Healthcare organizations hold some of the most sensitive information about Americans. Medical records can contain names, addresses, Social Security numbers, insurance details, diagnoses, prescription information, test results, and financial data.
That makes healthcare an attractive target for cybercriminals.
A healthcare data breach is also different from many other types of cyber incidents. If a retail company’s website goes offline, customers may be temporarily unable to shop. If a hospital’s systems become unavailable, doctors may lose access to medical records, pharmacies may struggle to process prescriptions, and healthcare providers may have difficulty billing insurers.
In other words, healthcare cybersecurity is not only an IT issue. It can become a patient care and patient safety issue.
Recent cyberattacks in the United States have demonstrated just how disruptive these incidents can become. They have also provided important lessons for hospitals, health systems, insurers, medical practices, and other healthcare organizations.
Why Is Healthcare a Major Target for Cyberattacks?
Healthcare organizations manage enormous amounts of valuable data.
Unlike a stolen credit card, which can be canceled and replaced, medical and identity information can remain valuable for years.
Healthcare organizations also operate complex technology environments. A large health system may have electronic health records, billing platforms, medical devices, laboratory systems, pharmacy technology, email platforms, cloud services, patient portals, and hundreds of third-party applications.
Every connection can potentially create another point of risk.
Another challenge is that healthcare cannot simply stop operating.
Hospitals need to provide care 24 hours a day. This makes ransomware particularly dangerous because attackers may attempt to disrupt critical systems and pressure organizations into paying to restore operations.
The U.S. Department of Health and Human Services (HHS) has repeatedly warned that ransomware, destructive malware, and malicious hacking remain significant threats to healthcare organizations.
The Change Healthcare Cyberattack: A Major Warning
One of the clearest examples of healthcare’s cybersecurity risk came from the cyberattack against Change Healthcare in February 2024.
Change Healthcare plays an important role in the U.S. healthcare payment system. Its technology connects healthcare providers, pharmacies, insurers, and other organizations.
When the attack occurred, the effects spread far beyond one company.
Healthcare organizations experienced problems processing claims and payments. Pharmacies and providers also faced disruption, demonstrating how heavily the healthcare system can depend on a small number of technology platforms.
The incident eventually became one of the largest healthcare data breaches ever reported in the United States.
According to information provided to the HHS Office for Civil Rights, Change Healthcare reported in July 2025 that approximately 192.7 million individuals had been impacted.
The scale is difficult to ignore.
But the most important lesson is not simply the number of people affected. The incident showed how a cyberattack against one major healthcare technology company can create problems throughout the healthcare ecosystem.
Lesson 1: Third-Party Risk Is Your Risk
Healthcare organizations increasingly rely on outside companies.
These vendors may provide:
- Billing and claims processing
- Electronic health record technology
- Cloud hosting
- Laboratory services
- Pharmacy technology
- Telehealth platforms
- Medical devices
- Data analytics
- Payment processing
- Patient communication tools
Outsourcing a service does not eliminate cybersecurity risk.
If a critical vendor is attacked, hospitals and clinics that depend on its systems may also face operational disruption.
Healthcare leaders should therefore know which third-party providers have access to sensitive information and which vendors are essential to daily operations.
Vendor security assessments should not be treated as a one-time task during procurement.
Organizations need an ongoing process for reviewing third-party cybersecurity risks, understanding how incidents will be reported, and planning for what will happen if a key vendor suddenly becomes unavailable.
The Ascension Cyberattack: When Digital Problems Affect Physical Care
Another major incident involved Ascension, one of the largest nonprofit health systems in the United States.
In May 2024, Ascension discovered unusual activity on its technology network and later confirmed that it had been the target of a ransomware attack.
The attack disrupted systems used across the health system.
Electronic health records and other technology were affected, forcing healthcare teams in some locations to use alternative processes while systems were restored.
This type of incident highlights a critical reality: hospitals need to be able to provide care even when digital systems are unavailable.
Lesson 2: Every Hospital Needs a Downtime Plan
Modern healthcare depends heavily on technology.
Doctors use electronic health records to review medical histories. Nurses use digital systems to manage care. Pharmacies rely on electronic prescriptions. Laboratories send test results electronically.
But what happens when those systems suddenly stop working?
