Skip to main content
Patient Protect circular logo mark in purple and white used for site navigationPatient Protect
Secure Care Research InstituteIndependently funded · Chicago, IL

Independent research into the economics, concentration, and consequences of healthcare data exposure.

We study why protected health information remains uniquely valuable to attackers, how technology is changing breach economics, and where systemic healthcare risk is concentrating. Every finding is published with its sources, methods, and limitations.

2

Foundational papers

1

Quarterly series

4

Published outputs

1,423

Breach dataset

60+

Sources

100%

Indep. funded

Last updated July 2026 · Q2 2026 Brief published July 2026

The research program

Three questions. One thesis.

Healthcare breaches are not isolated IT failures. They are the predictable result of valuable, immutable data; increasingly efficient attackers; concentrated vendor exposure; and delayed transparency. Each of the Institute's three research programs owns one part of that thesis.

Attackers operate in transparent, liquid data markets with near-perfect price discovery. Defenders operate blind. The asymmetry isn't an accident — it's the architecture.

The Cyber-Economic Stack · SSRN 5792382
Latest research · July 2026Vol. 1 · Issue 2 (Brief) · Q2 2026

One AI vendor held half the verified risk in Q2.

Ten independently verified disclosures. At least 2.7 million people affected. One AI-enabled utilization-management vendor accounted for 51.7% of the verified population impact. The upstream-concentration pattern established in Q1 persisted through a new AI-vendor channel.

10

Verified disclosures

2.7M+

Affected (floor)

51.7%

From one AI vendor

7/10

At specialty practices

Data, methods, and standards

What makes it a research institute.

Institutional authority is earned through documented practice — not through the volume of statistics on the screen. SCRI publishes its methodology, sources, known limitations, versioning behavior, and citation policy as standing artifacts. The same rules apply to every publication.

Full data & methods page

About the Institute

The Secure Care Research Institute.

The Secure Care Research Institute is the research program of Patient Protect LLC. It examines the economics, concentration, disclosure, and systemic consequences of healthcare data exposure.

Research is independently funded by Patient Protect and published with documented sources, methods, limitations, version histories, and citation guidance — whether or not findings support a commercial product decision.

Scale of exposure · 2024

276M

Americans with PHI exposed in 2024.

81% of the country — more than in any previous year. Detection latency averaged 93 days. The scale is the reason SCRI exists; the compilation and cost work is aimed at what the OCR portal cannot show on its own.

Source: HHS Office for Civil Rights Breach Reporting Tool, 2025.

From research to practice

Findings inform how we build.

SCRI's findings inform how Patient Protect approaches healthcare security, vendor risk, breach intelligence, and compliance infrastructure. Research conclusions are published with their methods and limitations whether or not they support a commercial product decision.

See how the research informs Patient Protect

Research-informed

  • Zero Trust architecture — sized to the vendor-cascade risk documented in the State of Compliance series.
  • AppSensor behavioral intrusion detection — sized to the 93-day detection latency described in the Stack paper.
  • On-premises AI compliance copilot — sized to the AI amplification factor quantified in the Stack paper.

Follow the research

Receive new SCRI papers, State of Compliance issues, dataset updates, and research briefings.

One list. Research only.