Skip to content

Menu

LexBlog, Inc. logo
NetworkSub-MenuBrowse by SubjectBrowse by PublisherJoin the NetworkGet StartedSubscribeSupportContact
Search
Close

IBM Security Report Underscores Significant Cost of Healthcare Industry Data Breach  

By John W. Kaveney on August 2, 2023
Email this postTweet this postLike this postShare this post on LinkedIn
Data Breach text on hex code illustration
Data Breach text on hex code illustration

As recently reported by HealthITSecurity, IBM Security’s 2023 Cost of a Data Breach Report revealed that the average cost of a healthcare data breach was almost $11 million in 2022, an $800,000 increase from the prior year and a 53% increase from 2020. The report further revealed that the global average cost of a data breach across all sectors in 2023 was $4.45 million, a 15% increase over the past three years.

IBM’s report analyzed 553 organizations impacted by data breaches during the time period between March 2022 and March 2023. To calculate the cost of data breaches, researchers involved in preparing the report took detection isolation, notification, post-breach response, and lost business costs into account.

The researchers found that the healthcare sector experienced the highest average cost of any industry for the 13th consecutive year. Critical infrastructure faced average breach costs that were significantly higher than other industries, and U.S.-based organizations faced higher breach costs overall than any other country.  

The IBM report further included these key findings:

  • Approximately 5% of the breaches studied were the result of known vulnerabilities that had yet to be addressed;
  • Despite an increased emphasis on cybersecurity, benign third parties or threat actors themselves were more likely to be the ones to identify a breach versus the internal security teams;
  • A shorter breach lifecycle was associated with an overall reduction in total cost for the breach;
  • Nearly a quarter of all attacks that were analyzed involved ransomware;
  • It was observed that organizations that stored data in public cloud systems and multiple environments observed higher costs and longer breach lifecycles; and
  • Only 51% of organizations that suffered a breach reported increasing security investment following the breach.

The IBM report underscores the critical importance of security teams being vigilant and organizations making appropriate investments in cybersecurity. While cybersecurity initiatives can be costly, the average expense of a data breach more than justifies that cost. Moreover, ensuring that your organization has the requisite procedures in place to identify, investigate and remediate a potential data breach quickly and efficiently is critical to minimizing both harm and expense.

Organizations would be well advised to review their HIPAA/HITECH policies and procedures, their compliance programs, and their cybersecurity insurance to ensure they have taken all necessary steps to minimize these risks and prepared their organizations to promptly respond should an incident arise.

Photo of John W. Kaveney John W. Kaveney

Partner, Healthcare and Litigation

John provides legal guidance to healthcare sector clients on a broad variety of topics, including Medicare/Medicaid reimbursement issues, corporate compliance, data privacy and cybersecurity concerns, healthcare provider licensure and medical staffing concerns, involuntary commitment laws, and general healthcare regulatory…

Partner, Healthcare and Litigation

John provides legal guidance to healthcare sector clients on a broad variety of topics, including Medicare/Medicaid reimbursement issues, corporate compliance, data privacy and cybersecurity concerns, healthcare provider licensure and medical staffing concerns, involuntary commitment laws, and general healthcare regulatory support. He represents a diverse roster of healthcare entities, including for-profit and nonprofit hospitals and health systems, academic medical centers, individual physicians and physician groups, ambulatory surgery centers, ancillary service providers, medical billing companies, skilled nursing and rehabilitation facilities, behavioral health centers and pharmacies.

John advises on Medicaid reimbursement matters before the New Jersey Division of Medical Assistance and Health Services (DMAHS), which administers the state’s Medicaid programs, and handles Medicare reimbursement disputes, both in New Jersey and in numerous other states, before the federal Provider Reimbursement Review Board (PRRB).

In the area of corporate compliance, John supports clients on matters including the implementation of new, and the assessment and improvement of existing, compliance programs. He assists healthcare clients in navigating compliance audits, internal investigations, and governmental investigations related to compliance issues, including potential violations of the federal Stark Law, Anti-Kickback Statute (AKS), and Civil Monetary Penalties law (CMP). He further provides general guidance concerning compliance and regulatory matters under state and federal healthcare laws.

On issues related to information privacy and cybersecurity at the intersection of healthcare law, John assists providers with issues arising under the Health Insurance Portability and Accountability Act (HIPAA) and the Health Information Technology for Economic and Clinical Health Act (HITECH). This includes the implementation and assessment of privacy and security policies and procedures to ensure the proper protection and utilization of protected health information (PHI) both by healthcare providers and the business associates with which they contract. In addition, he represents healthcare clients in investigating, reporting, and remediating information breaches and the liability such breaches create under various information privacy and security laws.

John also counsels healthcare providers with professional licensure issues and advises hospitals and health systems regarding their medical staff bylaws and corresponding policies and procedures, as well as assisting with internal investigations of medical staff members and the corresponding disciplinary process. He further provides legal guidance related to New Jersey’s involuntary commitment laws, and provides representation in civil litigation.

John serves as Editor-In-Chief of Healthcare Perspectives, Greenbaum’s blog covering issues of interest to the healthcare industry.

Results may vary depending on your particular facts and legal circumstances.

Contact information:

jkaveney@greenbaumlaw.com | 973.577.1796 | vCard | LinkedIn

For more information visit the Greenbaum, Rowe, Smith & Davis LLP website.

Read more about John W. KaveneyEmail
Show more Show less
  • Posted in:
    Health Care and Life Sciences
  • Blog:
    Healthcare Perspectives
  • Organization:
    Greenbaum, Rowe, Smith & Davis LLP
  • Article: View Original Source

Call us at 1-800-913-0988 or email sales@lexblog.com.

Facebook LinkedIn Twitter RSS
The Library at LexBlog
  • About LexBlog
  • The Field We Built
  • Library at LexBlog
  • Our Beliefs
  • Our Team
  • Contact LexBlog
  • Disclaimer
  • Editorial Policy
  • Terms of Service
  • Get Started
  • Publishing Solutions
  • Compass
  • Submit a Request
  • Support Center
  • System Status
Copyright © 2026, LexBlog, Inc. All Rights Reserved.
Law blog design & platform by LexBlog LexBlog Logo