Cybercriminals Flock to Healthcare Businesses as Attacks Surge

Cybercriminals are increasingly targeting healthcare businesses, exploiting vulnerabilities to disrupt operations and steal sensitive patient data. In a disturbing trend, attacks on service providers and other healthcare-related companies more than doubled in the first half of 2026 compared to the same period last year.

This surge is not surprising given that compromising a single provider can grant access to multiple hospitals, says Rebecca Moody, head of data research at Comparitech. “Through one central hub, you’re targeting multiple healthcare organizations with huge databases or providing third-party services to hundreds of hospitals,” she explains. This approach puts immense pressure on the affected entity, which must then address the concerns of its clients and potentially face increased ransom demands.

Healthcare providers are not immune to these attacks, but it’s their service providers and vendors that have seen a significant increase in cyberattacks. In February, TriZetto Provider Solutions disclosed a data breach affecting 3.4 million patients at its customers’ facilities, while QualDerm Partners revealed its own breach from December impacting 3.1 million people. These incidents highlight the vulnerability of healthcare businesses to ransomware and other types of attacks.

The FBI’s Internet Crime Complaint Center (IC3) reported that the healthcare industry was the most attacked critical-infrastructure sector in 2025, with hospitals facing a rising number of impersonation and social engineering-driven attacks. Errol Weiss, chief security officer at Health-ISAC, notes that hospital CISOs are taking these threats seriously but struggle to find and patch legacy devices, recruit experienced cybersecurity talent, and acquire necessary technology.

Ransomware gangs have been targeting healthcare businesses, with groups like Qilin focusing on the US industry and newer groups like The Gentlemen targeting Europe and other regions. These attacks often compromise not only patient data but also disrupt hospital operations, causing significant disruptions and financial losses. In February, a ransomware attack against the University of Mississippi Medical Center shut down network access across its 35 facilities.

The surge in healthcare business attacks is concerning given their critical role in providing medical services to patients. It’s essential for these businesses to prioritize cybersecurity, invest in robust security measures, and educate employees on how to spot and prevent social engineering attacks. By taking proactive steps, healthcare businesses can reduce the risk of a devastating cyberattack and protect patient data.

As we navigate this increasingly complex threat landscape, it’s clear that healthcare businesses must be more vigilant than ever. They should take immediate action to strengthen their cybersecurity posture by conducting regular vulnerability assessments, implementing robust security measures, and staying informed about emerging threats. By doing so, they can mitigate the risk of a cyberattack and safeguard patient data.


Source: Dark Reading — 2026-07-10