1 min read
Importance of Cybersecurity in Healthcare: Top 11 Reasons
💡Cybersecurity in healthcare protects two things at once: patient records and the ability to see patients at all. When ransomware hits, the...
16 min read
Alvin Amoroso : Updated on August 27, 2026
Assured Imaging paid $375,000 in April 2026 to settle with federal regulators. The ransomware attack behind it exposed records for 244,813 patients. Investigators asked for the security risk analysis. No evidence turned up that one had ever been done.
Three more settlements landed the same day. Together the four totaled $1,165,000 and covered roughly 427,000 patients. Each cited the same missing document.
Most breaches that end in a federal penalty start with maintenance nobody was assigned to finish. That is the argument this piece makes, and the enforcement record backs it up.
How attackers get in has shifted. Verizon found unpatched software passed stolen passwords as the top entry point in 2026, a first in 19 years of its reporting. Phishing moved off email, too. IBM put voice and SMS phishing at 17% of breaches, the most common single route into a network.
Vendors carry more weight now. Third parties were involved in 32% of the healthcare breaches Verizon tracked for 2026. Your billing service and your scheduling platform are part of your exposure, whether or not you count them that way.
Most advice on this subject assumes a hospital with a security team, a CISO, and a budget line for penetration testing. A 12 provider clinic has none of that. It still holds the same patient records. It faces the same attackers and answers to the same regulator.
Ahead: the nine threats worth planning for, five defenses that work at any size, the rules that apply, and what the penalties currently cost.
Attackers go after medical records because those records pay. Protected Health Information (PHI) puts a Social Security number, an insurance ID, a birth date, and a full medical history in one file.
IBM's 2026 Cost of a Data Breach Report names that patient data as the reason the sector keeps getting hit, since it feeds identity theft and insurance fraud.
Fraud losses are one cost. Care delays are the other, and they land on patients first.
Ascension took its systems offline on May 8, 2024, after a Black Basta ransomware attack. Its EHR and the MyChart patient portal went dark across 140 hospitals in 19 states. Clinical staff worked on paper for weeks while the health system rebuilt.
Here's what that looked like on the floor:
| System that went down | What staff did instead |
|---|---|
| Electronic health record | Handwritten charting and paper orders |
| MyChart patient portal | Phone calls to reach patients |
| E-prescribing | Paper scripts, entered at the pharmacy with a manual override and no second safety check |
| Test and procedure ordering | Elective procedures postponed; stat labs that ran 30 to 60 minutes took hours |
| Emergency intake | Ambulances diverted to other hospitals |
Nurses told CNN the manual workarounds put patients at risk. Ascension later confirmed the attack exposed data belonging to 5,599,699 people.
Delayed procedures, medication errors, and rerouted ambulances all trace back to the same locked systems. Continuity of care runs on the software attackers encrypt first.
Healthcare has topped every other industry for breach costs for more than a decade. IBM's 2026 report puts the average healthcare data breach at $6.6 million. US organizations across all sectors averaged $11.5 million, the highest of any country.
Those totals come from four places:
| Cost area | What it looks like |
|---|---|
| Regulatory fines | HIPAA penalties from the HHS Office for Civil Rights, sized to how the breach happened and what was in place beforehand |
| Recovery and remediation | Forensic investigation, system rebuilds, and the security work that should have been funded earlier |
| Legal fees and lawsuits | Patient class actions, now routine after a large exposure |
| Reputational damage | Patients who leave, and referral partners who stop sending |
A 12-provider clinic won't see a $6.6 million bill. It will still pay for forensics, breach notification letters, credit monitoring for affected patients, and legal review. Those costs arrive whether or not the practice can absorb them.
Ascension posted a $1.1 billion net loss in fiscal 2024 and said the attack significantly held back its financial recovery that year.
Verizon tracked 1,492 healthcare security incidents for its 2026 Data Breach Investigations Report, including 1,438 confirmed data disclosures. The root causes are not evenly split, and the ranking has shifted.
| How healthcare breaches started (Verizon 2026 DBIR) | Share |
|---|---|
| Exploiting an unpatched vulnerability | 20% |
| Phishing | 14% |
| Stolen credentials | 11% |
| Employee error | 11% |
| Involved a third party at some point | 32% |
Nine threats account for most of what practices deal with in 2026.
Ransomware showed up in 48% of all breaches Verizon analyzed for 2026, up from 44% the year before. The software locks a provider's files and the attackers demand payment, usually in cryptocurrency, to unlock them. Downtime puts patients at risk, which is why medical targets get picked.
