A patient record does not disappear after a breach. It gets sold. The average person hears "dark web" and pictures something abstract and criminal, but for a healthcare organization, it is a concrete destination with a price list, and the record of a single patient is worth far more there than almost anyone outside the industry realizes.
Understanding the dark web matters for healthcare specifically because it is where the data stolen in a breach ends up, where the credentials used to start the next breach get bought, and where the economics that make healthcare the most targeted sector in the country are actually set.
What the dark web actually is
The internet has three layers, and only one of them shows up in a Google search. The surface web is everything a standard search engine can find and index. Beneath it sits the deep web, which is simply any content behind a login or a paywall, such as your patient portal, your email inbox, your EHR, your online banking. None of that is sinister, it just is not publicly indexed, and it makes up the overwhelming majority of everything online.
The dark web is a small, deliberately hidden portion of the deep web. Reaching it requires specific software, most commonly Tor, short for The Onion Router, a browser that routes a user's connection through multiple encrypted layers to conceal their identity and location. That anonymity is the entire point. Tor was originally developed with US government backing for legitimate privacy purposes, and journalists, activists, and people living under censorship still rely on it. The same anonymity that protects a whistleblower, though, also protects a criminal marketplace, and that is where healthcare's problem begins.
Read also: What is the dark web?
Why a medical record is worth more than a credit card
Stolen payment cards are cheap because they are perishable. Cancel the card, and the data is worthless within hours. A medical record has no cancel button, and that permanence is exactly what sets the price.
The gap is stark. Denyl Green, global head of identity theft and breach notification at Kroll, told Forbes that stolen healthcare data on the dark web can be worth as much as $1,000 per record, compared to roughly $5 for a stolen credit card. A complete record carries a patient's full name, date of birth, Social Security number, home address, insurance details, diagnoses, and treatment history, which is everything a criminal needs to construct a convincing false identity that holds up under scrutiny.
That single dataset supports several kinds of fraud at once. Someone can obtain medical treatment or prescriptions under the victim's name, a crime known as medical identity theft. Someone can file fraudulent insurance claims. Someone can build a synthetic identity, stitching together real verified details from multiple breaches into a composite that financial institutions trust precisely because the underlying data points check out. A credit card enables one type of fraud until it is cancelled. A medical record enables several, indefinitely.
Where the data comes from before it gets there
Most stolen healthcare data does not come from a dramatic hospital hack. It comes through email, and it usually starts with a login.
The Verizon 2025 Data Breach Investigations Report found that 54% of ransomware victims had their credentials sitting in stealer logs before the attack ever happened. Stealer logs are collections of usernames and passwords harvested by infostealer malware, a type of program that quietly captures saved credentials from an infected device's browser and sends them off to the attacker. Those logs get sold in bulk on dark web forums, and a set of healthcare VPN or EHR logins is the kind of access that lets an attacker walk straight through the front door, bypassing perimeter defenses entirely because they are logging in as a legitimate user.
The infostealer infection almost always traces back to a phishing email. Paubox's 2025 Healthcare Email Security Report found that only 5% of known phishing attacks in healthcare get reported by employees to security teams, which means the message that harvests the credential, that eventually shows up for sale on a forum, that gives the next attacker their way in, passes through unnoticed almost every time.
Read more: What is a phishing attack?
How stolen data moves once a breach happens
Modern ransomware groups have changed the sequence of an attack in a way that feeds the dark web directly. Rather than simply encrypting a victim's files and demanding payment, they steal a copy of the data first, then encrypt, then threaten to publish everything unless the ransom is paid. This is double extortion, and it means the data is already gone before the victim even knows an attack is underway.
When a ransom goes unpaid, the stolen files get posted on leak sites, dedicated dark web pages where ransomware groups publish their victims' data as punishment and as a warning to future targets. From there it spreads across hacker forums and gets repackaged for sale. The Change Healthcare attack in 2024 showed how little paying guarantees, with the ALPHV group exfiltrating data on an estimated 100 million or more individuals, reportedly receiving a substantial ransom, and the stolen data surfacing anyway after a dispute among the criminals involved. Once data leaves an organization, no payment reliably brings it back or keeps it off the market.
