1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18

The Image With No Custodian

What Fifteen Years of Healthcare Leading Every Data-Breach Cost Ranking Reveals About Governing Clinical Imaging at the Scanner

IBM's Cost of a Data Breach Report has ranked healthcare as the most expensive sector for data breaches for over a decade running. The 2025 report put the average healthcare breach at $7.42 million; the 2026 report, released within the last two months, put it at $6.64 million, still the highest of any industry tracked. This paper extends The Governed Signal to clinical imaging, where HIPAA compliance today is a policy layer rather than a property of the image itself.

Ken Granville CEO & Co-Founder, MindAptiv Signal Paper V The Governed Signal August 2026
Vertical
Medical
Signal
MRI / X-Ray / CT / Clinical Imaging
Mechanism
SecuriSync™ Trust Record
Status
Enterprise Vertical V
Abstract

Healthcare has led every industry IBM tracks in average data-breach cost for more than a decade of consecutive annual reports, a streak independent coverage of IBM's Cost of a Data Breach Report describes as running 14 to 15 years depending on which year's report is used as the count's starting point. The 2025 report placed the average healthcare breach at $7.42 million; the 2026 report, published within the two months preceding this paper, placed it at $6.64 million, a year-over-year decline, but still the highest average cost of any sector in that year's report. Every MRI, X-ray, CT scan, and clinical photograph sits inside that exposure, captured, processed, transmitted, and stored by multiple systems and parties, with acquisition metadata that, once written, has no reliable mechanism to detect whether it was altered afterward.

This paper applies Signal Paper I's doctrine, Captured ≠ Governed, to clinical imaging, and states plainly, consistent with Signal Papers II through IV, which figures were independently verified before use. The breach-cost figures come from IBM's own published annual reports, cited by report year rather than restated as an industry-wide constant, because the underlying number has moved meaningfully between the two most recent reports.

Section 01A Scan Is Not a Clinical Record

An MRI, an X-ray, and a CT scan are, in standard clinical practice, captured in DICOM format, which embeds substantial technical metadata directly into the file at acquisition: scanner manufacturer and model, acquisition parameters specific to the modality, and study and series identifiers, among other standardized fields. A clinical photograph, by contrast, typically carries no comparable embedded acquisition metadata unless a specific system is configured to add it. What DICOM's header does not provide, for any modality, is tamper-evidence: the same metadata that documents a scan's origin can be edited, intentionally or unintentionally, without leaving a structural trace, a persistent and well-documented problem in clinical and research imaging that a 2025 letter in the European Journal of Nuclear Medicine and Molecular Imaging describes as a 40-year-old, still-unresolved issue with the DICOM standard. HIPAA governs how the resulting file is handled (who may access it, how it must be transmitted, what safeguards must exist), but HIPAA compliance, as currently implemented across most clinical imaging pipelines, is a policy and access-control layer built around the image, not a guarantee that the image's own metadata reflects its true history.

That distinction is not abstract. IBM's Cost of a Data Breach Report, an annual study now in its third decade, has found healthcare to be the costliest sector for data breaches for well over ten consecutive years, driven by the same structural facts every year: high-value patient data, complex multi-party handling, and, per IBM's own reporting, the longest average identification-and-containment timelines of any industry tracked.

A Note on Sourcing and Certainty
The healthcare breach-cost figures in this paper come from IBM's Cost of a Data Breach Report, 2025 and 2026 editions, cited by report year because the figure declined between the two: $7.42 million average per incident in the 2025 report, $6.64 million in the 2026 report. Independent coverage of IBM's report varies on whether healthcare's streak at the top of the cost ranking is best described as 14 or 15 consecutive years, depending on which report year is used as the starting point; this paper uses "more than a decade" rather than asserting a single precise count. The DICOM metadata claims in Section 01 are drawn from the published DICOM standard and independent clinical-informatics literature, including a 2025 peer-reviewed letter documenting DICOM header editing as a persistent, unresolved problem; this paper distinguishes between metadata's presence (real, standard, and embedded at capture) and its tamper-evidence (absent in standard clinical practice), and does not claim the two are the same property. Section 04's characterization of HIPAA's Integrity standard (45 CFR 164.312(c)(1)) is drawn from the Security Rule's published text and independent compliance literature describing that standard as addressable, inconsistently implemented, and typically applied downstream rather than at acquisition; this paper does not claim HIPAA lacks any integrity requirement, only that the requirement as commonly implemented does not close the gap described in Section 02. The Morpheus® acceleration and energy figures referenced in Section 03 remain historical measurements from AWS and Rowan University's Digital Engineering Hub validation work, not a guarantee for any deployment, consistent with Signal Papers I through IV.

