First, earlier this summer, IBM released its 21st Annual Cost of a Data Breach Report; the AI Tipping Point (the “IBM Report”). The IBM Report highlights how artificial intelligence is affecting cybersecurity: “AI-driven attacks increased 56 percent over last year’s study. The financial consequences were not minor. AI-driven attacks added an average of USD 1 million per breach as AI tools allow attackers to increase their velocity and scale. That speed is reshaping breach economics—and not in a good way.”
The IBM Report studied 602 organizations impacted by data breaches from March 2025 through February 2026.
Among several of the key findings from the IBM Report:
- the average breach cost in the United States was $11.5 million dollars
- the global average cost of a data breach was almost $5 million dollars
- for the 13th consecutive year, the healthcare industry recorded the highest average breach cost ($6.64 million) among all industries
- in most breaches (30 percent), the breached data was stored on-premises
- breached data stored across multiple locations took the longest to identify and contain (256 days)
- for the fourth year in a row, phishing was the top attack vector into breached organizations
- malicious or criminal attacks accounted for 55 percent of all data breaches, up almost 8 percent from last year’s report
- more than one in four organizations experienced a malicious, AI-driven attack—a 56 percent increase over last year’s report
- the financial consequences of AI-driven attacks added almost $1 million per breach
- among breached organizations this year, 39 percent reported their systems were hit by ransomware. This finding continues a four-year upward trend
- among breached organizations, 53 percent didn’t encrypt sensitive data at rest and in motion at the time of the breach. Another 10 percent of organizations said they weren’t sure if the data was encrypted.
To help prevent, mitigate and reduce the costs associated with a data breach, the IBM Report makes four recommendations:
- operate security at the new speed of attack
- shift identity security to continuous, runtime verification
- strengthen AI control through AI sovereignty, and
- prepare for post-quantum security risks
The second healthcare cybersecurity development relates to the Federal Trade Commission’s (“FTC”) September 9, 2026, announcement that it is rescinding its 2021 policy statement that extended application of the Health Breach Notification Rule to health apps and connected devices outside the purview of HIPAA. See the FTC press release. As a result of this FTC announcement, developers of health apps and connected devices are no longer considered ‘health care providers’. In addition, the FTC will no longer include ordinary wellness apps to be within HIPAA’s purview and unauthorized data sharing on its own beyond a cyber security incident will not trigger breach notification protocols. Importantly, the FTC decision does not obviate state-level data laws, such as the Washington State My Health My Data Act, that may be in effect and covering these forms of devices.
Finally, on September 17, 2026, the U.S. Department of Health and Human Services (“HHS”) Office for Civil Rights (“OCR”) announced a settlement with Ambry Genetics Corporation (“Ambry”) concerning potential violations of the Health Insurance Portability and Accountability Act of 1996 (HIPAA) Security Rule. As part of the settlement, Ambry agreed to pay $700,000 and enter into a two-year corrective action plan with OCR. In January of 2020, Ambry discovered that an employee’s email account was compromised by a phishing attack. The protected health information (PHI) of 225,370 individuals was potentially exfiltrated by the threat actor.
Ambry notified OCR of the incident in March 2020. The OCR press release announcing the settlement noted that OCR’s investigation revealed that Ambry had potentially violated provisions of the HIPAA Security Rule, including:
- Failing to conduct an accurate and thorough risk analysis of the potential risks and vulnerabilities to the electronic protected health information (ePHI) held by Ambry;
- Failing to implement procedures for terminating access to ePHI when the employment of or other arrangement with a workforce member ended or access was no longer appropriate; and
- Failing to assign a unique name and/or number for identifying and tracking user identity in electronic systems containing ePHI.
A copy of the Ambry OCR Resolution Agreement and Corrective Action Plan is here.
HIPAA continues to be in the news from the private sector (the IBM Report) and from federal government activity (the FTC policy recission, and Ambry OCR settlement), and many state governments are focusing time and energy on data accountability.
Every entity in the health care delivery sector – covered entities and business associates – must stay mindful of ensuring HIPAA Privacy Rule compliance and having HIPAA Security Rule protections in effect. Threat actors continue to target health care providers and their business allies. A security incident can be incredibly disruptive to an organization and lead to significant compliance remediation and economic consequences.
Saul Ewing attorneys assist HIPAA-covered entities and business associates with HIPAA compliance and with incident response activities. For questions about this alert, please contact Bruce Armon, Head, Health Care Practice, and Evan Foster, Head, Cybersecurity and Privacy Practice.