What it costs the patient and the organization
The downstream damage is severe and unusually hard to undo. Research from the Ponemon Institute, cited across identity protection reporting, found that the average victim of medical identity theft spent more than 200 hours and roughly $13,500 trying to repair the damage, and only a small fraction ever reached a resolution they considered satisfactory. Unlike a fraudulent credit charge that a bank reverses, a false entry in a medical record, a wrong blood type, an allergy that is not real, or a diagnosis that was never made can follow a patient into a future clinical decision with real consequences for their care.
For the organization, the breach that sends data to the dark web triggers the full weight of HIPAA. IBM's Cost of a Data Breach Report has put the average healthcare breach at $9.8 million, the highest of any sector for 14 consecutive years. The HHS OCR breach portal recorded well over 250 million patient records compromised across 2024 alone, a figure that means a large majority of the US population now has health data exposed somewhere. Behind each of those breaches sits notification obligations, potential OCR penalties, class action exposure, and the reputational cost of a community learning its hospital could not keep its records safe.
In the news
A recent TechTarget feature on the economics of the dark web gives a sense of the scale of the market this article describes. Threat intelligence tracking cited in the piece counted 2.86 billion compromised credentials circulating across criminal markets in 2025, harvested from more than 23 million infostealer-infected devices. Network access is sold as its own product, with initial access brokers listing verified entry points for between $500 and $3,000, and administrator-level credentials priced considerably higher. Payment happens almost entirely in cryptocurrency, with privacy-focused coins and stablecoins preferred for their resistance to tracing.
The piece also looks at how far law enforcement has been able to reach into this economy. Operation Cookie Monster, the FBI-led takedown of Genesis Market in 2023, resulted in 119 arrests across 17 countries. Operation Cronos seized 34 LockBit servers and identified the group's leader in 2024, and Operation RapTor produced 270 arrests across 10 countries in 2025. The results have been harder to sustain, though. BreachForums has been seized and rebuilt several times since 2023, and LockBit's leader remains in Russia, where a $10 million US State Department reward carries no practical weight without an extradition agreement. The takedowns show what coordinated enforcement can do, and the reconstitutions show why the market has continued to operate regardless.
Where the intervention actually works
Dark web monitoring services exist, and they have a role, scanning marketplaces and leak sites to alert an organization when its credentials or patient data appear. Monitoring is a detection tool, though. By the time a record shows up for sale, the breach has already happened, and the notification clock is already running.
The leverage sits earlier, at the email that starts the chain. Because most stolen healthcare data begins with a phishing message that harvests a credential, the most effective place to intervene is before that message is ever opened. Paubox's 2026 Healthcare Email Security Report tracked a 47% increase in attacks avoiding native email defenses in 2025, which tells you the default filtering built into Microsoft 365 and Google Workspace is not catching what it needs to catch. Paubox Inbound Email Security uses AI to analyze sender behavior, message intent, and contextual signals across every inbound message, catching the phishing attempts that signature-based filters miss before they reach an inbox and before a credential ever makes its way toward a dark web forum.
Learn more: Paubox Inbound Email Security
FAQs
Is it illegal to access the dark web?
No. The dark web itself is just a hidden part of the internet reached through anonymizing software like Tor, and it has legitimate uses for privacy, journalism, and circumventing censorship. Buying or selling stolen data on it is illegal, but visiting the network is not a crime in itself.
Why is healthcare data worth so much more than financial data?
A credit card can be cancelled within hours of being stolen, which destroys its value, while a medical record cannot be reset or revoked. It also contains everything needed for multiple kinds of fraud at once, identity theft, insurance fraud, and medical fraud, which is why a single record can sell for up to $1,000 compared to a few dollars for a card.
How does patient data usually end up on the dark web?
Most often through a chain that starts with a phishing email harvesting an employee's login, which gives attackers access to steal data, which then gets sold or published on dark web forums and leak sites. Double extortion ransomware, where groups steal data before encrypting it, has made this the standard path.
What is medical identity theft and why is it so hard to fix?
Medical identity theft is when someone uses stolen patient information to obtain treatment, prescriptions, or insurance payouts under another person's name. It is difficult to resolve because it can corrupt the victim's actual medical record with false information, and unlike financial fraud, there is no simple mechanism to reverse it, with victims averaging more than 200 hours and thousands of dollars to repair the damage.
What is the most effective way to keep patient data off the dark web?
Stop the breach at its most common entry point. Since most stolen healthcare data begins with a phishing email that harvests a credential, pre-delivery email filtering that removes those messages before staff ever see them addresses the problem earlier and more reliably than monitoring for data after it has already been stolen and listed for sale.