Section 02Where a Diagnostic Record Actually Breaks

The chain-of-custody gap in clinical imaging recurs across the diagnostic pathway.

At Acquisition
A scanner writes DICOM metadata (device identity, calibration and technique parameters) directly into the file. That metadata has no cryptographic signature, so an edit made afterward, whether intentional or accidental, leaves no structural trace distinguishing it from the original.
At Transmission
The image moves between the imaging center, the radiologist, the referring physician, and the patient's broader record, often across multiple systems and vendors, each a point where the image could be altered, misattributed, or exposed without a structural trace.
At Diagnosis and Second Opinion
The image informs a diagnosis, and may later be reviewed for a second opinion, an insurance determination, or a malpractice inquiry, each reliance compounding the consequence of an unresolved integrity question in the original file.
At Breach or Dispute
The image, along with the broader record it belongs to, becomes part of a breach incident or a legal or insurance dispute, at which point IBM's cost data describes the resulting exposure as consistently the most expensive of any industry tracked.

Current HIPAA compliance practice mitigates pieces of this chain through access logs, encryption in transit and at rest, and audit trails. The Security Rule's Integrity standard, 45 CFR 164.312(c)(1), also calls for "electronic mechanisms to corroborate that electronic protected health information has not been altered or destroyed in an unauthorized manner". This is a real requirement, typically implemented through cryptographic hashing, digital signatures, or version control. It is, however, an addressable rather than mandatory specification, is widely described in compliance literature as the least understood and most inconsistently implemented of the technical safeguards, and where it is implemented, it is almost always a system-level control applied downstream in the EHR or PACS rather than a property intrinsic to the image from the moment a scanner produces it. The gap this paper describes is narrower than an absence of any integrity requirement: it is the difference between an addressable, inconsistently-applied, downstream check and a mechanism present from acquisition onward that makes every later step in the diagnostic chain provable by construction rather than reconstructed after an incident.

Section 03What Governed at the Scanner Requires

illumin8 Medical applies the architecture described in Signal Papers I through IV to clinical imaging. StreamWeave® encryption is intrinsic at the scanner, so no unencrypted version of a governed clinical image exists anywhere in the pipeline: not at transmission, not at storage, not at the diagnostic workstation. Every image carries a SecuriSync™ Trust Record from acquisition outward, and each dataset receives a Nebulo® identity from a space MindAptiv states is collision-proof at any practical scale, so a patient's imaging history accumulates across years and providers without risk of one study being mistaken for, or substituted for, another.

Morpheus® addresses one of clinical imaging's most compute-intensive steps: MRI reconstruction. MindAptiv's published, third-party-validated figures for Morpheus® report processing acceleration of roughly 20 to 114 times and energy reduction of up to approximately 99.7% on the specific workloads tested by AWS and Rowan University's Digital Engineering Hub. Consistent with Signal Papers I through IV: those remain historical measurements from that validation work, not a performance guarantee for a clinical deployment specifically. What illumin8 Medical guarantees is procedural: governance occurs at the scanner, on every image, regardless of the reconstruction speed a given facility's hardware achieves.

This Series' Doctrine, Applied to a Clinical Image
Captured ≠ Governed
A scan that exists is not a scan a diagnostic chain can fully trust. Governance is what turns the first into the second, at the scanner, not through an access-control policy layered on top afterward.

The architectural basis for extending this claim to clinical imaging follows the same patent scope established in Signal Paper I: MindAptiv's foundational patents are drafted around digital signals generally, with images and other data types named explicitly in the earliest patent's own title. This paper does not re-derive that claim or its stated limits; see Signal Paper I, Section 05, for what has and has not been independently reviewed in the patents' claim language.

Section 04What Changes When Compliance Is Structural, Not Attested

HIPAA compliance today is demonstrated primarily through policy documentation, access logs, audit trails, and, where implemented, downstream integrity checks such as hashing or digital signatures applied at the EHR or PACS level. A breach investigation or regulatory audit still has to reconstruct the image's history from these separate records after the fact. A governed image carries its access and handling constraints as an intrinsic property, established at acquisition, rather than as a downstream compliance artifact that has to be cross-referenced against the image after the fact to prove nothing improper occurred.