Payment behavior has changed. Of victims in Verizon's dataset, 69% refused to pay, up from 65%. The median ransom actually paid fell to $139,875.
Attackers adjusted by threatening to leak stolen files publicly, which makes clean backups less of a complete answer than they used to be.
Attackers have moved off email. IBM's 2026 report found voice and SMS phishing was the single most common way into a network, appearing in 17% of breaches, with an average cost of $5.9 million. Verizon measured a 40% jump in the success rate of mobile social engineering.
Spear phishing narrows the aim. Someone researches a specific biller or office manager, then writes a message that fits a conversation already in progress. Verizon calls this pretexting, and it now often impersonates a vendor, an IT contact, or a physician inside an existing thread.
Employee error caused 11% of healthcare breaches in Verizon's 2026 count. IBM's healthcare figures put human error at 13%, with IT failures at 26% and deliberate attacks at 59%.
Most insider incidents are ordinary mistakes: a laptop left in a car, a reused password, a chart sent to the wrong fax number, a phishing link clicked between patients. A smaller share involves staff who take data on purpose.
Verizon's analysts note that admins and developers cause errors with a far bigger blast radius than front-office staff, since one misconfigured storage bucket exposes more records than any misaddressed email.

Connected devices now sit throughout clinical space: infusion pumps, heart monitors, imaging equipment, patient wearables. Many run software that can't be patched on a normal schedule, and some run operating systems the maker stopped supporting years ago.
Since 2023, the FDA has required makers of connected "cyber devices" to submit a software bill of materials and a patching plan under Section 524B of the Food, Drug, and Cosmetic Act.
Older equipment already installed carries no such guarantee. Each unpatched device is a way onto the same network that holds the EHR.
A denial-of-service attack floods a network or website with traffic until real users can't get through. For a practice, that means the patient portal stops loading, online scheduling goes down, and internal messaging stalls.
No data leaves the building in a pure flood attack, so it usually doesn't trigger HIPAA breach notification. It still falls under the HIPAA Security Rule, which covers the availability of electronic PHI, not just its privacy. Attackers also use these floods as cover while running a quieter intrusion elsewhere.
Some attackers want the records themselves. They get in, find where PHI lives, and copy out as much as they can before anyone notices. The files get sold or used for insurance fraud, tax fraud, and blackmail.
Detection is the weak point. IBM found healthcare takes longer than any other sector to identify and contain a breach. Verizon reports that only 26% of critical vulnerabilities were fully fixed in 2025, down from 38% the prior year, with a median resolution time of 43 days. That gap is the working window.
Infostealer malware sits quietly on a machine and harvests saved passwords, browser sessions, and login tokens. Those credentials get sold, and the buyer is often a ransomware crew. Verizon's 2026 report traces this pipeline directly, from stolen credential to encrypted network.
Generative AI has lowered the effort involved. Verizon found the median attacker now uses AI across roughly 15 different steps of an attack, including writing malware. IBM measured that one in four malicious breaches involved AI on the attacker's side, a 56% increase, at an average cost of $6 million.
Practices keep moving records, backups, and applications to hosted platforms. Misconfigured storage and weak access rules expose data without anyone breaking in.
Unapproved AI tools are the newer problem. Verizon found employee use of shadow AI tripled to 45%, meaning staff pasting data into tools nobody vetted.
IBM reported that 92% of organizations hit by an AI-related breach had no proper AI access controls. A practice can't sign a business associate agreement with a tool it doesn't know its staff are using.
Third parties were involved in 32% of healthcare breaches Verizon analyzed for 2026. Across all industries, that figure hit 48%, a 60% jump in a single year. Attackers target the billing service, the transcription vendor, or the scheduling platform, then use that access to reach the practice.
Scale is the difference. A single business associate breach at Conduent exposed more than 25 million records in 2025, dwarfing what any one clinic could lose on its own.
HHS proposed an update to the HIPAA Security Rule in early 2025 that would add specific vendor oversight duties for covered entities, which is a direct response to this pattern in cybersecurity healthcare.
No single control stops a modern attack. These five hold up whether a practice runs 3 providers or 300.
Zero Trust works on one rule: never trust, always verify. No user and no device gets access by default, whether the request comes from the front desk or from outside the building. Every request is checked, approved, and encrypted before anything opens.
Segmentation is the part that pays off during an attack. When the billing workstation, the imaging equipment, and the EHR server sit on separate network segments, an attacker who lands on one can't walk to the others.
HHS proposed an update to the HIPAA Security Rule on January 6, 2025 that would make multi-factor authentication, encryption of ePHI, and network segmentation explicit requirements.
