cybersecurity. Our report offers a comprehensive analysis of breach patterns, financial impacts, and emerging risks.

Icon of a gear, pencil and paper.

In-Depth Analysis

Explore detailed data on breach trends, PHI exposure, and third-party risks, curated from national sources over the past decade.

icon of a check mark

Expert Recommendations

Benefit from expert advice on addressing top vulnerabilities and strengthening resilience against real-world attacks. Stern Security has extensive experience in the healthcare industry, is the winner of the NC Tech Cyber Award, is SOC 2 Type 2 certified, and has been featured on numerous News platforms.

icon of a check mark

Actionable Insights

Gain practical steps to enhance your organization’s security posture and make informed decisions to mitigate risks effectively.

Unlock Critical Insights Today!

Stern Security Successfully Completes SOC 2 Type II Audit 

Stern Security Successfully Completes SOC 2 Type II Audit 

FOR IMMEDIATE RELEASE 

Stern Security Successfully Completes SOC 2 Type II Audit 

Raleigh, NC, July 18th,  2025Stern Security, a cybersecurity firm and creator of Velocity for cyber risk quantification, today announced the successful completion of its SOC 2 Type II examination for the Velocity platform. 

The attestation confirms that Stern Security has implemented and maintained effective controls aligned with the American Institute of Certified Public Accountants (AICPA) Trust Services Criteria for Security. The examination, conducted by an independent auditing firm, evaluated the design and operational effectiveness of Stern Security’s systems and processes.

Our clients trust us with their cybersecurity challenges, and this attestation shows our commitment to aligning with globally recognized security standards,” said Jon Sternstein, CEO of Stern Security.

SOC 2 is a widely recognized standard for service organizations that handle sensitive customer data. Achieving SOC 2 Type II compliance demonstrates Stern Security’s ongoing commitment to safeguarding client data and maintaining the highest standards of operational security.

About Stern Security

Stern Security is a cybersecurity firm that empowers organizations to quantify risk, strengthen defenses, and make data-driven decisions. Known for its proprietary Velocity platform, Stern Security helps clients across industries—including healthcare, government, and education—identify vulnerabilities, reduce risks, and communicate internal and third-party security posture with clarity. With a focus on both technical excellence and strategic insight, Stern Security turns complex cybersecurity challenges into actionable outcomes.

For more information, visit www.sternsecurity.com.

CBS17 Interview: Cyber Workforce Development

CBS17 Interview: Cyber Workforce Development

There is a growing need for cybersecurity expertise to secure businesses of all sizes. To meet demand, colleges in North Carolina are coming together to create programs to train students and give experience in the field helping businesses. Through the Carolina Cyber Network, schools including Wake Technical Community College are pairing students with local businesses to offer cybersecurity help. This is a win-win for both sides as the students get real-world experience and the businesses get inexpensive help.

On July 22nd, 2025, CBS17 went to Wake Tech to hear graduates of Wake Tech’s cybersecurity SENTINEL program discuss how they help local businesses. The students in this program are using the Velocity platform, by Stern Security to perform risk assessments for these organizations. CBS17 interviewed Stern Security’s Founder & CEO, Jon Sternstein, to learn the importance of these types of cyber workforce development programs.

The full interview can be seen here: https://www.cbs17.com/news/local-news/wake-county-news/wake-tech-cybersecurity-students-helping-small-businesses/

Case Study: Securing Epic Community Connect with Stern Security’s Velocity Platform

Case Study: Securing Epic Community Connect with Stern Security’s Velocity Platform

Background

Epic Systems is the leading Electronic Health Record (EHR) platform used by healthcare organizations across the country. While large hospital systems can afford to implement Epic directly, smaller physician practices typically gain access through Epic Community Connect. This program allows large health systems to extend their Epic environment to affiliated practices, enabling patient data sharing and streamlined workflows.

However, this integration comes with strict requirements: Epic mandates nearly 20 cybersecurity controls that must be met by every participating practice.

