IBM’s Cost of a Data Breach Report 2026, released July 29, confirmed CHARGE’s July warning that 2026 was shaping up to be one of the “most disastrous for healthcare cybersecurity in recent memory." For the thirteenth year running, the healthcare industry recorded the highest average cyber breach cost – USD 6.64 million – among all other industries. Most saliently, the newest risk surface threatening health organizations is the least-controlled: shadow AI.
Shadow AI
IBM reported that security incidents involving shadow AI more than doubled from 20% to 43%, threatening data loss, compromise and disrupted operations. Those breaches are especially concerning in healthcare settings: according to Wolters Kluwer, roughly 58% of healthcare professionals have confronted use of unapproved consumer-grade AI tools at least once at work, with at least 20% of health professionals using them; chatbot misuse topped ECRI’s annual list of health technology hazards for 2026.
As CHARGE reported in July, the risk of shadow AI is bi-directional, introducing error artifacts and faulty information into health consultations and workflows from both physicians and patients. Now, IBM’s reporting explicitly identifies shadow AI usage as a cyber breach surface. Crucially, while the Cost of a Data Breach Report quantifies the inflated financial risk of cyber breaches in healthcare, it sidesteps healthcares’ key risk differentiator: cyberattacks correlate to a 20% increase in in-patient mortality rates.
“Governance failures, not model risk."
More generally, IBM reported that 1 in 4 malicious data breaches are now AI-enabled; that confirms CHARGE July analysis of AI-breaches which threatened 147 million patient records and 200 health organizations at Abbott Laboratories, AdaptHealth and Craneware. Also in July, a Health-ISAC report revealed that “only 22 percent of surveyed CISOs rate themselves at the top two maturity levels for restoring operations” after an incident, and that “only 6 to 10 percent of” health “programs reach Level 5” maturity in any cyber function. Restoring operations are especially critical as in-patient mortality rates increase due to delayed care.
Those undeveloped governance and regulatory structures led IBM to identify AI breaches primarily as API compromises, cloud misconfigurations, or lethargic and archaic CISO response structures. At Abbott Laboratories and AdaptHealth, for example, threat actors targeted “weak points” in the security environments of misconfigured third party portals.
As such, IBM characterized AI risks as “governance failures, not model risk.” That revelation is cause for both concern and optimism. AI implementation within clinical workflows and at point-of-care promises to improve patient outcomes and alleviate provider burden – but those same workflows are threatened by moribund governance frameworks unable to properly map deployed AI or monitor shadow AI. Robust, prescient, and efficient governance infrastructure can thus deliver needed AI solutions and neuter cyber threats. It is healthcare’s foremost imperative to build it.
References
[1] IBM Report: https://www-api.ibm.com/adobe/assets/urn:aaid:aem:21111142-1251-4369-86fb-57b82f5bb108/original/as/Cost-of-a-Data-Breach-Report-2026.pdf
[2] Wolters Kluwer Report: https://www.wolterskluwer.com/en/news/wolters-kluwer-survey-finds-broad-presence-of-unsanctioned-ai-tools-in-hospitals-and-health-systems
[3] ECRI Report: https://home.ecri.org/blogs/ecri-news/misuse-of-ai-chatbots-tops-annual-list-of-health-technology-hazards



