The healthcare industry has become a prime target for cybercriminals, with attacks surging in the first half of 2026. According to data from technology research firm Comparitech, the number of cyberattacks on healthcare businesses more than doubled compared to the same period last year, while hospitals and clinics saw a modest increase of 14% in attacks.
The reason behind this shift is clear: attackers have recognized that compromising a single provider can grant access to multiple hospitals, says Rebecca Moody, head of data research at Comparitech. By targeting a central hub, such as a medical billing or insurance services company, cybercriminals can gain entry into the systems of numerous healthcare organizations, often with vast databases and third-party relationships.
This strategy allows attackers to maximize their impact while minimizing their efforts. “It puts more pressure on the entity that’s been affected because they’ve then got to answer to all their clients,” Moody explains. “If loads of data has been stolen, it might increase the chances of getting your ransom.” The latest data shows that healthcare continues to be a popular target for cybercriminals, with several high-profile breaches in recent months.
For example, TriZetto Provider Solutions disclosed a data breach affecting 3.4 million patients at its customers’ facilities in February, while QualDerm Partners revealed its own breach from December affecting 3.1 million people. The FBI’s Internet Crime Complaint Center (IC3) also reported that the healthcare industry had been the most attacked critical-infrastructure sector in 2025.
Hospitals are not immune to these attacks, however. In fact, they’re seeing more impersonation and social engineering-driven attacks, which can be particularly difficult to detect. “Hospital CISOs I talk to are taking these threats seriously,” says Errol Weiss, chief security officer at Health-ISAC. “Their No. 1 challenge is having the resources to adequately protect the hospital networks — that means having the budget to recruit and retain experienced cybersecurity talent and acquiring much-needed technology.”
The healthcare sector’s legacy devices, always-on clinical operations, and heavy third-party dependence create a perfect storm of vulnerabilities for attackers. As a result, ransomware gangs are targeting healthcare businesses and their vendors rather than hospitals and doctors’ offices.
The latest Comparitech report found that the number of ransomware attacks on all industries increased by 11% in the past six months compared to the prior period. However, the report also noted that these gangs are increasingly focusing on healthcare businesses and their vendors. Qilin, a notorious ransomware group, has targeted the US healthcare industry, while newer groups, such as The Gentlemen, appear to be focusing more on Europe and other regions.
The consequences of these attacks can be severe. In February, a ransomware attack against the University of Mississippi Medical Center disrupted operations for over two weeks, forcing the hospital to shut down network access across its 35 facilities. As the healthcare industry continues to face an onslaught of cyberattacks, it’s essential that providers and businesses take proactive measures to protect themselves.
This includes investing in robust cybersecurity tools and recruiting experienced talent to manage these threats. It also means being vigilant about patching legacy devices, monitoring for suspicious activity, and educating staff on social engineering tactics. By taking these steps, healthcare organizations can mitigate the risks associated with cyberattacks and ensure that their patients’ sensitive data remains secure.
Source: Dark Reading — 2026-07-10