Healthcare organizations continue to experience email-related data breaches, and many of them are tied to the same basic security gaps that experts have warned about for years. A new analysis by email security firm Paubox found that the majority of healthcare organizations reporting email breaches to federal regulators in 2025 lacked fundamental email security controls designed to prevent spoofing, impersonation, and unauthorized message interception.
The findings come from the 2026 Healthcare Email Security Report, which analyzed 170 email-related breaches reported to the Department of Health and Human Services Office for Civil Rights during 2025.
The big picture: At first glance, the number of incidents declined slightly from 180 breaches reported in 2024 to 170 in 2025. But according to the report, the underlying causes of many breaches remain unchanged. The analysis found that breached organizations consistently lacked baseline security configurations that are widely recommended by regulators and cybersecurity experts.
Key findings include:
- 74% of breached organizations lacked effective DMARC enforcement, which prevents spoofed emails from appearing legitimate.
- More than half had permissive or missing SPF records, allowing unauthorized servers to send messages that appear to come from the organization.
- None of the breached organizations enforced MTA-STS, a protocol that requires encrypted connections between email servers.
Without these protections, attackers can send spoofed emails, harvest credentials, or intercept messages that may contain sensitive information.
Email remains a primary attack vector: Most incidents follow familiar patterns, including phishing attacks, compromised employee credentials, spoofed messages, or improper handling of sensitive information sent through email.
The report notes that these attack paths are well understood and heavily documented. The issue is not new threats, but long-standing configuration weaknesses that remain unaddressed in many environments.
The researchers also found that 41% of breached organizations fell into a high-risk category based on their email security configuration, up from 31% the year before.
Platform exposure and configuration discipline: The report also highlights the widespread use of cloud-based email platforms.
More than half of breached organizations relied on Microsoft 365 as their primary email platform, reflecting its dominant role in healthcare communications. However, the report emphasizes that the presence of security tools or enterprise platforms does not guarantee protection. Many breaches occurred in environments where advanced platforms were deployed but foundational security controls were either incomplete or improperly configured.
The bottom line: Regulators continue to stress the importance of safeguarding sensitive healthcare information.
“Patients must be able to trust that sensitive health information in their files is protected to preserve their trust in the patient-doctor relationship and ensure they get the care they need,” said Melanie Fontes Rainer, director of the HHS Office for Civil Rights, in a published report.
The next wave of breaches is unlikely to come from new or sophisticated attacks, according to the report. Instead, it will likely come from the same long-standing gaps in email configuration that organizations have had years to address.