Every device on the network counts as an endpoint: the check-in tablet, the provider's laptop, the billing PC, the connected ultrasound.
Endpoint Detection and Response tools watch those machines for behavior that doesn't fit, like a workstation suddenly reading thousands of files at 2 a.m. Extended Detection and Response pulls in signals from email, cloud apps, and servers so the pieces connect.
Speed is what these tools buy. IBM found healthcare takes 279 days on average to identify and contain a breach, longer than any other sector.
Verizon reports that only 26% of critical vulnerabilities were fully fixed in 2025, down from 38% the year before, with a median resolution time of 43 days. Detection tools shorten a window that most practices are currently leaving wide open.
A security risk analysis has been required since 2003 under 45 CFR 164.308(a)(1)(ii)(A). It means writing down every place ePHI lives, what could go wrong, and how likely each risk is.
OCR launched its Risk Analysis Initiative in late 2024 because investigators kept finding the same gap after every ransomware breach. By April 23, 2026, the agency had closed 13 investigations under the initiative and 19 ransomware investigations overall.
| Settlement | Amount | What OCR found |
|---|---|---|
| Assured Imaging (April 2026) | $375,000 | No evidence a risk analysis had ever been completed; 244,813 patients affected; missed the 60-day notification deadline |
| Regional Women's Health Group (April 2026) | $320,000 | Ransomware breach affecting 37,989 individuals |
| Top of the World Ranch (February 2026) | $103,000 | Compromised employee email account |
| MMG Fusion (March 2026) | $10,000 | Business associate breach; PHI of 15 million individuals posted to the dark web |
The four April settlements totaled $1,165,000 and covered roughly 427,000 patients. Each entity also accepted two years of OCR monitoring.
OCR Director Paula M. Stannard has said the initiative expands into risk management in 2026. A filed-away analysis from 2021 won't satisfy that. The agency now asks what you did about what you found.
Penetration testing and vulnerability scanning fit here too. Scanning finds known flaws in software; a penetration test hires someone to try the attack for real.
Verizon found people involved in 62% of breaches in its 2026 report. That's the largest single factor in cybersecurity in healthcare, and it's the cheapest one to address.
Annual slide decks don't move that number. A working program covers four things:
Train front desk and billing hardest. Those two seats handle the most inbound contact from strangers.
An incident response plan says who does what in the first hour. It names the person who calls the attorney, the person who calls the cyber insurer, the person who disconnects affected machines, and the person who tells patients.
Downtime procedures belong in the same document. Ascension ran on paper for weeks in 2024. IBM found most breached organizations took more than 100 days to recover fully.
Your plan should answer how appointments get scheduled, how prescriptions get written, and how patients get reached when the EHR is unavailable.
HIPAA gives you 60 days to notify affected individuals. Assured Imaging's settlement cited that deadline directly.
Test the plan with a tabletop exercise at least once a year. Walk the whole team through a scenario out loud, then fix what the exercise exposes.

Three sets of rules can apply to a US practice at once. HIPAA always does. HITRUST is optional but increasingly asked for. GDPR reaches further than most practices expect.
A fourth arrived this year. OCR began enforcing 42 CFR Part 2 on February 16, 2026, which adds separate protections for substance use disorder records.
The Security Rule applies to covered entities and their business associates. It sorts requirements into three groups:
Administrative safeguards cover how security gets managed: the risk analysis, staff training, sanctions for policy violations, and a contingency plan for when systems go down.
Physical safeguards cover the building and the hardware: locked server closets, screens angled away from the waiting room, a process for wiping devices before disposal.
Technical safeguards cover the software: who can open which record, encryption of ePHI, and audit logs showing who looked at what.
Penalties scale with how much you knew and whether you fixed it. HHS published updated amounts in the Federal Register on January 28, 2026:
| Tier | When it applies | Per violation |
|---|---|---|
| 1 | Didn't know, couldn't reasonably have known | $145 to $73,011 |
| 2 | Reasonable cause, not willful neglect | $1,461 to $73,011 |
| 3 | Willful neglect, corrected within 30 days | $14,602 to $73,011 |
| 4 | Willful neglect, not corrected | $73,011 to $2,190,294 |
The statutory annual cap is $2,190,294 for repeated violations of the same requirement. Under a 2019 enforcement notice still in effect, OCR applies lower annual caps to the first three tiers: $36,505, $146,053, and $365,052.
One provision works in your favor. Public Law 116-321 requires HHS to consider whether you had recognized security practices in place for the previous 12 months when it sets a penalty or decides on remedies.
Following a framework like NIST or the 405(d) practices won't make you immune. It can reduce what you pay.