Healthcare organizations need clear downtime procedures.
Staff should know how to continue essential operations when electronic systems are unavailable. That may include alternative methods for documenting patient information, processing medications, communicating between departments, and managing laboratory requests.
Simply having a written plan is not enough.
Hospitals should regularly test their plans through cybersecurity exercises so employees understand what to do during a real incident.
HHS cybersecurity guidance specifically emphasizes incident planning, preparedness, backup strategies, and recovery procedures.
Lesson 3: Multi-Factor Authentication Is Essential
Passwords alone are no longer enough to protect important healthcare systems.
If an employee’s password is stolen through phishing, malware, or another attack, criminals may be able to access systems using valid credentials.
Multi-factor authentication, commonly called MFA, adds another security step.
For example, a user may need a password plus an authentication app, security key, or another verification method.
HHS lists multi-factor authentication among its essential Healthcare and Public Health Cybersecurity Performance Goals.
Healthcare organizations should especially consider strong MFA for:
- Remote access
- Email accounts
- Administrative accounts
- Cloud applications
- Systems containing sensitive health information
However, MFA should not be viewed as a complete cybersecurity strategy.
It works best when combined with strong password practices, access controls, monitoring, employee training, and other security measures.
Lesson 4: Employees Remain an Important Part of Cybersecurity
Technology can block many attacks, but people remain an important part of an organization’s security.
Cybercriminals frequently use phishing emails and other social engineering methods to convince employees to reveal passwords, open malicious attachments, or visit fake websites.
Healthcare workers are particularly busy.
A doctor, nurse, administrator, or billing employee may receive hundreds of emails while managing urgent responsibilities. Attackers understand this and may create messages that appear to be routine business requests.
Regular cybersecurity training can help employees recognize suspicious activity.
Training should explain:
- How to recognize phishing emails
- Why unknown links can be dangerous
- How to identify unusual login requests
- Why passwords should never be shared
- How to report suspicious activity quickly
Employees should also know exactly where to report a potential incident.
A worker who reports a suspicious email quickly may help prevent a much larger breach.
Lesson 5: Backups Must Actually Work
Ransomware attacks can encrypt files and prevent organizations from accessing important systems.
Reliable backups can make recovery easier.
But simply creating backups is not enough.
Healthcare organizations should make sure their backups are protected, available when needed, and regularly tested.
If attackers can access both the main systems and the backups, recovery becomes much more difficult.
HHS guidance states that HIPAA-regulated organizations must maintain data backup plans as part of their contingency planning requirements.
Organizations should also test their recovery processes.
The first time a hospital attempts to restore critical systems from backups should not be during a major ransomware attack.
Lesson 6: Network Segmentation Can Limit Damage
A large hospital network can contain thousands of connected devices.
If every system is closely connected, an attacker who compromises one area may have opportunities to move deeper into the organization.
Network segmentation helps divide systems into separate sections.
For example, an organization may separate medical devices, administrative systems, guest Wi-Fi, financial systems, and other important technology environments.
HHS includes network segmentation among its enhanced cybersecurity goals.
The purpose is simple: if attackers gain access to one area, security controls can make it harder for them to reach everything else.
This can potentially reduce the impact of a cyberattack.
Lesson 7: Know Every Device and System Connected to Your Network
Healthcare organizations cannot protect technology they do not know exists.
Hospitals may have computers, servers, smartphones, tablets, connected medical devices, printers, cameras, laboratory equipment, and other network-connected systems.
Some devices may also run older software because replacing specialized medical equipment can be expensive.
This creates security challenges.
Organizations should maintain an accurate inventory of their technology assets.
For each important system, security teams should understand:
- What the system does
- What data does it store
- Who has access
- Whether it connects to the internet
- Which software does it use
- When it was last updated
- Whether known vulnerabilities exist
HHS identifies asset inventory as an important enhanced cybersecurity goal for healthcare organizations.
Lesson 8: Patch Known Vulnerabilities Quickly
Cybercriminals often do not need to discover completely new ways to attack an organization.
Sometimes they exploit security weaknesses that are already publicly known.
Software companies regularly release security updates to fix these vulnerabilities.
Healthcare organizations should have processes for identifying vulnerabilities and applying important patches quickly.
This can be complicated in hospitals because certain systems cannot simply be shut down without considering patient care.
