Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
healthcare-sector-threateducation-sector-threatbreach-disclosure-notificationransomware-group-operation

2025 Data Breach Trends in Healthcare and Education Sectors

Updated 2mo agoFirst seen Feb 16, 20264 sources

Reporting on 2025 breach activity indicates incident volumes largely plateaued while impact varied by sector. In U.S. healthcare, HHS OCR portal data shows large breaches (affecting 500+ individuals) remained in the ~700–750 per year range, with an apparent 4.3% year-over-year decline in 2025 that may change as late reports are added; a late-2025 federal government shutdown is cited as a factor that could delay postings and inflate later totals. Despite relatively stable breach counts, the number of affected individuals dropped sharply year over year, from a record 289,162,330 in 2024 to at least 61,556,256 in 2025 (a reported 78% reduction).

In education, a Comparitech roundup cited in sector reporting attributes 251 claimed ransomware attacks against schools and universities globally in 2025 (vs. 247 in 2024), with 94 confirmed by victim organizations; while attack counts were steady, known exposed records across confirmed incidents rose to 3.9 million (up 27% from 3.1 million). Drivers highlighted include third-party software vulnerabilities and a small number of large higher-education breaches. Separately, general guidance for healthcare organizations reiterates HIPAA Breach Notification Rule obligations (45 CFR §§ 164.400–414), including notification timelines (no later than 60 days after discovery) and escalation requirements for larger incidents (e.g., 500+ affected individuals).

Share:
2025 Data Breach Trends in Healthcare and Education Sectors
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

10 events from the most recent confirmed update back to the earliest known activity.

10 EVENTS
Dec 31, 20256mo ago

OCR resolved 21 HIPAA enforcement cases in 2025

During 2025, HHS OCR resolved 21 HIPAA enforcement actions and imposed $8,330,066 in financial penalties. The report said failures in risk analysis were the most commonly cited compliance issue.

Aflac disclosed the largest healthcare hacking incident of 2025

The 2025 healthcare breach report identified a hacking incident at Aflac as the largest healthcare data breach of the year. It was highlighted as the biggest single event among 2025 healthcare disclosures.

Large healthcare breach count fell 4.3% year over year in 2025

The number of large U.S. healthcare data breaches reported to HHS OCR declined by 4.3% in 2025 compared with 2024. The report cautioned that the final 2025 total may still rise because of late reporting and a 43-day federal government shutdown that paused portal updates.

Healthcare breaches affecting 61.6 million people were reported for 2025

At least 61,556,256 individuals were affected by U.S. healthcare data breaches involving 500 or more people reported to HHS OCR in 2025. This represented a 78.7% drop from 2024, largely because there were fewer mega breaches.

New York schools reported 662 data incidents in 2025

New York State's Education Department reported 662 school data incidents in 2025, up 72% from 384 in 2024. The annual report said Long Island schools reported 44 incidents, and cited human error, third-party unauthorized access, and external breaches including phishing, ransomware, and malware as key causes.

NYS school data incidents rose 72% in 2025, with 44 reported on Long Island - DataBreaches.Net

Confirmed 2025 school breaches exposed 3.9 million records

Confirmed ransomware incidents affecting educational institutions in 2025 exposed 3.9 million records, up 27% from 2024. The increase was linked partly to third-party software vulnerabilities and several unusually large higher-education breaches.

Ransomware gangs claimed 251 attacks on schools in 2025

In 2025, ransomware groups claimed 251 attacks on educational institutions, a slight increase from 2024. Of those 2025 claims, 94 were confirmed by the targeted schools or universities.

Oct 31, 20258mo ago

Quorum Cyber reported 63% rise in global higher-education cyber incidents

Quorum Cyber's 2026 Global Cyber Risk Outlook for Higher Education reported 425 cyber incidents affecting educational institutions across 67 countries between November 2024 and October 2025, up from 260 in the prior 12-month period. The report said data breaches rose 73% and hacktivist activity increased 75%, with universities targeted by nation-state actors and ransomware groups including FunkSec, Cl0p, and INC.

Global education sector attacks surge 63% | brief | SC Media
Dec 31, 20241y ago

Healthcare sector recorded 18 mega breaches in 2024

The 2025 healthcare breach report uses 2024 as a comparison year, noting 18 healthcare breaches affecting more than 1 million individuals occurred in 2024. These mega breaches heavily drove the much higher 2024 victim total compared with 2025.

Educational institutions saw 247 ransomware claims in 2024

Comparitech's education ransomware roundup reported that ransomware gangs claimed 247 attacks on schools and universities in 2024. Confirmed 2024 incidents exposed about 3.1 million records.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

55 LINKEDOpen in app
Organizations
50 linked
Quorum CyberInfosecurity MagazineQueen Mary University of LondonUSR HoldingsVirtual Private Network SolutionsMcLaren Health CareDaVitaComparitechCovewareMeta PlatformsIdentity Theft Resource CenterRadiology Associates of RichmondAnne Arundel DermatologyGovTechAflacFrederick HealthBlue Shield of CaliforniaYale New Haven Health SystemEpisourceDecisely Insurance Services, LLCAscension HealthGoshen Medical CenterConcentra Inc.Northwest RadiologistsGoogleSoutheast Series of Lockton Companies, LLCUnited Seating and Mobility, LLCKelly & Associates Insurance Group, Inc.Medusind Inc.PIH HealthBayCare Health SystemSolara Medical SuppliesHealth Fitness CorporationServiceaide, Inc.ComstarVision Upright MRIElgon Information SystemsDeer Oaks – The Behavioral Health SolutionBlack FogWarby ParkerComprehensive Neurology, PCSyracuse ASCCadia Healthcare FacilitiesNortheast Surgical GroupOnsite MammographyBST & Co. CPAs, LLPNortheast Radiology, P.C.Community Health SystemsNewsdayOrthopedicsNY
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.