In 2026, the average healthcare data breach costs $7.42 million and takes 279 days to detect. Billions are being spent on firewalls, encryption, and AI-powered threat detection. Almost nobody is asking what happens to the patient data sitting on retired laptops, imaging workstations, and decommissioned servers — and that gap is costing organizations everything.
This week, Boston Scientific — one of America’s largest medical device companies — disclosed a ransomware attack that disrupted its global operations, including its ability to process and ship orders across its cardiology, neurology, and oncology product lines. The investigation is still underway. The full impact is unknown.
It’s the latest in what has become the defining cybersecurity story of 2026: healthcare is under siege, and the attacks are getting smarter, faster, and more destructive.
But here’s what this week’s Boston Scientific breach, and the 281 other healthcare data compromises recorded in Q2 2026 alone, have in common with a problem that almost never makes the news: in most healthcare organizations, the cybersecurity conversation stops at the network perimeter. It almost never reaches the storage room full of retired laptops, the imaging workstation that was replaced last quarter, or the server that was decommissioned when the clinic moved to the cloud.
That’s where patient data goes to become someone else’s problem — quietly, undocumented, and completely unprotected.
The numbers are extraordinary — and getting worse
Healthcare has led every other US industry in data breach costs for fourteen consecutive years. Not occasionally. Every single year for more than a decade.
In 2025, healthcare recorded 770 HIPAA breaches — a record for any year since tracking began. The first quarter of 2026 saw a 29.4% increase in individuals affected compared to the same period in 2025. The Change Healthcare breach — still the largest healthcare data breach in American history — ultimately affected 192.7 million individuals and cost UnitedHealth an estimated $3.1 billion in direct cyberattack-related impacts.
Ransomware alone accounts for 48% of healthcare breaches in 2026 — also a record high. And AI has become the attacker’s most powerful new tool: between March 2025 and February 2026, one in four US data breaches was AI-enabled, up 56% from the prior year. Healthcare organizations are experiencing what HHS has explicitly linked to patient safety risks and direct care disruption — not just financial exposure.
When a hospital’s systems go offline because of ransomware, it’s not just an IT problem. It’s a patient care problem. Thirty-six percent of healthcare facilities reported an increase in medical complications directly attributable to ransomware attacks. This is a public health issue dressed as a cybersecurity one.
The cybersecurity budget problem that nobody talks about
Here’s a number that puts everything else in context: the average healthcare organization invests only 4 to 7 percent of its IT budget in cybersecurity. In financial services — the second most targeted industry — that figure runs two to three times higher. Healthcare is the most attacked sector in America, and one of the least funded for defense.
But even within those constrained cybersecurity budgets, there’s a structural blind spot that the industry almost universally shares. The money that does get spent goes toward network security — firewalls, endpoint detection, multi-factor authentication, identity management, threat monitoring. These are the right investments for stopping attackers from getting in.
Almost nothing goes toward what happens to data when it leaves the building on retired hardware. And patient data leaving the building is not a hypothetical threat. It is a documented, recurring cause of HIPAA breaches — and one that California’s Attorney General has already pursued through enforcement settlements tied specifically to improper disposal of Protected Health Information.
The hardware problem hiding in every healthcare organization
Think about the devices that move through a typical California healthcare organization in a single year. Nurse workstations. Physician laptops. Patient check-in tablets. Imaging workstations attached to MRI and CT equipment. Administrative desktops in billing and HR. Telehealth endpoints distributed across remote staff. Medical IoT devices with embedded storage.
Every one of those devices accumulates Protected Health Information during its operational life. Patient records. Insurance data. Social Security numbers. Prescription histories. Diagnostic images. Billing files. Clinical notes.
When those devices are replaced — which happens constantly in healthcare, where equipment cycles through quickly and COVID-era device deployments are now reaching end-of-life simultaneously — the question of what happens to that data is answered differently in every organization. And in far too many of them, the answer is: nobody really knows.
What 61% of healthcare breaches have in common with your storage room
Industry research consistently finds that 61% of healthcare data breach threats originate from negligent employees — not malicious external attackers. People who don’t know the rules. People who take a laptop home when they leave a job. People who hand a tablet to IT without a formal offboarding process. People who genuinely believe “deleting the files” makes a device safe to dispose of.
