HEALTHCARE DATA BREACHES
A PHI breach is one phone call away. AI industrialized the call.
AI attackers
are actively
targeting
healthcare orgs
KBA, OTPs, and voice biometrics were not built for AI.
Voice-channel attacks are not new. The scale is. Generative AI lets one attacker run convincing synthetic voices and bots at machine speed, fooling agents and legacy controls alike. KBA and one-time passcodes were never built for AI-generated identity backed by stolen PII.
Nearly 60% of organizations report fraudsters using compromised PII to bypass KBA.4 And traditional voice biometrics verify a single factor, a matching voice profile, that AI clones can now defeat.
How AI voice calls create data breaches
Three questions answered on every interaction, before PHI changes hands.
Is this a machine?
Is this a bad actor?
Is this the right person?
Fortify your security.
Related research + insights
Access expert research, detailed guides, and practical resources on voice and video security to strengthen your organization’s defenses.
Deepfakes Aren’t Just Headlines Anymore. They’re Becoming Healthcare Policy.
AI Attacks in Healthcare: Bots, Deepfakes, and Rising Risk
The KBA Tax: What Knowledge-Based Authentication Really Costs Health Plans
1 Pindrop, “2025 Voice Intelligence and Security Report,” June 2025.
2 2. U.S. Dept. of Health and Human Services, Office for Civil Rights, Annual Report to Congress on Breaches of Unsecured Protected Health Information, 242,908,056 individuals affected by breaches that occurred in 2024.
3 Gartner, “How to Respond to the 2026-2027 Threat Landscape,” May 2026.
4 HYPR / TransUnion, 2025 State of Omnichannel Fraud Report Insights, May 2025.