Skip to main content
Patient Protect circular logo mark in purple and white used for site navigationPatient Protect
Foundational PaperSSRN 5792382 · v2.6 · 2025

The Cyber-Economic Stack

How AI turns healthcare data into a financialized attack asset.

A three-layer analytical framework linking dark-market economics, AI amplification, and healthcare's transparency deficit — unified in a single Transparency-Adjusted Risk Function (TARF) that quantifies systemic exploitability. Analysis of 1,423 healthcare breaches (2020–2025) shows halving disclosure latency could reduce sector-wide exploit ROI by 25–35%.

$280–310

Per-record PHI dark-market price

8–10×

PHI premium over credit card data

93 days

Avg. healthcare detection latency

1,423

Breach dataset (2020–2025)

The question

Why does stolen healthcare data remain unusually profitable?

Credit-card fraud is a solved problem: numbers rotate, chip readers block counterfeits, banks refund. PHI is not solved. Its criminal-market price has increased, not decreased, and the introduction of generative AI has raised per-record attacker yield. The paper builds a three-layer model that explains why — and identifies which layer is actually the policy lever.

“Attackers operate in transparent, liquid data markets with near-perfect price discovery. Defenders operate blind. The asymmetry isn't an accident — it's the architecture.”

— The Cyber-Economic Stack, §9.5 · SSRN 5792382

The framework

The cornerstone failure isn't encryption — it's asymmetry.

The stack models this asymmetry through three empirical indices unified in a single exploitability score, TARF. The primary lever to reduce it: disclosure transparency.

TARFt = (DMVIt × AAFt × Rt) / HTIt

DMVI = Dark-market value indexAAF = AI amplification factorR = Reusability decay factorHTI = Healthcare transparency index
1

Dark-Market Value Index (DMVI)

Median price of stolen PHI in criminal markets. Unlike credit cards, PHI is immutable — SSNs, diagnoses, and birth dates cannot be revoked, creating permanent multi-domain fraud utility.

PHI: $280–310 / record · Credit cards: $30–50 · PHI CAGR: +4.1%

2

AI Amplification Factor (AAF)

How generative AI increases attacker ROI per record. The ChatGPT release collapsed the skill barrier — voice cloning from 3-second samples, synthetic personas at scale, phishing that passes every test.

AAF: 1.18–1.30 · Voice fraud: 12% → 34% post-AI · +$38.60 / record

3

Healthcare Transparency Index (HTI)

Scores disclosure quality across speed, richness, and cadence. HTI lives in the denominator of TARF — higher transparency compresses exploitability. Healthcare scores 23 vs. finance's 81.

Healthcare HTI: 23 · Finance: 81 · 3.5× deficit · r = −0.52 (p = 0.003)

Findings

Five results anchor the framework.

01

PHI commands $280–310 per record — an 8–10× premium over credit card data.

The premium is structural, not cyclical. Unlike credit cards, PHI is immutable — SSNs, diagnoses, and birth dates cannot be revoked. Immutability creates permanent multi-domain fraud utility: medical identity theft, tax fraud, synthetic account origination, insurance fraud, and prescription fraud all remain executable from the same record for decades.

02

AI has amplified attacker return by 18–30% per record since ChatGPT.

Voice fraud +70%, synthetic identity +27%, phishing yield +36% per compromised record. The mechanism is a collapse of the skill barrier — voice cloning from 3-second samples, synthetic personas at scale, and phishing that passes every heuristic. AI does not create new attack vectors; it makes the existing ones cheaper and faster to execute at industrial scale.

03

Healthcare's transparency score is 23. Finance's is 81.

The Healthcare Transparency Index (HTI) scores disclosure quality across speed, richness, and cadence. A 3.5× transparency deficit produces the 93-day arbitrage window during which stolen data retains maximum liquidity. HTI is the primary lever in the TARF denominator — the field with the most upside for reducing systemic exploitability.

04

Halving disclosure latency projects to $8–12B in suppressed annual fraud.

