1069
Healthcare certificates
5.3% of all BIMI certs
25.9%
High-notability rate
287 of 1069 are major institutions
+43%
2024 → 2025 growth
254 → 363 annual issuances
249
Entrust certs
22.5% — above global avg
13.1%
CMC adoption
145 certs — highest CMC % of any sector

01 · The specific failure

What Happens When a Patient Cannot Identify a Real Hospital Email

Composite scenario — based on documented phishing patterns

A patient receives an email appearing to be from their hospital asking them to confirm an upcoming procedure by clicking a link to verify insurance details. The email uses the hospital logo, the correct address format, the hospital’s standard email template, and a sender name that closely matches the institution’s actual sending domain. The patient clicks the link, enters their insurance number and date of birth, and submits the form.

The real hospital sent no such email. The patient has provided their insurance details to a credential harvesting operation. The hospital’s email domain was not spoofed — an adjacent domain was used, and the hospital’s DMARC policy only protects its own domain, not impersonating domains. The hospital had not deployed BIMI. Their customers had no visual verification signal to distinguish real communications from this type of impersonation.

This scenario type is documented in public breach reports across the US, UK, and Australia. Specific institutional names are not used.

The scenario above is not a theoretical risk. Healthcare is consistently among the top 3 most impersonated sectors in phishing campaign intelligence reports. The combination of high email frequency, high patient trust, and high-value personal data makes healthcare an extremely attractive target for brand impersonation operations. BIMI does not prevent the impersonating email from being sent. It equips patients with a positive verification signal for real communications.

02 · The penetration gap

1069 Certificates Against an Industry Sending Hundreds of Millions of Emails

Healthcare represents 5.3% of all BIMI certificates. Technology holds 25.8%. Banking holds 16.5%. Healthcare’s email volume, relative to those sectors, is not 5.3% of the total — it is substantially larger in many markets. The gap between email volume and BIMI penetration is wider in healthcare than anywhere else in the dataset.

“Banking deployed BIMI as a fraud prevention measure. Technology deployed it as a brand signal. Healthcare has not yet deployed it at scale — not because the risk is lower, but because the procurement path for security infrastructure in healthcare organisations is longer, more committee-driven, and more compliance-filtered than in other sectors. The risk is the same. The response is delayed.”
Healthcare BIMI growth by year — 2021 to 2026 YTD
Growth is consistent — the sector is moving, but from a low base

Healthcare issuances — 2021: 27; 2022: 64; 2023: 163; 2024: 254; 2025: 363; 2026 YTD: 237
The DMARC completion pipeline

Healthcare organisations completing DMARC enforcement in 2026 are the BIMI deployers of 2027. The evidence for this lag-to-follow pattern: banking’s 2022 DMARC adoption wave preceded its 2023–2024 BIMI surge by approximately 12–18 months. Healthcare DMARC enforcement is accelerating, driven by HIPAA guidance updates in the US and NHS cyber security requirements in the UK. The 2027 healthcare BIMI cohort is already in the DMARC pipeline.

03 · Country breakdown

Where Healthcare BIMI Has and Has Not Deployed

CountryHealthcare certs% of country totalContext
US United States57451.8%HIPAA-adjacent deployments; major health systems and insurers leading
IN India696.2%Apollo, Fortis, Manipal group deployments; private hospital chains leading
GB United Kingdom908.1%NHS trust coverage remains low; private sector and pharma leading
DE Germany534.8%Statutory health insurer deployments; hospital groups still early
AU Australia413.7%Private health insurers and major private hospitals; public sector minimal
FR France444%Mutuelle and complementary insurance coverage; public hospitals minimal

The UK stands out. With 90 healthcare certificates from a country with the NHS — one of the world’s largest single healthcare email operations — the public sector gap is stark. NHS trusts are beginning DMARC enforcement journeys driven by NCSC requirements, and that infrastructure will enable BIMI deployment in the 2027–2028 timeframe. The private healthcare and pharmaceutical sectors in the UK are already deploying.

