Last week we wrote about the 47.4% of IT teams flying blind on Shadow AI. This week, Comparitech and Dark Reading put a number on the target that’s getting hit hardest because of that gap: healthcare.
In February, a ransomware attack on the University of Mississippi Medical Center (UMMC) disrupted operations for more than two weeks. The hospital is the only Level 1 trauma center in the state. Surgeries were rescheduled. Cancer patients had to be diverted. The CEO called it “the most significant operational challenge in our history.” It was not a one-off. Comparitech, tracking incidents across the healthcare sector through the first half of 2026, found that attacks against healthcare businesses — not the hospitals themselves, but the vendors, billing providers, and clearinghouses behind them — more than doubled year over year. The 110% surge is the headline. The mechanism is the part that should keep a CIO up at night.
Rebecca Moody, head of data research at Comparitech, said the obvious thing out loud: “Through one central hub, you’re targeting multiple healthcare organizations that often have huge databases or were providing third-party services to hundreds of hospitals.”
The German medical-billing company Unimed learned this in March. Unimed processes billing for roughly 95% of Germany’s university hospitals and more than half of its larger clinics. One intrusion. Tens of thousands of patient records out. The same shape played out in February at TriZetto Provider Solutions, where a breach exposed the data of 3.4 million patients across the company’s healthcare-provider customers. QualDerm Partners disclosed in February that a December 2025 attack had compromised 3.1 million patient records.
Notice the pattern. None of those headlines name a hospital. They name the company the hospitals depend on. The attackers aren’t picking locks anymore. They’re picking the lockmaker.
The small-clinic version of this is real. The 40-physician orthopedic group that outsources its billing to a clearinghouse, the regional imaging center that uses a third-party transcription service, the dental practice that hands its claims processing to a SaaS vendor — every one of those is a single breach away from having to notify tens of thousands of patients they never treated. The vendor may not even tell you before the press release goes out.
The other half of the equation is the hospital itself. The FBI’s Internet Crime Complaint Center said in April 2026 that healthcare was the most-attacked critical-infrastructure sector in all of 2025. That is not a new finding. It is the same finding the FBI has published every year for the past decade. What changed in 2026 is the gap between attacker capability and defender capacity stopped closing.
Errol Weiss, chief security officer at the Health Information Sharing and Analysis Center (Health-ISAC), described the structural trap in plain language: legacy medical-device complexity, always-on clinical operations, and heavy third-party dependence, all under the budget pressure of a 60% gross margin business that the government reimburses below cost. Hospital CISOs are taking the threats seriously. They are also losing the hiring war to payers, pharma, and the vendors they already depend on.
The Shadow AI thread from last week lands directly here. When an overworked nurse pastes a medication list into ChatGPT at 2 a.m. to make sense of a discharge summary, and when a billing clerk uploads a denial letter to Claude to draft an appeal, the data has left the building. There is no DLP rule in the world that catches that on a personal phone on the hospital Wi-Fi. Most hospitals have not even tried.

On July 16, 2026, Owen Flowers (18) and Thalha Jubair (20) were each sentenced to five and a half years in a UK court for the 2024 ransomware attack on Transport for London. The Transport for London case was the headline. The healthcare part of the plea is the part that matters for this article.
Flowers was arrested at home on September 6, 2024 — three days after the TfL intrusion ended. The NCA says officers caught him mid-attack on two U.S. healthcare organizations: SSM Health Care Corporation and Sutter Health. Search warrants turned up devices holding proof of all three intrusions. In chats that prosecutors entered into evidence, Flowers acknowledged that locking those systems down “might kill some 90-year-old on life support.” The arrest is what stopped him.
The DOJ’s September 2025 indictment against Jubair, still untested in court, ties the broader Scattered Spider crew to roughly 120 intrusions, at least 47 U.S. victims, and more than $115 million in ransom payments between May 2022 and September 2025. Healthcare was not a side project. It was a quarter of the work. Scattered Spider’s tradecraft — SIM swap, voice phishing, MFA bypass via the carrier — works against hospitals because hospitals answer the phone and accept SMS codes, the same way every other enterprise does.
For a small hospital, a regional clinic network, or a healthcare-adjacent vendor, the work is unglamorous and the order matters.
The 110% surge is not a peak. It is the new floor. Healthcare is the most attacked critical-infrastructure sector in the United States for the fifteenth year running, the ransomware crews have learned that vendors are a multiplier, and the people behind Scattered Spider are in court because they tried it on SSM Health and got caught. Next time they may not get caught. The hospitals that handle the next eighteen months well are not the ones with the best vendor security questionnaire. They are the ones who accepted early that the lockmaker is the target, not the lock.
