Independent research into the economics, concentration, and consequences of healthcare data exposure.
We study why protected health information remains uniquely valuable to attackers, how technology is changing breach economics, and where systemic healthcare risk is concentrating. Every finding is published with its sources, methods, and limitations.
2
Foundational papers
1
Quarterly series
4
Published outputs
1,423
Breach dataset
60+
Sources
100%
Indep. funded
Last updated July 2026 · Q2 2026 Brief published July 2026
The research program
Three questions. One thesis.
Healthcare breaches are not isolated IT failures. They are the predictable result of valuable, immutable data; increasingly efficient attackers; concentrated vendor exposure; and delayed transparency. Each of the Institute's three research programs owns one part of that thesis.
Attackers operate in transparent, liquid data markets with near-perfect price discovery. Defenders operate blind. The asymmetry isn't an accident — it's the architecture.
The Cyber-Economic Stack · SSRN 5792382
01 · Consequence
The Economics of ePHI Exposure
What does a healthcare breach actually cost after the immediate incident ends?
10-year cumulative impact exceeds year-one expenses by 300–500%.
Explore the paper02 · Mechanism
The Cyber-Economic Stack
Why is healthcare data so valuable, and how do AI and delayed disclosure increase attacker returns?
A 3.5× transparency deficit creates a 93-day arbitrage window.
Explore the framework03 · Evidence
Live · Q2 2026State of Compliance
Where is healthcare breach risk concentrating right now?
10
Disclosures
2.7M+
Affected
51.7%
One vendor
In Q2 2026, half of verified impact came from a single AI-enabled vendor.
Explore the seriesOne AI vendor held half the verified risk in Q2.
Ten independently verified disclosures. At least 2.7 million people affected. One AI-enabled utilization-management vendor accounted for 51.7% of the verified population impact. The upstream-concentration pattern established in Q1 persisted through a new AI-vendor channel.
10
Verified disclosures
2.7M+
Affected (floor)
51.7%
From one AI vendor
7/10
At specialty practices
Publications archive
Full archive →Data, methods, and standards
What makes it a research institute.
Institutional authority is earned through documented practice — not through the volume of statistics on the screen. SCRI publishes its methodology, sources, known limitations, versioning behavior, and citation policy as standing artifacts. The same rules apply to every publication.
Full data & methods pageResearch methodology
Three-mode program design — foundational papers, quarterly empirical series, practitioner analysis.
Data sources & limits
Seven authoritative channels. What the compilation captures and what it does not.
Versioning & corrections
Every publication carries a version. Material corrections are announced.
Citation & reuse
Cite freely with attribution. Datasets released under CC BY 4.0.
About the Institute
The Secure Care Research Institute.
The Secure Care Research Institute is the research program of Patient Protect LLC. It examines the economics, concentration, disclosure, and systemic consequences of healthcare data exposure.
Research is independently funded by Patient Protect and published with documented sources, methods, limitations, version histories, and citation guidance — whether or not findings support a commercial product decision.
Scale of exposure · 2024
276M
Americans with PHI exposed in 2024.
81% of the country — more than in any previous year. Detection latency averaged 93 days. The scale is the reason SCRI exists; the compilation and cost work is aimed at what the OCR portal cannot show on its own.
Source: HHS Office for Civil Rights Breach Reporting Tool, 2025.
From research to practice
Findings inform how we build.
SCRI's findings inform how Patient Protect approaches healthcare security, vendor risk, breach intelligence, and compliance infrastructure. Research conclusions are published with their methods and limitations whether or not they support a commercial product decision.
See how the research informs Patient ProtectResearch-informed
- Zero Trust architecture — sized to the vendor-cascade risk documented in the State of Compliance series.
- AppSensor behavioral intrusion detection — sized to the 93-day detection latency described in the Stack paper.
- On-premises AI compliance copilot — sized to the AI amplification factor quantified in the Stack paper.
Follow the research
Receive new SCRI papers, State of Compliance issues, dataset updates, and research briefings.
One list. Research only.