It doesn’t. Not by any standard that HIPAA, OCR, or a forensic investigator would accept.
A standard factory reset leaves recoverable data on most devices. A simple file deletion leaves the data completely intact — only the pointer to it is removed. Even a full format does not satisfy the NIST SP 800-88 Rev. 2 Purge requirement for solid-state drives, which are now standard across virtually every healthcare endpoint fleet.
The attacker who breached Change Healthcare needed stolen credentials and nine days of lateral movement to reach 192 million records. The attacker who buys a retired healthcare laptop on the secondary market needs only a free data recovery tool and an afternoon.
What 61% of healthcare breaches have in common with your storage room
The healthcare organizations in California that are ahead of this problem share a common operational discipline: they treat device retirement as an extension of their HIPAA compliance program — not as a facilities or IT logistics issue.
- Every device retirement triggers a documented offboarding process. Serial number, data classification, sanitization method, chain of custody, and Certificate of Destruction — before anything leaves the building. Not as a batch process at year-end. Every device, every time.
- SSD and NVMe devices get Purge-level sanitization — not overwrite. Standard overwrite does not satisfy NIST SP 800-88 Rev. 2 for solid-state drives. If your ITAD vendor is wiping SSDs the same way they wiped spinning drives in 2018, that is not a compliant program under either NIST or HIPAA’s technical safeguard requirements.
- Third-party vendor risk extends to the ITAD vendor. HIPAA Journal has identified supply chain breaches as one of 2026’s biggest healthcare cybersecurity challenges — a breach at one vendor can expose millions of records simultaneously. Your IT disposal partner has physical access to every device leaving your organization. Vet them with the same scrutiny you apply to any Business Associate.
- Medical imaging equipment and IoT devices are not exempt. PACS workstations, connected medical devices, and clinical tablets store PHI and require the same certified data destruction process as administrative laptops. A 99% rate of hospitals managing devices with known exploited vulnerabilities means the attack surface extends far beyond the devices IT teams typically track.
- Retired hardware is assessed for value before destruction. Healthcare IT refreshes are expensive. A certified ITAD program that assesses every retiring device for secondary market value — before applying certified data destruction — recovers real dollars that offset refresh costs. Compliance and value recovery are not competing priorities. They are the same process, done right.
The California angle that changes the urgency
California healthcare organizations carry a compliance obligation that goes beyond federal HIPAA requirements. The California Confidentiality of Medical Information Act imposes its own data protection requirements. California SB 1215, effective January 1, 2026, expanded e-waste coverage to battery-embedded devices — meaning most modern healthcare laptops, tablets, and handheld clinical devices now carry a California disposal obligation on top of HIPAA’s requirements. And the California Attorney General has already demonstrated willingness to pursue enforcement actions tied specifically to improper PHI disposal.
For California healthcare organizations, every retiring device now sits at the intersection of federal HIPAA requirements, state CMIA protections, and California e-waste law. Managing those three frameworks from one certified, documented ITAD program is not just best practice. It is the minimum defensible posture in 2026.
The conversation your security team and your facilities team need to have — together
Healthcare cybersecurity in 2026 is a board-level conversation. The costs are too high, the regulatory exposure too serious, and the patient safety implications too real for it to stay in the IT department. But that conversation has to include the full data lifecycle — not just the network perimeter.
Every device that has ever touched patient data is a cybersecurity asset until it is provably, documentably destroyed. The storage room full of retired equipment is not a facilities problem. It is an open HIPAA liability and a potential breach waiting for someone to pick up a box.
At Reboot Tech Recycling, we work with healthcare organizations across California — hospitals, clinics, imaging centers, and health systems — to build certified ITAD programs that treat device retirement as the final step in HIPAA compliance. Certified data destruction aligned to NIST SP 800-88 Rev. 2. Serial-level chain-of-custody documentation. Certificates of Destruction for every device. R2v3-certified material recovery. And value recovery assessment on every qualifying asset before anything is destroyed.
Healthcare has been the most breached industry in America for fourteen straight years. The organizations that break that pattern will be the ones that close every vulnerability — including the one sitting in the storage room down the hall.