The frequency of cyberattacks on U.S. healthcare organizations is rising. So is their sophistication, their operational reach and the difficulty of containing them once they begin.
A Fitch Ratings special report published Aug. 18 identifies the forces compounding healthcare’s cyber risk as structural and interlocking. Ransomware remains the dominant and most disruptive threat vector, with groups now using artificial intelligence to accelerate early-stage attacks — crafting more convincing phishing campaigns, scanning networks for unpatched vulnerabilities at speed and running credential-stuffing at scale.
A Ponemon Institute survey sponsored by Proofpoint found that 93% of U.S. healthcare organizations experienced at least one cyberattack in 2025, with 72% reporting that at least one attack disrupted patient care. CrowdStrike’s 2026 Global Threat Report identifies healthcare as one of the top 10 most targeted industries globally.
That frequency is accelerating. Ransomware groups pushed attack volumes higher across the sector in the first half of 2026, with 410 incidents recorded globally — a 14% increase from the prior half. U.S. healthcare organizations accounted for more than half the worldwide total.
The anatomy of a breach has also broadened. Ransomware and system intrusions account for the majority of healthcare incidents, but human error runs a persistent second. According to Verizon’s Data Breach Investigations Report, the most common staff mistakes in 2025 were misdelivery of data to the wrong recipient, loss of physical devices and misconfiguration that inadvertently exposed records without appropriate controls. In fast-paced clinical environments, policy deviations are more likely and the consequences of a single mistake more severe than in most other sectors. Healthcare takes an average of nine months to identify and contain a breach — time during which revenue cycle operations continue to degrade and recovery costs mount.
“Healthcare’s greatest cyber vulnerability is not technology itself, but the sector’s limited tolerance for disruption, where operational outages can immediately affect patient care and organizational performance,” said Fitch Senior Director Gerry Glombicki.
For health system leaders, the challenge is that risk now extends beyond the organization’s own network. A wave of cyberattacks on medical device manufacturers in 2026 has demonstrated that the threat surface runs through hospital operating rooms and supply chains, not just IT departments.
The March 2026 attack on Stryker disrupted manufacturing and forced procedure delays at hospitals across the country when a breach of its internal environment shut down order processing and shipping for nearly three weeks, affecting patient-specific surgical cases. Most incidents were data-related rather than disruptions to device functionality or patient safety but the attack surface that connected medical devices create is real and expanding.
The question of ecosystem understanding has particular force in light of the regulatory gap. The proposed HIPAA Security Rule update — which would make encryption, multi-factor authentication, network segmentation and annual penetration testing mandatory, eliminating the longstanding option to document alternatives for “addressable” controls — has been delayed until July 2027. HHS estimates the proposed update would cost the sector $33 billion over five years, and 57 hospital and health system leaders have asked HHS to rescind the proposal entirely, citing financial burden and implementation timelines. Healthcare organizations are operating under a compliance framework written in 2003, applied to a threat environment that didn’t exist then.
Sunil Dadlani, executive vice president, chief information and digital transformation officer at Atlantic Health System in Morristown, N.J., has argued the governance dimension of technology investment is as consequential as the technology itself.
“Momentum without governance is chaos and fragmentation, whereas governance without momentum is stagnation,” Mr. Dadlani said during a “Becker’s Healthcare Podcast” episode.
At the Becker's 11th Annual IT + Revenue Cycle Conference: The Future of AI & Digital Health, taking place September 14–17 in Chicago, healthcare executives and digital leaders from across the country will come together to explore how AI, interoperability, cybersecurity, and revenue cycle innovation are transforming care delivery, strengthening financial performance, and driving the next era of digital health. Apply for complimentary registration now.