Compressing healthcare's detection-to-disclosure interval from 93 days to 46 days is modeled to reduce sector-wide exploit ROI by 25–35% — equivalent to $8–12 billion in suppressed fraud losses annually. The mechanism operates through liquidity decay: exposed records lose criminal-market value once notification triggers PHI-refresh workflows at insurers and pharmacies.

05

TARF shows preliminary predictive validity (r = 0.61, n=18).

Applied retrospectively across 18 litigated healthcare breach cases with public cost outcomes, TARF-projected exploitability correlated with actual per-incident cost at r = 0.61. Small sample and litigation-selection bias limit generalizability; the correlation is directionally supportive of the framework and motivates the ongoing State of Compliance quarterly application.

Why it matters

The 93-day gap is a policy variable.

Framing healthcare breaches as security-hygiene failures pushes policy attention to encryption and access controls. The stack reframes the failure as a market asymmetry, which relocates the leverage: HTI, not DMVI, is the tractable layer. Attackers set DMVI. Regulators, sector coordinators, and covered entities set HTI — through breach notification cadence, disclosure richness, and the speed of PHI-refresh workflows at pharmacies and payers.

“The 93-day gap between breach occurrence and victim notification is a 93-day window during which stolen medical identities are sold, synthetic accounts opened, fraud committed — all while responsible entities remain silent.”

— The Cyber-Economic Stack, §9.1 · SSRN 5792382

Methodology

How the paper was built.

Empirical foundation is a 1,423-breach healthcare dataset spanning 2020–2025. DMVI is calibrated against 60+ dark-market price observations aggregated from published Intel 471, Recorded Future, and Flashpoint reporting. AAF is estimated from voice-fraud incidence data (Pindrop) and phishing-yield benchmarks pre- and post-ChatGPT release. HTI is scored against notification speed, disclosure richness (per-record detail depth), and cadence of update issuance across the 1,423-breach set.

IBM Security & Ponemon Institute. Cost of a Data Breach Report 2024.

Pindrop Security. Annual Voice Fraud Report 2025.

HHS OCR. HIPAA Breach Reporting Tool, 2020–2025.

Intel 471, Recorded Future, Flashpoint. Dark Web PHI Market Analysis 2024.

Limitations

What the framework does not claim.

TARF is diagnostic, not causal

Correlation with cost outcomes is real but preliminary (n=18). The framework is a lens for structuring intervention analysis, not a proven causal model.

DMVI depends on observable markets

Dark-market pricing is inferred from public forum monitoring and vendor-published reports. Genuinely closed markets are under-sampled by construction.

AAF is a moving target

AI capability is advancing faster than measurement. Reported AAF (1.18–1.30) reflects the post-ChatGPT / pre-frontier-agent state. Ongoing revision expected.

HTI scores are U.S.-centric

Comparative HTI against non-U.S. regulatory regimes would require replication with foreign disclosure frameworks. Cross-country application is deferred.

Cite this paper

Suggested citation.

Permitted uses include academic citation with full attribution, fair-use quotation for commentary or news reporting, and sharing of the published PDF in its complete and unaltered form.

APA

Perrin, A. (2025). The cyber-economic stack: How AI turns healthcare data into a financialized attack asset. Secure Care Research Institute, Patient Protect LLC. https://papers.ssrn.com/abstract=5792382

Chicago

Perrin, Alexander. "The Cyber-Economic Stack: How AI Turns Healthcare Data Into a Financialized Attack Asset." Working Paper. Chicago: Secure Care Research Institute, Patient Protect LLC, 2025. https://papers.ssrn.com/abstract=5792382.

BibTeX

@techreport{perrin2025_cyber_economic_stack,
  author      = {Perrin, Alexander},
  title       = {The Cyber-Economic Stack: How AI Turns Healthcare Data Into a Financialized Attack Asset},
  institution = {Secure Care Research Institute, Patient Protect LLC},
  year        = {2025},
  type        = {Working paper},
  url         = {https://papers.ssrn.com/sol3/papers.cfm?abstract_id=5792382}
}

Follow the research

New papers, State of Compliance issues, and dataset updates.

Get the paper

Read full paper on SSRN

JEL D82, I18, L51 · Secure Care Research Institute, Chicago