Skip to main content
Patient Protect circular logo mark in purple and white used for site navigationPatient Protect
Secure Care Research InstituteIndependently funded · Chicago, IL

Independent research into the economics, concentration, and consequences of healthcare data exposure.

We study why protected health information remains uniquely valuable to attackers, how technology is changing breach economics, and where systemic healthcare risk is concentrating. Every finding is published with its sources, methods, and limitations.

2

Foundational papers

1

Quarterly series

4

Published outputs

1,423

Breach dataset

60+

Sources

0

Outside funders

Last updated July 2026 · Q2 2026 Brief published July 2026

Key finding · Q2 2026

One vendor. Half the verified impact.

Finding extract

51.7%

Of verified Q2 2026 healthcare breach impact traced to a single AI-enabled vendor incident — Xsolis, whose utilization-management platform is deployed across approximately 600 hospital clients.

This is the vendor-concentration failure the Cyber-Economic Stack paper formalizes as the Transparency-Adjusted Risk Function at §3 — a single upstream compromise, cascaded across every downstream covered entity.

Q2 2026 brief →·TARF §3 →·Verified population impact, 10 disclosures

The research program

Three questions. One thesis.

Healthcare breaches are not isolated IT failures. They are the predictable result of valuable, immutable data; increasingly efficient attackers; concentrated vendor exposure; and delayed transparency. Each of the Institute's three research programs owns one part of that thesis.

Attackers operate in transparent, liquid data markets with near-perfect price discovery. Defenders operate blind. The asymmetry isn't an accident — it's the architecture.

The Cyber-Economic Stack · SSRN 5792382
Latest research · July 2026Vol. 1 · Issue 2 (Brief) · Q2 2026

One AI vendor held half the verified risk in Q2.

Ten independently verified disclosures. At least 2.7 million people affected. One AI-enabled utilization-management vendor accounted for 51.7% of the verified population impact. The upstream-concentration pattern established in Q1 persisted through a new AI-vendor channel.

10

Verified disclosures

2.7M+

Affected (floor)

51.7%

From one AI vendor

7/10

At specialty practices

Data, methods, and standards

What makes it a research institute.

Institutional authority is earned through documented practice — not through the volume of statistics on the screen. SCRI publishes its methodology, sources, known limitations, versioning behavior, and citation policy as standing artifacts. The same rules apply to every publication.

Full data & methods page

About the Institute

The Secure Care Research Institute.

The Secure Care Research Institute is the research program of Patient Protect LLC. It examines the economics, concentration, disclosure, and systemic consequences of healthcare data exposure.

Research is independently funded by Patient Protect and published with documented sources, methods, limitations, version histories, and citation guidance — whether or not findings support a commercial product decision.

Scale of exposure · 2024

276M

Americans with PHI exposed in 2024.

81% of the country — more than in any previous year. Detection latency averaged 93 days. The scale is the reason SCRI exists; the compilation and cost work is aimed at what the OCR portal cannot show on its own.

Source: HHS Office for Civil Rights Breach Reporting Tool, 2025.

From research to practice

Findings inform how we build.

SCRI's findings inform how Patient Protect approaches healthcare security, vendor risk, breach intelligence, and compliance infrastructure. Research conclusions are published with their methods and limitations whether or not they support a commercial product decision.

See how the research informs Patient Protect

Research-informed

  • Zero Trust architecture — sized to the vendor-cascade risk documented in the State of Compliance series.
  • Behavioral intrusion detection at the application layer — sized to the 93-day detection latency described in the Stack paper.
  • AI compliance copilot on Patient Protect-controlled inference infrastructure — sized to the AI amplification factor quantified in the Stack paper.
CC BY 4.0

License

SCRI research is openly licensed.

Datasets and citations are released under Creative Commons Attribution 4.0. Papers themselves are free to read, cite, and redistribute with attribution to the Secure Care Research Institute and Patient Protect LLC. No permission required for citation, quotation, or teaching use.

Full citation guidance →

Follow the research

Receive new SCRI papers, State of Compliance issues, dataset updates, and research briefings.

One list. Research only.

Corrections & Updates

Healthcare security data changes as investigations progress, vendors update systems, and laws and guidance evolve. If you see something outdated, incomplete, or incorrect — or have newer source material — we’d appreciate hearing from you.

Submit a correction →

Part of the HIPAA Foundation · Free tools & resources

See the full collection
ResearchFree to read · Proprietary

Cite the research

Research is free. The platform translates the findings into live monitoring — vendor concentration alerts, behavioral anomaly detection, breach-cost modeling.

Next in the sequence

Healthcare Breach Dataset

The methodology behind Patient Protect's breach-economic and threat-intelligence work. Free to read, free to cite.