The State of Healthcare Cybersecurity in 2026

The State of Healthcare Cybersecurity in 2026

When I work with healthcare clients, one of the first things I tell them is that I completely understand how difficult it has been to prioritize cybersecurity updates when their values, their mission, and their budgets are entirely focused on serving their patients.

Unfortunately, after a series of ransomware attacks have disrupted hospitals, clinics, long-term care facilities, diagnostic labs, insurers, and pharmacies around the world, it’s increasingly clear that cybercriminals won’t shy away from risking lives to make a profit.

Recent healthcare cybersecurity statistics

Healthcare executive looking at healthcare cybersecurity icons.

Following cybersecurity best practices is fundamental in order to provide reliable care. And these recent statistics from the American Hospital Association paint a grim picture:

  • In 2025 alone, the health care sector suffered 460 ransomware attacks — far more than any other critical infrastructure sector, according to the FBI
  • 574 million individuals have had their health data compromised in hacking incidents reported to HHS since 2020
  • Since 2020, more than 3,200 hacking incidents have been reported to HHS OCR — many of them "double extortion" attacks where criminals demand a ransom both to unlock systems and to prevent publication of stolen patient records

Why is healthcare a top target for cybersecurity threats?

Healthcare isn’t the only tempting target for a hacker. K–12 schools and universities are also popular targets. However, healthcare organizations present a perfect “golden triangle” of opportunity for criminals.

Healthcare organizations typically have:

  1. Highly valuable and private data
  2. Insufficient cybersecurity and IT staff
  3. Built-in catastrophic consequences

Leaked data can be a major breach of patients' privacy. Any IT systems disruptions related to an attack can severely affect patient care and even put patients' lives in danger. Given the severity of the potential impact, victims of attacks at these medical organizations will have a higher motivation to pay ransoms than in many other sectors — and these hackers know that.

What is the biggest threat to the security of healthcare data?

Healthcare executive looking at computer with "system hacked" warning.

Believe it or not, there’s both good and bad news here. The single biggest threat to healthcare data is actually phishing.

Here are the numbers:

  • In a single year, 88% of healthcare workers opened phishing emails
  • Over 90% of all cyberattacks against the healthcare industry are phishing scams

The bad news is that simple phishing scams can lead to far more devastating attacks. More than 90% of successful cyberattacks start with a phishing email. The good news? That means the vast majority of cyberattacks are entirely preventable with proper security awareness training.

The importance of employee training

Smiling group of doctors and nurses.

Currently, only 14% of healthcare organizations provide monthly security awareness training. 28% only offer it sporadically, and 10% provide none at all. That’s not entirely surprising, as regular and engaging cybersecurity training can take time. And that’s often what a hospital’s short-staffed IT department doesn’t have to give.

Therefore, it should come as no surprise that healthcare organization employees also tend to be some of the most phish-prone.

When employees are offered engaging and regular training, it’s been proven to be remarkably effective. However, sending out a memo every now and then isn’t going to cut it. Not all training is the same. Our security awareness training partner, KnowBe4, has been able to reduce employees’ phish-prone percentage (PPP) from 34.3% down to 4.6% over the course of a year.

Additional healthcare cybersecurity best practices

Security awareness training is incredibly important and incredibly effective, but as human beings, we all still will have careless moments from time to time.

If your organization hasn’t kept up with cybersecurity best practices, it’s time to get up to speed. The Cybersecurity and Infrastructure Security Agency (CISA) has put together a variety of helpful cybersecurity resources for healthcare organizations, and I’ve also put together a comprehensive blog on how to use the Center for Internet Security (CIS) cybersecurity controls for organizations of all types and sizes — including midsized to enterprise-scale healthcare organizations.

However, here’s a scaled-down list of must-haves:

  • Require multifactor authentication and strong, unique passwords on all accounts
  • Provide regular security awareness training for all employees
  • Conduct regular security audits
  • Use encryption technology to protect sensitive data
  • Secure and regularly patch any and all networked devices, including medical devices and networked printers
  • Protect your network from internal as well as external threats
  • Don’t overlook physical security
  • Conduct regular security tabletop exercises and update your incident response plans accordingly
  • Foster a culture of security from the top down
  • Perform regular vendor due diligence and end partnerships with vendors that don’t take security seriously

Cybersecurity Advisory Services

In an ideal world, every healthcare organization would have the resources to adopt cybersecurity best practices immediately. But that’s not the world we live in.

Chief information security officers (CISOs) can provide expert advice on which updates to prioritize immediately, which can wait, and which tools and services offer the most ROI. Most healthcare organizations would benefit greatly from this type of advanced IT expertise, but it typically comes with a high price tag. Fortunately, many IT providers, including Marco, are now offering more affordable fractional CIO and CISO services.

However, if you’d like a few quick answers on where your organization might be falling short, I’d recommend using our cyber health tool. It only takes five minutes, and you can get customized recommendations for what to update ASAP as well as what can wait. 

 

 

 

Related Posts

Healthcare Cybersecurity in 2026
Healthcare Cybersecurity in 2026

Cyberattacks and IT incidents have risen sharply in 2025 and 2026, and if current trends are any indication, cybercriminals are becoming bolder and far more dangerous. Just this pa...

5 Common Healthcare Cybersecurity Challenges (And How MDR/SOC Can Help)
5 Common Healthcare Cybersecurity Challenges (And How MDR/SOC Can Help)

In our conversations with healthcare clients, we hear the same five security challenges come up again and again. If you're reading this, you're probably dealing with some version o...

NIST Cybersecurity Framework: Full Overview & Guide
NIST Cybersecurity Framework: Full Overview & Guide

Back in 2013, the federal government directed NIST (National Institute of Standards and Technology) to work with industry leaders to build a common framework for cybersecurity risk...

Urgent PaperCut NG/MF Vulnerability: What You Need to Know
Urgent PaperCut NG/MF Vulnerability: What You Need to Know

If you run PaperCut NG or PaperCut MF, this is the one advisory to stop and read today. In short: PaperCut has confirmed active, real-world exploitation of a vulnerability affectin...

How To Measure Your Cybersecurity Posture Against the NIST Framework
How To Measure Your Cybersecurity Posture Against the NIST Framework

A lot of businesses aren’t sure whether they actually have cybersecurity best practices in place. To be fair, cybersecurity is a moving target, and what was considered sufficient p...

The AI Governance Framework Every Org Needs Before Scaling AI
The AI Governance Framework Every Org Needs Before Scaling AI

AI is showing up in the enterprise faster than most governance programs can keep pace with: forecasting models, customer service bots, code generation tools, decision-support syste...

What Is Vishing?
What Is Vishing?

Vishing is short for “voice phishing.” Like other forms of phishing attacks — including email and text-based scams — the goal is to trick someone into handing over credentials, fin...

Cybersecurity Tips for Small Business Owners
Cybersecurity Tips for Small Business Owners

Too many small business owners still think they’re “too small” to be targeted by a cybercriminal. Unfortunately, 43% of cyberattacks each year are aimed at small businesses.

Why Is MFA Important — and Is Your Business Using It Correctly?
Why Is MFA Important — and Is Your Business Using It Correctly?

Passwords alone haven't been enough to protect business accounts for years. Most IT professionals know this. Most business owners have heard it. And yet credential theft remains on...

What Is Cloud-Native Security?
What Is Cloud-Native Security?

Most businesses didn't set out to build a cloud-native environment. They started using Microsoft 365, added a cloud-based phone system, migrated a few workloads to Azure or AWS, an...