Over 90% of health and human service organizations experienced a cyberattack in the past 12 months. The average number of cyberattacks within that 12-month period was 43, according to a new survey, 2025 Poneman Health Care Cybersecurity Survey.

These cyberattacks are expensive. The cost for the most expensive types of cyberattack was $3.9 million. A cost breakdown shows that disruption to operations was $1.4 million, lost productivity was $1.2 million, damage or theft of IT assets or infrastructure cost nearly $625,000, and remediation and investigations cost $507,000.

But beyond the cost, nearly three in four U.S. health care organizations that experienced a cyberattack in the past year saw disruption to consumer services. Ninety-three percent of health care entities