The State of Healthcare Cybersecurity in 2025

The State of Healthcare Cybersecurity in 2025

When I work with healthcare clients, one of the first things I tell them is that I completely understand how difficult it has been to prioritize cybersecurity updates when their values, their mission, and their budgets are entirely focused on serving their patients. 

Unfortunately, after a series of ransomware attacks have disrupted hospitals, clinics, long-term care facilities, diagnostic labs, insurers, and pharmacies around the world, it’s increasingly clear in 2025 that cybercriminals won’t shy away from risking lives to make a profit. 

Recent Healthcare Cybersecurity Statistics

Healthcare executive looking at healthcare cybersecurity icons.

Following cybersecurity best practices is fundamental in order to provide reliable care. And these recent statistics from the Ponemon Institute paint a grim picture of the catastrophic damage hackers can do to unsecured systems: 

  • 92% of healthcare organizations experienced a cyberattack in the past 12 months
  • The average cost of the single most expensive attack topped $4.7 million
  • 31% said careless users caused data loss and exfiltration

Why Is Healthcare a Top Target for Cybersecurity Threats?

Healthcare isn’t the only tempting target for a hacker. K-12 schools and universities are also popular targets. However, healthcare organizations present a perfect “golden triangle” of opportunity for criminals. 

Healthcare organizations typically have:  

  1. Highly valuable and private data
  2. Insufficient cybersecurity and IT staff
  3. Built-in catastrophic consequences
Leaked data can be a major breach of patients' privacy. Any IT systems disruptions related to an attack can severely affect patient care and even put patients' lives in danger. Given the severity of the potential impact, victims of attacks at these medical organizations will have a higher motivation to pay ransoms than many other sectors — and these hackers know that. 

What Is the Biggest Threat to the Security of Healthcare Data?

Healthcare executive looking at computer with "system hacked" warning.

Believe it or not, there’s both good and bad news here. The single biggest threat to healthcare data is actually phishing

Here are the numbers:

  • Last year alone, 88% of healthcare workers opened phishing emails
  • Over 90% of all cyberattacks against healthcare industries are phishing scams

The bad news is that simple phishing scams can lead to far more devastating attacks. More than 90% of successful cyberattacks start with a phishing email. The good news? That means the vast majority of cyberattacks are entirely preventable with proper security awareness training. 

The Importance of Employee Training

Smiling group of doctors and nurses.

Currently, only 14% of healthcare organizations provide monthly security awareness training. 28% only offer it sporadically, and 10% provide none at all. That’s not entirely surprising, as regular and engaging cybersecurity training can take time. And that’s often time a hospital’s short-staffed IT department doesn’t have to give. 

Therefore, it should come as no surprise that healthcare organization employees also tend to be some of the most phish-prone

When employees are offered engaging and regular training, it’s been proven to be remarkably effective. However, sending out a memo every now and then isn’t going to cut it. Not all training is the same. Our security awareness training partner, KnowBe4, has been able to reduce employees’ phish-prone percentage (PPP) from 34.3% down to 4.6% over the course of a year. 

Additional Healthcare Cybersecurity Best Practices

Security awareness training is incredibly important and incredibly effective, but as human beings, we all still will have careless moments from time to time. 

If your organization hasn’t kept up with cybersecurity best practices, it’s time to get up to speed. The Cybersecurity and Infrastructure Security Agency (CISA) has put together a variety of helpful cybersecurity resources for healthcare organizations, and I’ve also put together a comprehensive blog on how to use the Center for Internet Security (CIS) cybersecurity controls for organizations of all types and sizes — including midsized to enterprise-scale healthcare organizations. 

However, here’s a scaled-down list of must-haves in 2025: 

  • Require multifactor authentication and strong, unique passwords on all accounts
  • Provide regular security awareness training for all employees
  • Conduct regular security audits
  • Use encryption technology to protect sensitive data
  • Secure and regularly patch any and all networked devices, including medical devices and networked printers
  • Protect your network from internal as well as external threats
  • Don’t overlook physical security
  • Conduct regular security tabletop exercises and update your incident response plans accordingly
  • Foster a culture of security from the top down
  • Perform regular vendor due diligence and end partnerships with vendors that don’t take security seriously 

Cybersecurity Advisory Services

In an ideal world, every healthcare organization would have the resources to adopt cybersecurity best practices immediately. But that’s not the world we live in. Chief information security officers (CISOs) can provide expert advice on which updates to prioritize immediately, which can wait, and which tools and services offer the most ROI. Most healthcare organizations would benefit greatly from this type of advanced IT expertise, but it typically comes with a high price tag. Fortunately, many IT providers, including Marco, are now offering fractional CIO and CISO services. 

However, if you’d like a few quick answers on where your organization might be falling short, I’d recommend an online resource my team recently put together. It’s an interactive cybersecurity checklist that you can use online or download, and it clarifies where your current cybersecurity posture is sufficient and where additional investments may be needed. Link below! 

Get Our Cybersecurity Checklist  Download Now

 

Related Posts

Urgent PaperCut NG/MF Vulnerability: What You Need to Know
Urgent PaperCut NG/MF Vulnerability: What You Need to Know

If you run PaperCut NG or PaperCut MF, this is the one advisory to stop and read today. In short: PaperCut has confirmed active, real-world exploitation of a vulnerability affectin...

How To Measure Your Cybersecurity Posture Against the NIST Framework
How To Measure Your Cybersecurity Posture Against the NIST Framework

A lot of businesses aren’t sure whether they actually have cybersecurity best practices in place. To be fair, cybersecurity is a moving target, and what was considered sufficient p...

What Is Vishing?
What Is Vishing?

Vishing is short for “voice phishing.” Like other forms of phishing attacks — including email and text-based scams — the goal is to trick someone into handing over credentials, fin...

Cybersecurity Tips for Small Business Owners
Cybersecurity Tips for Small Business Owners

Too many small business owners still think they’re “too small” to be targeted by a cybercriminal. Unfortunately, 43% of cyberattacks each year are aimed at small businesses.

5 Common Healthcare Cybersecurity Challenges (and How MDR/SOC Can Help)
5 Common Healthcare Cybersecurity Challenges (and How MDR/SOC Can Help)

In our conversations with healthcare clients, we hear the same five security challenges come up again and again. If you're reading this, you're probably dealing with some version o...

Why Is MFA Important — and Is Your Business Using It Correctly?
Why Is MFA Important — and Is Your Business Using It Correctly?

Passwords alone haven't been enough to protect business accounts for years. Most IT professionals know this. Most business owners have heard it. And yet credential theft remains on...

What Is Cloud-Native Security?
What Is Cloud-Native Security?

Most businesses didn't set out to build a cloud-native environment. They started using Microsoft 365, added a cloud-based phone system, migrated a few workloads to Azure or AWS, an...

The Security Strategy AI-Powered Attacks Demand
The Security Strategy AI-Powered Attacks Demand

The threat environment changed. Not gradually. Abruptly. Tools like Anthropic’s Claude Mythos and the latest generation of AI-assisted exploitation capabilities have fundamentally ...

Data Security Governance Best Practices for 2026
Data Security Governance Best Practices for 2026

Data security has reached a breaking point. Sensitive information now lives in more places than ever, sprawled across SaaS applications, cloud drives, on-premises servers, and incr...

Top Cybersecurity Laws and Regulations To Know About in 2026
Top Cybersecurity Laws and Regulations To Know About in 2026

Many companies are now facing the challenges posed by malicious hackers attacking their IT environment. Unfortunately, the fallout continues even after the attack is contained, inc...