HITRUST built the Common Security Framework so one assessment answers several standards at once. Its controls map across HIPAA, NIST, ISO, and others, which spares you from proving the same thing four different ways.
Three assessment levels exist. The e1 covers essential cybersecurity hygiene, the i1 covers a broader set of implemented controls, and the r2 is the full risk-based certification. Most small practices never need the r2.
Where certification matters is contracts. Health plans, hospital networks, and larger partners increasingly ask vendors and affiliated groups for a HITRUST report before signing. If you're bidding for that kind of work, the assessment stops being optional.
GDPR follows the person, not the passport. It applies when you process data about someone located in the European Union, which can include an American patient living in Berlin or a traveler seen while abroad. Citizenship isn't the test.
The rules cover consent, what you may do with the data, and how fast you report a breach. GDPR gives you 72 hours to notify the supervisory authority, against HIPAA's 60 days for notifying individuals.
Fines run higher too. The ceiling is €20 million or 4% of worldwide annual revenue, whichever is larger.
For most US practices, GDPR never comes up. For any group running telehealth across borders or treating patients who live overseas, it's worth a conversation with counsel before it does.
The Bureau of Labor Statistics projects 29% employment growth for information security analysts between 2024 and 2034, roughly seven times the average across all occupations.
ISC2 puts the global gap at 4.8 million unfilled security positions and ranks healthcare among the sectors with the widest skills gaps.
That shortage costs money. IBM found organizations with severe security staffing shortages averaged $5.74 million per breach, about $1.76 million more than better-staffed peers.
If you run a practice rather than a security team, read this as a hiring guide. It tells you what to look for in a contractor or a first security hire.
Four things separate a healthcare security hire from a general IT one.
Technical proficiency covers network security, cloud security, identity and access management, and encryption.
Regulatory knowledge means working familiarity with HIPAA, HITRUST, and the rules that apply to your setting, including 42 CFR Part 2 for substance use disorder records.
Analytical skill shows up in reading threat intelligence, running a risk analysis, and investigating an incident without jumping to conclusions.
Communication is the one most candidates undersell. Explaining a segmentation project to a physician who wants to know why the imaging cart moved networks is the job, not a side task.
One note on certifications. ISC2 is retiring the HCISPP, the healthcare-specific credential, which goes inactive on December 1, 2026. Candidates now build a healthcare path from general credentials like the CISSP plus documented experience in clinical settings.
| Role | What it covers | Typical pay |
|---|---|---|
| Chief Information Security Officer | Sets the whole security program, reports to the board, owns vendor oversight and incident readiness | Glassdoor's 2026 median sits near $237,000, higher at large systems with bonus and equity |
| Security Analyst | Watches the network, spots problems, responds when something fires | BLS put the 2024 median for information security analysts at $120,360 |
| Compliance Officer | Keeps the risk analysis current, tracks business associate agreements, prepares for OCR requests | Varies widely; often blended with practice management in smaller groups |
| Medical Device Security Specialist | Inventories connected equipment, handles segmentation for devices that can't be patched | A newer specialty, priced above general analyst work |
Two forces are reshaping what practices have to defend: AI showing up on both sides of the attack, and telehealth rules that keep changing by the year.
AI and machine learning tools watch network traffic and user behavior for patterns that don't fit.
A billing account that suddenly opens 4,000 charts, a login from a country you don't serve, a workstation talking to a server it never touched before. Those signals get flagged before anyone reports a problem.
The savings are measurable. Ponemon's research for IBM found organizations making extensive use of AI and automation in security saved around $1.9 million per breach and cut response time by roughly 80 days.
Attackers have the same tools:
| Attackers using AI | Defenders using AI |
|---|---|
| One in four malicious breaches were AI-enabled in IBM's 2026 data, up 56% year over year | 85% of breached organizations plan to increase spending on security tools and governance |
| Those breaches averaged $6 million, about $1 million above the global average | Three quarters plan to deploy AI agents for alert triage, vulnerability management, and scanning |
| Verizon found the median attacker uses AI across roughly 15 steps of an attack | Faster detection is the main lever, since breaches over 200 days cost far more |
One caution before buying anything. Verizon found employee use of unapproved AI tools tripled to 45%, and IBM reported 92% of organizations hit by an AI-related breach had no access controls on those tools. Write the policy before you write the check.
Remote visits move PHI across networks you don't control. The patient's home Wi-Fi, a phone on public internet at a coffee shop, a provider working from a spare bedroom. Each one sits outside your firewall.