04 · Entrust concern

22.5% Entrust Exposure — Above Average in the Most Sensitive Sector

249 healthcare certificates were issued by Entrust — 22.5% of the sector total, above the global average of 21.9%. For healthcare organisations, an expired BIMI certificate carries a specific operational risk: a period where verified communications from the institution appear visually unverified to patients. In a sector where patients are actively trained to be cautious about healthcare email communications, that gap is not just operational — it is a patient safety concern.

Why Entrust Exited the CA Market

In November 2024, Google announced that Chrome would stop trusting new TLS/SSL certificates issued by Entrust, citing a pattern of compliance failures and mis-issuances spanning several years. Mozilla Firefox followed with an equivalent public distrust decision. Because BIMI’s Verified Mark Certificate (VMC) and Common Mark Certificate (CMC) infrastructure relies on publicly-trusted Certificate Authority roots, this browser distrust effectively ended Entrust’s ability to issue new BIMI certificates. Entrust’s last BIMI certificate was issued in May 2025. As of the July 2026 dataset snapshot, only 0 Entrust BIMI certificates remain active globally — all expire by December 2026 with no renewal path. Existing holders must migrate to DigiCert, GlobalSign, or Sectigo before their certificate’s expiry date to avoid losing their verified inbox logo.

Healthcare IT teams managing BIMI should treat certificate expiry tracking as an operational continuity issue with clinical communication implications. The 90-day migration planning window recommended for all Entrust certificate holders applies with additional urgency here.

FAQ

Healthcare Sector Questions

Does HIPAA require BIMI or DMARC?

HIPAA's Security Rule does not specifically mandate DMARC or BIMI. However, the rule's requirements for technical safeguards protecting electronic protected health information (ePHI) have been interpreted by compliance advisors to include email authentication as a reasonable and appropriate security measure. HHS guidance updated in 2024 referenced DMARC as part of a recommended email security baseline for covered entities. BIMI is not referenced directly in HIPAA guidance, but DMARC enforcement — its prerequisite — is increasingly treated as a HIPAA-aligned security control.

How does BIMI work alongside secure patient email portals?

BIMI and patient portal communications are complementary. Many healthcare organisations have moved sensitive communications to authenticated patient portals — but they still send email notifications and alerts directing patients to those portals. These notification emails are exactly the type of communication that AI-generated phishing replicates. BIMI verifies the notification email's identity in the patient's inbox, making it clear which portal-access emails are genuinely from the healthcare organisation.

Why does healthcare have the highest CMC adoption rate of any sector?

Healthcare's 13.1% CMC rate — highest of any sector — reflects two things. First, a significant number of healthcare organisations are newer entities (specialist clinics, telehealth companies, digital health platforms) that have not yet completed trademark registration processes. CMC's prior-use path makes BIMI accessible to these organisations immediately. Second, some healthcare organisations use trade names or brand marks that are complex to trademark, and CMC provides an interim or permanent path without the trademark requirement.
BIMI deployment for healthcare organisations
VMCcerts supports healthcare organisations with BIMI readiness assessment, HIPAA-aligned deployment, Entrust migration, and CMC/VMC certificate issuance — with appropriate sensitivity to healthcare IT procurement processes.
Cite This Report



VMCcerts Research. (2026). Healthcare Sector BIMI Benchmark 2026 [Research Report]. VMCcerts. https://vmccerts.com/research/healthcare-sector-bimi-benchmark-2026
VMCcerts Research. “Healthcare Sector BIMI Benchmark 2026.” VMCcerts, 2026, https://vmccerts.com/research/healthcare-sector-bimi-benchmark-2026.
@techreport{vmccerts2026HealthcareBIMI,
author = {VMCcerts Research},
title = {Healthcare Sector BIMI Benchmark 2026},
institution = {VMCcerts},
year = {2026},
url = {https://vmccerts.com/research/healthcare-sector-bimi-benchmark-2026},
note = {Dataset: VMCcerts BIMI Dataset v2026.2. Snapshot: 2026-07-02.}
}
TY – RPRT
AU – VMCcerts Research
TI – Healthcare Sector BIMI Benchmark 2026
PY – 2026
PB – VMCcerts
UR – https://vmccerts.com/research/healthcare-sector-bimi-benchmark-2026
ER –