This does not change the underlying HIPAA requirements, and it does not change the fact, illustrated by IBM's own data across every recent report, that healthcare handles some of the most valuable and heavily targeted data of any industry. What it changes is the starting position when a breach investigation, an OCR audit, or a malpractice discovery request asks whether a given image's access history is complete and unaltered: a governed image answers that question by construction, the same way a governed LiDAR scan or camera frame does in the earlier papers in this series, rather than requiring the reconstruction of access logs, transmission records, and system audit trails maintained separately from the image itself.

Why a Declining Breach-Cost Figure Doesn't Undercut This Argument
Healthcare's average breach cost fell from $7.42 million to $6.64 million between IBM's 2025 and 2026 reports. That decline does not weaken the case for governance at the scanner; IBM attributes recent global declines primarily to faster detection, not to a reduction in the underlying volume or sensitivity of the data being breached, and healthcare remained the single most expensive sector in both reports. A faster, cheaper breach response is not the same claim as a smaller underlying exposure.

Section 05What This Paper Does Not Claim

This paper does not claim that illumin8 Medical has been deployed at any specific hospital, imaging center, or health system, and no specific breach, audit, or diagnostic outcome is represented here. It does not claim a single precise figure for how many consecutive years healthcare has led IBM's breach-cost ranking; independent sources describe the streak as 14 or 15 years depending on the starting report year, and this paper uses "more than a decade" rather than asserting a specific count it cannot verify to the year. It does not claim that HIPAA's Security Rule lacks an integrity or data-authentication requirement; 45 CFR 164.312(c)(1) states one. It claims only that this requirement is addressable rather than mandatory, inconsistently implemented in practice, and typically applied downstream rather than intrinsic to an image from the moment of capture.

What Is Guaranteed and What Is Not
Consistent with Signal Papers I through IV: MindAptiv does not guarantee a specific acceleration multiple or energy-reduction percentage for a clinical deployment, and the 20–114× and approximately 99.7% figures remain historical measurements from specific tested workloads, not a service-level commitment, and not a claim about MRI reconstruction speed at any specific facility. What illumin8 Medical guarantees is procedural: governance occurs at the scanner, on every image, regardless of the processing performance a given facility's hardware achieves.

This paper does not claim that a governed image chain satisfies every HIPAA requirement on its own or replaces the need for a broader compliance program; it addresses the chain-of-custody and intrinsic-provenance gap specifically, which is one component of a much larger regulatory framework. It also does not claim that governance at the scanner would have prevented any specific breach reported in IBM's data, most of which involve external attack vectors like phishing and credential theft that a governed image's provenance chain does not, by itself, address.

Series context · This paper does not represent a completed audit, breach investigation, or regulatory finding · See Signal Paper I for the patent-scope discussion Section 03 relies on

Section 06Why Medical Follows Security

Medical imaging inherits the same governance architecture described in Signal Papers I through IV because a clinical scan is, structurally, the same class of signal as a camera frame or a LiDAR point: data captured by an instrument, relied on by parties who were not present at capture, with consequences that compound the further the record travels from its origin. What medical imaging adds to the pattern is the highest documented breach cost of any industry, per IBM's own annual measurement, and a regulatory framework, HIPAA, that currently treats provenance as a policy commitment rather than a property of the data.

That is why medical follows security as the fifth paper in this series: it extends the evidentiary argument from a single rule of evidence to an entire regulatory compliance regime, and does so in the industry IBM's own data identifies as bearing the highest cost when that regime is not satisfied.

Section 07Where This Series Goes From Here

The next paper in this series turns to thermal and infrared inspection, where the governing standards are drawn from ASTM International, the American Petroleum Institute (API), and the International Electrotechnical Commission (IEC) rather than a rule of evidence or a healthcare privacy statute.

Series context · Signal Paper V of The Governed Signal, the series behind illumin8 · Follows Signal Paper IV, The Frame That Can't Testify · Precedes Signal Paper VI, Thermal
The Governed Signal: Signal Paper V

A scan is not a clinical record.
Governance is what makes provenance a property of the image.

Healthcare has led every industry IBM tracks in average data-breach cost for more than a decade, most recently at $6.64 million per incident. illumin8 Medical governs the image at the scanner, not through a policy layer built around it afterward, so HIPAA-relevant provenance is intrinsic to the file from acquisition through diagnosis, second opinion, and legal review. This is Signal Paper V. Seven more instruments remain.

Request Platform Access → Full White Paper Series

White Paper Series · The Governed Signal