Identity verification is the harder problem. Confirming that the person on the video call is the patient, and that the prescriber is who the screen says, takes work that an in-person check does automatically.
|
Regulation keeps moving under all of it. DEA and HHS issued a fourth temporary extension effective January 1 through December 31, 2026, letting DEA-registered practitioners prescribe Schedule II through V medications by audio-video without a prior in-person visit. Audio-only remains allowed for Schedule III through V medications treating opioid use disorder. |
These deadlines have real consequences. When Medicare telehealth flexibilities lapsed for 41 days starting September 30, 2025, Brown University researchers found fee-for-service telemedicine visits dropped 24% in the first 17 days, and 40% in some states.
The DEA's proposed Special Registration rule would build identity verification, clinician credentialing, prescription drug monitoring checks, and record retention into the requirements themselves. The agency has signaled a final rule for November 2026. Practices running telehealth should treat identity checks and encrypted connections as things to have working now, not after the rule lands.
Read OCR's 2026 settlements and the pattern isn't clever attackers. It's the risk analysis nobody finished. The vulnerability that sat open for 43 days. The vendor nobody checked.
Resilience means your practice keeps seeing patients when something breaks. Separate network segments, so a compromised imaging cart can't reach the EHR.
A downtime plan that answers how prescriptions get written and how patients get reached. Staff who flag a strange text in five minutes instead of five days.
Two moves return the most for the least money: a current, documented risk analysis, and multi-factor authentication on the EHR, email, and remote access. Neither needs a security team. Both are the first things OCR asks about.
Then look outward. Third parties were involved in 32% of the healthcare breaches Verizon tracked for 2026.
Every tool touching patient data — scheduling, billing, messaging, intake forms — needs a signed business associate agreement and a clear answer about how it protects PHI.
Patient communication is one of those tools, and it's usually the one handling the most inbound contact from outside your walls.
Curogram runs two-way texting, telehealth visits, digital intake, and text-to-pay under HIPAA, connected to the EHR you already use. Encrypted in transit and at rest, access controlled by role, covered by a BAA.
Request a demo today and we'll walk through where PHI moves in your current patient communication setup.
Cybersecurity in healthcare refers to the comprehensive set of strategies, technologies, and practices used to protect healthcare organizations' electronic information, computer networks, and medical devices from unauthorized access, attack, or damage. Its primary goals are to ensure the confidentiality, integrity, and availability of patient data and clinical systems, thereby safeguarding patient safety and maintaining trust.
While many general cybersecurity certifications are valuable, some are particularly respected in the healthcare space. The Certified Information Systems Security Professional (CISSP) is often considered the gold standard for security leaders. However, for those focusing specifically on healthcare, the Certified in Healthcare Privacy and Security (CHPS) offered by AHIMA is highly relevant. Other key certifications include the Certified Information Security Manager (CISM) for management and the CompTIA Security+ for foundational knowledge.
While all functions are interconnected and vital, the most essential function of healthcare cybersecurity is arguably risk management to ensure business and clinical continuity. This encompasses protecting patient data (confidentiality and integrity) and ensuring that systems are always running (availability). Without system availability, patient care can halt, leading to direct harm. Therefore, the ultimate function is to protect the organization's core mission: delivering safe and effective patient care without interruption.
While many attacks have been devastating, one of the most significant and widely discussed incidents was the 2024 Change Healthcare ransomware attack. The attack was carried out by the BlackCat/ALPHV ransomware group and disrupted medical claims processing and payments across the entire U.S. healthcare system for weeks. It impacted countless pharmacies, hospitals, and clinics, highlighting the systemic risk posed by attacks on critical third-party vendors. The incident served as a stark wake-up call, demonstrating how a single point of failure could have a cascading effect on national healthcare infrastructure. Another historically significant attack was the 2017 WannaCry ransomware outbreak, which crippled parts of the UK's National Health Service (NHS), leading to the cancellation of thousands of appointments and operations.
Start with the two items OCR asks about first: a current, documented risk analysis and multi-factor authentication on your EHR, email, and remote access. Neither requires headcount. Next, segment your network so a compromised imaging cart or scanner can't reach patient records. Then audit business associate agreements, since third parties were involved in 32% of the healthcare breaches Verizon tracked for 2026.
1 min read
💡Cybersecurity in healthcare protects two things at once: patient records and the ability to see patients at all. When ransomware hits, the...
1 min read
💡 HIPAA is not enforced by one agency. The Office for Civil Rights (OCR), part of the U.S. Department of Health and Human Services, handles the...
1 min read
💡 You can text patient lab results, but standard SMS is not HIPAA compliant on its own. HIPAA never banned texting. It requires that the delivery...