The Cyber-Economic Stack
How AI turns healthcare data into a financialized attack asset.
A three-layer analytical framework linking dark-market economics, AI amplification, and healthcare's transparency deficit — unified in a single Transparency-Adjusted Risk Function (TARF) that quantifies systemic exploitability. Analysis of 1,423 healthcare breaches (2020–2025) shows halving disclosure latency could reduce sector-wide exploit ROI by 25–35%.
$280–310
Per-record PHI dark-market price
8–10×
PHI premium over credit card data
93 days
Avg. healthcare detection latency
1,423
Breach dataset (2020–2025)
On this page
The question
Why does stolen healthcare data remain unusually profitable?
Credit-card fraud is a solved problem: numbers rotate, chip readers block counterfeits, banks refund. PHI is not solved. Its criminal-market price has increased, not decreased, and the introduction of generative AI has raised per-record attacker yield. The paper builds a three-layer model that explains why — and identifies which layer is actually the policy lever.
“Attackers operate in transparent, liquid data markets with near-perfect price discovery. Defenders operate blind. The asymmetry isn't an accident — it's the architecture.”
— The Cyber-Economic Stack, §9.5 · SSRN 5792382
The framework
The cornerstone failure isn't encryption — it's asymmetry.
The stack models this asymmetry through three empirical indices unified in a single exploitability score, TARF. The primary lever to reduce it: disclosure transparency.
TARFt = (DMVIt × AAFt × Rt) / HTIt
Dark-Market Value Index (DMVI)
Median price of stolen PHI in criminal markets. Unlike credit cards, PHI is immutable — SSNs, diagnoses, and birth dates cannot be revoked, creating permanent multi-domain fraud utility.
PHI: $280–310 / record · Credit cards: $30–50 · PHI CAGR: +4.1%
AI Amplification Factor (AAF)
How generative AI increases attacker ROI per record. The ChatGPT release collapsed the skill barrier — voice cloning from 3-second samples, synthetic personas at scale, phishing that passes every test.
AAF: 1.18–1.30 · Voice fraud: 12% → 34% post-AI · +$38.60 / record
Healthcare Transparency Index (HTI)
Scores disclosure quality across speed, richness, and cadence. HTI lives in the denominator of TARF — higher transparency compresses exploitability. Healthcare scores 23 vs. finance's 81.
Healthcare HTI: 23 · Finance: 81 · 3.5× deficit · r = −0.52 (p = 0.003)
Findings
Five results anchor the framework.
PHI commands $280–310 per record — an 8–10× premium over credit card data.
The premium is structural, not cyclical. Unlike credit cards, PHI is immutable — SSNs, diagnoses, and birth dates cannot be revoked. Immutability creates permanent multi-domain fraud utility: medical identity theft, tax fraud, synthetic account origination, insurance fraud, and prescription fraud all remain executable from the same record for decades.
AI has amplified attacker return by 18–30% per record since ChatGPT.
Voice fraud +70%, synthetic identity +27%, phishing yield +36% per compromised record. The mechanism is a collapse of the skill barrier — voice cloning from 3-second samples, synthetic personas at scale, and phishing that passes every heuristic. AI does not create new attack vectors; it makes the existing ones cheaper and faster to execute at industrial scale.
Healthcare's transparency score is 23. Finance's is 81.
The Healthcare Transparency Index (HTI) scores disclosure quality across speed, richness, and cadence. A 3.5× transparency deficit produces the 93-day arbitrage window during which stolen data retains maximum liquidity. HTI is the primary lever in the TARF denominator — the field with the most upside for reducing systemic exploitability.
Halving disclosure latency projects to $8–12B in suppressed annual fraud.
Compressing healthcare's detection-to-disclosure interval from 93 days to 46 days is modeled to reduce sector-wide exploit ROI by 25–35% — equivalent to $8–12 billion in suppressed fraud losses annually. The mechanism operates through liquidity decay: exposed records lose criminal-market value once notification triggers PHI-refresh workflows at insurers and pharmacies.
