In October 2020, patients of Vastaamo, a psychotherapy provider serving roughly 40,000 people in Finland, began receiving emails demanding bitcoin. The alternative was public release of their therapy notes. Attackers had stolen the clinic's full database two years earlier, including care plans, clinical notes, and the national identification numbers tied to them, and Vastaamo had known about the exposure and said nothing. Finland's president called the breach relentlessly cruel. He was not exaggerating. For a subset of those patients, someone was now holding a record of their trauma, addiction, or suicidal ideation over them, in exactly the place that record was supposed to stay private.
This is the human cost of a breach. It belongs in a category most breach cost models leave out entirely.
When healthcare organizations weigh security investment, the math is usually anchored to two numbers: the cost of an OCR settlement and the cost of breach notification, credit monitoring, and legal defense. Those numbers get a board's attention, and they measure the wrong thing. The real cost of a healthcare breach falls into two categories that rarely appear on a compliance dashboard. Direct costs are the concrete harm done to a patient's health, finances, and physical safety. Opportunity costs are the care that never happens because trust has already been damaged. Both are real. Neither shows up in a regulatory fine.
What Direct Costs Look Like For A Patient
In 2006, someone stole Anndorie Sachs's driver's license from her car in Utah. Months later, a woman claiming to be Sachs walked into a hospital in labor, gave birth to a baby who tested positive for drugs, and disappeared. Child Protective Services called Sachs asking why she had abandoned her newborn. She had not given birth. Her identity, not her wallet, had been stolen, and it took a home visit from caseworkers to sort out that she was not the mother on the chart. That is medical identity theft working as designed: someone else's diagnoses, allergies, blood type, or drug history attached to a real patient's record. A mismatched blood type or a missing allergy flag in a corrupted chart is not a financial abstraction. It can kill someone during a transfusion or a routine prescription. Ponemon Institute research conducted for the Medical Identity Fraud Alliance put the average out-of-pocket cost to a victim at $13,450, mostly legal fees and payments to providers and insurers for care the victim never received, and found that victims spent an average of more than 200 hours working toward a resolution. Only one in ten considered that resolution satisfactory.
Ransomware does more direct damage to more patients, faster. When Change Healthcare was hit in February 2024, the attack did not just take down a vendor's servers. Change Healthcare processes roughly 15 billion healthcare transactions a year and touches records for about one in three patients in the country, according to the Department of Health and Human Services. Pharmacies across the country could not process insurance claims, and patients were told to wait or pay cash for medications they needed that day. Hospitals and physician practices went weeks without being able to bill, and the resulting cash crunch outlasted the outage itself. By January 2025, reports put the number of people whose data was exposed at more than 190 million, roughly six in ten Americans. Four years earlier, a ransomware attack on the University of Vermont Health Network showed what this disruption looks like inside the hospital rather than at the pharmacy counter. Chemotherapy appointments were delayed, mammograms and breast ultrasounds were suspended, and biopsies stopped while the network worked to restore access to patient records and scheduling systems. Cancer does not pause for an incident response timeline.
Vastaamo remains the sharpest documented case of a third category: extortion built specifically on the most sensitive health data a person has. Ransomware groups have taken note. Threatening to publish a psychiatric history, a substance use record, or a reproductive health record is a more effective lever than threatening to publish a credit card number, because the shame is the payload.
Genetic data adds a fourth dimension none of these other categories share: it cannot be reissued. When 23andMe disclosed in late 2023 that a credential stuffing attack had exposed data tied to 6.9 million accounts, including ancestry profiles, health predisposition data, and family relationship information pulled through its DNA Relatives feature, the company reset passwords and made two-factor authentication mandatory. Those fixes protect the next password. They do nothing for the DNA already exposed. A stolen Social Security number can be replaced. A password can be rotated. A genome cannot, and the exposure follows every biological relative of that person whether or not they ever used the service.
The Opportunity Costs No One Prices In
The costs above are visible because someone can put a number on them. The costs below are just as real and far harder to see, because they show up as care that quietly stops happening. A 2025 study of twelve California hospitals over three years found that hospital visits dropped by an average of 4.65 percent in the months following a publicized data breach, with the effect strongest after insider-caused breaches and larger record counts. Healthier patients with other care options skipped visits at higher rates. Patients managing chronic conditions, who had less room to walk away, did not.
Some patients stay in the system and change what they tell it. A 2020 study out of Ohio State published in the Journal of General Internal Medicine found that patients concerned about the security of electronic health records were three times more likely to withhold information from their physicians than patients without those concerns. That is not a privacy win. A physician making a diagnosis or a prescribing decision without a complete history of mental health treatment, substance use, or reproductive care is working from a corrupted chart of a different kind, one the patient corrupted on purpose because trust had already broken down.
Trust, once damaged, does not stay contained to the organization that lost it. In a 2015 TransUnion survey of more than 1,200 patients, 65 percent said they would avoid a provider after a breach, and more than half of recent hospital patients said they would consider switching providers entirely, a figure that rose to 73 percent among patients under 35. Every provider switch is a continuity of care gap. A new physician starts without the longitudinal record that would have caught the drug interaction or recognized the pattern the last provider already knew. That erosion does not stay contained to the breached organization either. A patient who stops trusting one health system's data practices tends to grow more guarded with the next one too, which is a cost the entire industry absorbs, not just the company named in the breach notification.
None of this shows up on a HIPAA risk assessment or an OCR resolution agreement, which measure only whether an organization followed a process, not whether a patient's chart is still trustworthy, whether a cancer patient's treatment stayed on schedule, or whether the next patient walking into a therapist's office believes the record of what she says will stay hers. Security budgets built only against fine exposure and notification costs are underpricing the actual risk, sometimes by an order of magnitude, and patients pay the gap, not shareholders.
I have spent two decades building security programs inside healthcare organizations, and boardroom conversations almost always start with regulatory exposure. That is a reasonable place to start, not to stop. The number that should worry an executive team is not what OCR could fine them. It is what happens to the patient whose therapy notes, chemotherapy schedule, or genetic profile lives in the system that board is deciding how much to secure. That is the question we bring into every risk assessment at Bowen & Company.