Home / Blog / Cybersecurity
March 13, 2026 by Brandon Agostinelli
In the United States, healthcare continues to sit at the bullseye of cybercrime. The FBI’s 2024 Internet Crime Report and the American Hospital Association’s analysis of that report show that the health sector suffered more reported cyberthreats than any other critical infrastructure vertical that year, totaling 444 incidents that combined ransomware with data theft[1]. At the same time, ransomware attacks against U.S. critical infrastructure rose around 9% year‑over‑year, and total cybercrime losses climbed to $16.6 billion[2].
Zooming out, the 2025 Verizon Data Breach Investigations Report explains why attackers keep helping themselves to initial access. Third‑party involvement in breaches doubled to 30% year over year[3]. Exploitation of vulnerabilities as an initial access vector jumped 34% to account for 20% of breaches, nearly overtaking credential abuse. Additionally, ransomware appeared in 44% of breaches (a 37% increase)[4]. Attackers are targeting the healthcare ecosystem at its softest points: vendors, perimeter devices, and time‑pressed staff.
Two incidents from 2024 turned these statistics into national headlines. First, the Change Healthcare ransomware attack disrupted claims, eligibility, and prescription processing on an unprecedented scale[5]. Every hospital in the country felt downstream impact as revenue cycles faltered and pharmacies fell back to manual workarounds. Public disclosures and testimony highlighted the absence of multi‑factor authentication (MFA) on a remote portal that attackers abused. Second, Ascension’s ransomware event forced Emergency Medical Services diversions and downtime protocols across a 140‑hospital system. In the months following the incident, the organization confirmed that approximately 5.6 million individuals were affected[6]. Together, these crises revealed just how concentrated and interconnected risk has become in U.S. healthcare.
The National Institute of Standard and Technology Cybersecurity Framework (CSF) 2.0 introduced the new Govern function and strengthened guidance for supply‑chain risk management. These are two areas that hospital boards and executives must own. Implementing practices commensurate with CSF 2.0 is a pragmatic way to align strategy, budget, and daily controls to the threats actually hitting healthcare.
In addition, federal regulators are preparing the first major upgrade to the HIPAA Security Rule since 2013, driven by the sharp rise in cyberattacks, large‑scale breaches, and operational disruptions across healthcare. The proposal, released by the United States Department of Health & Human Services and Office for Civil Rights (OCR) in late 2024 and published as a formal rulemaking notice in January 2025, seeks to raise the cybersecurity floor for all HIPAA‑regulated organizations. At a high level, the proposed rule would require hospitals and business associates to:
The Notice of Proposed Rulemaking eliminates the long‑standing distinction between required and addressable implementation specifications[10]. Under the proposal, all specifications become mandatory, unless a narrow exception applies. This is one of the most significant shifts in HIPAA since 2013.
Healthcare’s targeting isn’t about hype; it’s about economics (data value, extortion leverage), exposure (edge flaws and vendors), and consequences (patient care). But the sector is improving: more attacks are blocked before encryption, ransom payments are down, and recovery times are shortening. This serves as evidence that disciplined programs work. Make 2026 the year that your organization moves from compliance‑centric to outcome‑driven security. Achieving this looks like board‑owned governance, faster edge patching, identity management that clinicians can live with, segmented networks, resilient recovery, and real vendor accountability. The result is not just better information security; it’s safer patient care.
[1] https://www.aha.org/news/headline/2025-05-12-report-health-care-had-most-reported-cyberthreats-2024
[2] https://cyberscoop.com/fbi-ic3-cybercrime-report-2024-key-statistics-trends/
[3] https://www.hipaajournal.com/verizon-dbir-2025/
[4] See above.
[5] https://www.aha.org/system/files/media/file/2025/02/Change-Healthcare-Cyberattack-Underscores-Urgent-Need-to-Strengthen-Cyber-Preparedness.pdf
[6] https://www.hipaajournal.com/ascension-cyberattack-2024/
[7] The accumulated cost and risk of using outdated, unpatched, or poorly integrated IT systems (like legacy EHRs) instead of modernizing them.
[8] https://www.verizon.com/business/resources/Tea/reports/2025-dbir-data-breach-investigations-report.pdf
[9] https://www.sophos.com/en-us/blog/the-state-of-ransomware-in-healthcare-2025
[10] https://www.hhs.gov/hipaa/for-professionals/security/hipaa-security-rule-nprm/index.html
[11] Unapproved, unmanaged, or hidden resources, systems, or data that operate outside the control of an organization’s central IT, security, or administration departments.