TARF shows preliminary predictive validity (r = 0.61, n=18).
Applied retrospectively across 18 litigated healthcare breach cases with public cost outcomes, TARF-projected exploitability correlated with actual per-incident cost at r = 0.61. Small sample and litigation-selection bias limit generalizability; the correlation is directionally supportive of the framework and motivates the ongoing State of Compliance quarterly application.
Why it matters
The 93-day gap is a policy variable.
Framing healthcare breaches as security-hygiene failures pushes policy attention to encryption and access controls. The stack reframes the failure as a market asymmetry, which relocates the leverage: HTI, not DMVI, is the tractable layer. Attackers set DMVI. Regulators, sector coordinators, and covered entities set HTI — through breach notification cadence, disclosure richness, and the speed of PHI-refresh workflows at pharmacies and payers.
“The 93-day gap between breach occurrence and victim notification is a 93-day window during which stolen medical identities are sold, synthetic accounts opened, fraud committed — all while responsible entities remain silent.”
— The Cyber-Economic Stack, §9.1 · SSRN 5792382
Methodology
How the paper was built.
Empirical foundation is a 1,423-breach healthcare dataset spanning 2020–2025. DMVI is calibrated against 60+ dark-market price observations aggregated from published Intel 471, Recorded Future, and Flashpoint reporting. AAF is estimated from voice-fraud incidence data (Pindrop) and phishing-yield benchmarks pre- and post-ChatGPT release. HTI is scored against notification speed, disclosure richness (per-record detail depth), and cadence of update issuance across the 1,423-breach set.
IBM Security & Ponemon Institute. Cost of a Data Breach Report 2024.
Pindrop Security. Annual Voice Fraud Report 2025.
HHS OCR. HIPAA Breach Reporting Tool, 2020–2025.
Intel 471, Recorded Future, Flashpoint. Dark Web PHI Market Analysis 2024.
Limitations
What the framework does not claim.
TARF is diagnostic, not causal
Correlation with cost outcomes is real but preliminary (n=18). The framework is a lens for structuring intervention analysis, not a proven causal model.
DMVI depends on observable markets
Dark-market pricing is inferred from public forum monitoring and vendor-published reports. Genuinely closed markets are under-sampled by construction.
AAF is a moving target
AI capability is advancing faster than measurement. Reported AAF (1.18–1.30) reflects the post-ChatGPT / pre-frontier-agent state. Ongoing revision expected.
HTI scores are U.S.-centric
Comparative HTI against non-U.S. regulatory regimes would require replication with foreign disclosure frameworks. Cross-country application is deferred.
Cite this paper
Suggested citation.
Permitted uses include academic citation with full attribution, fair-use quotation for commentary or news reporting, and sharing of the published PDF in its complete and unaltered form.
APA
Perrin, A. (2025). The cyber-economic stack: How AI turns healthcare data into a financialized attack asset. Secure Care Research Institute, Patient Protect LLC. https://papers.ssrn.com/abstract=5792382
Chicago
Perrin, Alexander. "The Cyber-Economic Stack: How AI Turns Healthcare Data Into a Financialized Attack Asset." Working Paper. Chicago: Secure Care Research Institute, Patient Protect LLC, 2025. https://papers.ssrn.com/abstract=5792382.
BibTeX
@techreport{perrin2025_cyber_economic_stack,
author = {Perrin, Alexander},
title = {The Cyber-Economic Stack: How AI Turns Healthcare Data Into a Financialized Attack Asset},
institution = {Secure Care Research Institute, Patient Protect LLC},
year = {2025},
type = {Working paper},
url = {https://papers.ssrn.com/sol3/papers.cfm?abstract_id=5792382}
}Follow the research
New papers, State of Compliance issues, and dataset updates.
Get the paper
JEL D82, I18, L51 · Secure Care Research Institute, Chicago