The Challenge

Meeting Epic’s cybersecurity standards is no small feat—especially for smaller practices. These physician offices:

  • Often lack in-house cybersecurity or even basic IT expertise.
  • Are not owned by the sponsoring hospital system, so they can’t rely on the hospital’s cybersecurity resources.
  • Must attest to meeting Epic’s cybersecurity requirements on a quarterly basis—a demanding and continuous burden.

This combination of limited resources and high expectations creates a major security and compliance gap.

The Solution: Velocity by Stern Security

A major U.S. healthcare system—already using Stern Security’s Velocity platform for third-party risk management (TPRM), faced this very challenge. With over 70 Epic Community Connect practices, the organization needed a fast, scalable, and effective way to ensure compliance across all affiliates.

The healthcare system turned to Stern Security and asked: Can Velocity handle this?

The answer was a resounding yes.

Despite tight deadlines, Stern Security:

  • Built a tailored Epic Community Connect cybersecurity assessment module within Velocity.
  • Translated technical requirements into clear, non-technical language that practice administrators could easily understand.
  • Developed automated quarterly reminders to simplify ongoing compliance.
  • Identified and validated contacts for each practice.
  • Completed 70+ assessments across the entire physician network—on time and within scope.

The Results

In just two months, the entire process was up and running. Every assessment was successfully executed using the Velocity platform. The healthcare system now has a repeatable, scalable process for Epic Community Connect cybersecurity compliance—with evidence-based results they can trust.

Why It Matters

Healthcare organizations participating in Epic Community Connect are required to meet Epic’s cybersecurity standards. Without the right tools, this can be a costly and error-prone process.

Velocity by Stern Security is purpose-built to simplify these complex assessments:

  • Streamline compliance with clear, understandable requirements.
  • Reduce risk by validating evidence and automating processes.
  • Empower providers to focus on what they do best—delivering outstanding patient care.

Ready to Simplify Your Epic Community Connect Assessments?

Let Velocity do the heavy lifting.

Whether you manage 5 or 500 connected practices, Stern Security’s Velocity platform can help you maintain compliance, reduce risk, and protect patient data—all with less effort.

Contact us today to learn how Stern Security can help your organization streamline Epic Community Connect cybersecurity compliance.

Presentation: Quantifying Risk in the Age of AI Threats

Presentation: Quantifying Risk in the Age of AI Threats

Background

On July 10th, 2025, Stern Security‘s Founder & CEO, Jon Sternstein spoke to financial organizations at the Carolinas Credit Union League event. Jon Sternstein discussed the essentials of quantifying cyber risk in the age of AI threats. The world is rapidly evolving and there are numerous way to conduct cyber risk quantification and business impact analysis activities to speak the language of the business.

Presentation Abstract

“Love, Lies, and Ledger Sheets: Quantifying Cyber Risk in the Age of AI Threats” by Jon Sternstein

In a world where artificial intelligence can mimic your voice and craft malware that slips past traditional defenses, cybersecurity is no longer about counting vulnerabilities—it’s about understanding business risk. Join Stern Security’s Founder & CEO, Jon Sternstein, as he unveils the evolving threat landscape through real-world stories (starting with a romance you won’t forget), and makes the case for why credit unions must shift from legacy reporting to actionable cyber risk quantification. Plus, a light look at global tensions and what they could mean for your cyber defenses.”

Conclusion

The presentation went into details about modern threats (AI deception threats, romance scams, gift card scams, wire transfer attacks, hacking incidents) in addition to proven solutions. Jon discussed various methodologies to quantify risk from simple to advanced options. Stern Security’s Velocity platform automates the cyber quantification needed to translate the security risk into business terminology and quickly help make security teams successful. The presentation include engaging true stories, laughs, “wow” factors, and audience participation cyber challenges. The credit unions left the event inspired and armed with the tools they need to increase their security posture to the next level.