Skip to main content
Patient Protect circular logo mark in purple and white used for site navigationPatient Protect
Foundational PaperSSRN 5257628 · v1.8 · 2025

The Economics of ePHI Exposure

A Long-Term Impact Model of Healthcare Data Breaches.

A ten-year cumulative cost model for healthcare data breaches across six impact domains: regulatory penalties, litigation, cyber insurance shifts, patient attrition, remediation, and downstream fraud. The paper demonstrates that breach consequences compound rather than conclude after year one, with 10-year impact exceeding immediate expenses by 300–500% for most providers.

$4–6M

10-yr impact, 5,000-record breach

300–500%

10-yr costs over year-one

65–70%

Patients willing to switch

Attacks on physician practices 2021→22

The question

What does a healthcare breach actually cost after the headlines end?

Industry breach cost reports capture year-one expenses. They do not capture what happens in years two through ten: regulatory settlements that arrive after multi-year investigations, class actions that certify long after notification, insurance repricing that persists across renewal cycles, and downstream fraud enabled by exposed PHI that never expires. This paper builds a ten-year additive impact model to close that gap.

“This analysis reframes breaches not as isolated security failures, but as chronic financial liabilities with systemic implications. Small providers — who make up the backbone of American care delivery — are the least equipped to absorb this kind of long-tail risk.”

— The Economics of ePHI Exposure, §7 · SSRN 5257628

Findings

Five results anchor the model.

01

Breach consequences compound rather than conclude after year one.

Ten-year cumulative costs exceed year-one expenses by 300–500% for most providers. The dominant driver is not the immediate incident response — it's the multi-year erosion of patient trust, insurance premium repricing, downstream fraud remediation, and regulatory scrutiny.

02

A single 5,000-record breach generates $4–6M in 10-year impact.

Modeled for a mid-sized clinic with weak security. Six impact domains are additive: regulatory penalties, litigation, cyber insurance shifts, patient attrition, remediation costs, and downstream fraud enabled by exposed PHI.

03

Patient attrition is the dominant cost driver, not fines.

65–70% of patients report willingness to switch providers post-breach. For independent practices operating on 12–15% margins, revenue erosion routinely exceeds direct incident costs by year three.

04

Attacks on independent physician practices grew 6× from 2021 to 2022.

Reported in Critical Insight's 2022 Healthcare Data Breach Report. The trend continued in the years since — small providers now sit at the intersection of high data value, low security investment capacity, and constrained recovery cash flow.

05

Documented small-practice closures directly attributed to ransomware.

Two documented small-practice closures directly attributed to ransomware occurred in 2019. The 10-year model was built in part to explain why: the operational disruption compounds against margin structure that cannot absorb a multi-quarter revenue interruption.

Why it matters

A breach isn't a quarter — it's a decade.

Insurance underwriters, regulators, and practice owners typically scope breach cost against the current or next fiscal quarter. The 10-year model demonstrates that the largest cost components — attrition, insurance repricing, and downstream fraud — do not materialize until years two through five. Practices that survive the initial disruption often fail during the compounding period that follows.

What compounding looks like

A cancer patient whose chemotherapy was delayed three weeks. A diabetic who rationed insulin for nine days. A rural clinic that closed permanently, leaving 4,000 patients without primary care. These aren't edge cases. They're the predictable output of a system where stolen health data is worth more than credit cards, and the average time between breach and notification is longer than a fiscal quarter.

The six additive domains

§1

Regulatory penalties

OCR civil money penalties, state AG enforcement, sector-specific fines.

§2

Litigation

Class action suits, individual plaintiffs, downstream vendor claims.

§3

Cyber insurance shifts

Premium repricing, coverage exclusions, deductible escalation post-incident.

§4

Patient attrition

Revenue erosion from switching behavior, referral network damage.

§5

Remediation

Forensics, notification, credit monitoring, system rebuild, staff time.

§6

Downstream fraud

Long-tail medical identity theft, synthetic-identity account origination, insurance fraud committed with exposed PHI.

Methodology

How the paper was built.

The paper is a synthesis and extension of prior work rather than a primary-collection study. Cost curves are constructed from published IBM/Ponemon Cost of a Data Breach data, Ponemon medical identity theft studies, Critical Insight healthcare breach reports, and JAMA Internal Medicine PHI breach type research. Attrition modeling draws on published patient-behavior surveys post-incident. Legal cost modeling draws on OCR settlement records and reported class-action certifications and payouts.

IBM Security & Ponemon Institute. Cost of a Data Breach Report 2024.

Ponemon Institute. Fifth Annual Study on Medical Identity Theft 2019.

Critical Insight. Healthcare Data Breach Report 2022.

Jiang JX, Bai G. Types of Information Compromised in Breaches of PHI. JAMA Internal Medicine 2019.

Limitations

What the model does not claim.

Aggregate, not per-entity

Cost bands are modeled averages across provider size categories. Individual entity outcomes vary with security posture, incident vector, insurance coverage, and geography.

10-year horizon is a modeling window

Downstream fraud enabled by stolen PHI can persist beyond 10 years — the paper's window is chosen for tractability, not because impacts terminate.

Assumes weak-baseline security

Findings scale most directly to providers without mature control regimes. Providers with mature Zero Trust, MFA, and encryption in force will fall in the lower band of each cost domain.

US regulatory context

The paper is scoped to U.S. HIPAA/OCR enforcement and state AG regimes. Non-U.S. providers face structurally different regulatory and litigation environments.

Read the paper

Preview the first eight pages.

Working paper, 39 pages. Available in full on SSRN. Full-text PDF also available for direct download after email confirmation.

Unlock the full preview

Enter your email to unlock all 8 preview pages and the full paper on SSRN.

Recorded briefing

A 22-minute walkthrough with the author.

Research briefing video thumbnail

Gated · Research Briefing

Watch: The Economics of ePHI Exposure

10-year breach cost model, key findings, and what they mean for independent practices.

Cite this paper

Suggested citation.

Permitted uses include academic citation with full attribution, fair-use quotation for commentary or news reporting, and sharing of the published PDF in its complete and unaltered form.

APA

Perrin, A. (2025). The economics of ePHI exposure: A long-term impact model of healthcare data breaches. Secure Care Research Institute, Patient Protect LLC. https://papers.ssrn.com/abstract=5257628

Chicago

Perrin, Alexander. "The Economics of ePHI Exposure: A Long-Term Impact Model of Healthcare Data Breaches." Working Paper. Chicago: Secure Care Research Institute, Patient Protect LLC, 2025. https://papers.ssrn.com/abstract=5257628.

BibTeX

@techreport{perrin2025_ephi_economics,
  author      = {Perrin, Alexander},
  title       = {The Economics of ePHI Exposure: A Long-Term Impact Model of Healthcare Data Breaches},
  institution = {Secure Care Research Institute, Patient Protect LLC},
  year        = {2025},
  type        = {Working paper},
  url         = {https://papers.ssrn.com/sol3/papers.cfm?abstract_id=5257628}
}

Follow the research

New papers, State of Compliance issues, and dataset updates.