Healthcare IT and clinical teams therefore need to work together to decide how critical updates can be safely implemented.
HHS lists mitigating known vulnerabilities as one of its essential cybersecurity goals.
Lesson 9: Limit Access to Sensitive Information
Not every employee needs access to every system.
For example, employees should only have access to the systems and patient records they need to perform their jobs.
Limiting access reduces risk. Organizations should follow the principle of giving users only the level of access they need to perform their jobs.
Administrative or privileged accounts require even stronger protection because they may provide broad access to systems.
HHS also recommends separating standard user accounts from privileged accounts.
When an employee, contractor, or other workforce member leaves the organization, their access should be removed quickly.
Inactive accounts can become an unnecessary security risk.
Lesson 10: Cybersecurity Must Be a Leadership Issue
Cybersecurity cannot be left entirely to the IT department.
A serious healthcare cyberattack can affect:
- Patient care
- Hospital operations
- Revenue
- Regulatory compliance
- Employee productivity
- Patient trust
- Brand reputation
- Vendor relationships
These are executive and board-level concerns. Healthcare leaders should regularly ask about their organization’s biggest cyber risks.
They should understand which systems are most important, whether recovery plans have been tested, which vendors create significant dependencies, and how quickly the organization could respond to an attack.
Cybersecurity investment should also be considered part of operational resilience rather than simply another technology expense.
What Should Healthcare Organizations Do After a Breach?
Even strong cybersecurity programs cannot guarantee that an organization will never experience an attack.
Preparation is therefore essential.
When an incident occurs, organizations need to quickly determine what happened, which systems are affected, whether the attack is still active, and what information may have been accessed.
HHS ransomware guidance emphasizes important response stages (including detection, containment, threat removal, recovery, and post-incident analysis).
Communication is also important. Healthcare organizations may need to communicate with patients, employees, law enforcement, regulators, insurance companies, business partners, and other stakeholders.
HIPAA-regulated organizations may also have specific breach notification responsibilities. A well-prepared organization should know who is responsible for making these decisions before a crisis occurs.
What Can Patients Do After a Healthcare Data Breach?
Patients also have a role in protecting themselves.
If you receive a notice saying your information was involved in a healthcare breach, read it carefully.
The organization should explain what happened, what information may have been affected, and what steps it is taking.
Depending on the type of information involved, patients may want to:
- Change passwords for affected accounts
- Avoid reusing the same password across different services
- Enable multi-factor authentication when available
- Monitor bank and credit card statements
- Review health insurance statements for unfamiliar activity
- Watch for suspicious medical bills
- Be cautious about unexpected emails, calls, or text messages
- Consider credit monitoring or a credit freeze when appropriate
Patients should be particularly careful about phishing after a public breach.
Criminals may use news about an incident to send fake emails or messages pretending to come from the affected healthcare organization.
Cybersecurity Is Becoming Part of Patient Safety
The biggest lesson from recent healthcare data breaches is that cybersecurity and patient care can no longer be separated.
When hospital technology fails, the effects can reach emergency departments, pharmacies, laboratories, billing offices, physicians, and patients.
HHS summarizes this idea clearly through its healthcare cybersecurity initiative: cyber safety is patient safety.
That mindset is important.
Cybersecurity should not be viewed only as protecting databases from hackers. It is also about keeping healthcare services available when patients need them.
Conclusion
Recent healthcare cyberattacks have exposed important weaknesses across the U.S. healthcare system.
The Change Healthcare attack demonstrated how a single technology provider can affect organizations across the country. Incidents involving major health systems have shown how quickly a digital attack can disrupt everyday healthcare operations.
There is no single security tool that can prevent every breach.
Instead, healthcare organizations need multiple layers of protection. Multi-factor authentication, employee training, reliable backups, network segmentation, vulnerability management, strong access controls, vendor oversight, and tested incident response plans should all be part of the strategy.
Healthcare leaders must also recognize that cybersecurity is no longer just the responsibility of the IT team.
Protecting healthcare technology means protecting patient information, maintaining access to care, supporting healthcare workers, and keeping critical services running.
As healthcare becomes connected and dependent on digital technology, cybersecurity will become an important part of delivering safe and reliable care in the United States.








