Last week we wrote about the 47.4% of IT teams flying blind on Shadow AI. This week, Comparitech and Dark Reading put a number on the target that’s getting hit hardest because of that gap: healthcare.
In February, a ransomware attack on the University of Mississippi Medical Center (UMMC) disrupted operations for more than two weeks. The hospital is the only Level 1 trauma center in the state. Surgeries were rescheduled. Cancer patients had to be diverted. The CEO called it “the most significant operational challenge in our history.” It was not a one-off. Comparitech, tracking incidents across the healthcare sector through the first half of 2026, found that attacks against healthcare businesses — not the hospitals themselves, but the vendors, billing providers, and clearinghouses behind them — more than doubled year over year. The 110% surge is the headline. The mechanism is the part that should keep a CIO up at night.
Why the Vendor Becomes the Bullseye
Rebecca Moody, head of data research at Comparitech, said the obvious thing out loud: “Through one central hub, you’re targeting multiple healthcare organizations that often have huge databases or were providing third-party services to hundreds of hospitals.”
The German medical-billing company Unimed learned this in March. Unimed processes billing for roughly 95% of Germany’s university hospitals and more than half of its larger clinics. One intrusion. Tens of thousands of patient records out. The same shape played out in February at TriZetto Provider Solutions, where a breach exposed the data of 3.4 million patients across the company’s healthcare-provider customers. QualDerm Partners disclosed in February that a December 2025 attack had compromised 3.1 million patient records.
Notice the pattern. None of those headlines name a hospital. They name the company the hospitals depend on. The attackers aren’t picking locks anymore. They’re picking the lockmaker.
The small-clinic version of this is real. The 40-physician orthopedic group that outsources its billing to a clearinghouse, the regional imaging center that uses a third-party transcription service, the dental practice that hands its claims processing to a SaaS vendor — every one of those is a single breach away from having to notify tens of thousands of patients they never treated. The vendor may not even tell you before the press release goes out.
Legacy, Always-On, and Underfunded
The other half of the equation is the hospital itself. The FBI’s Internet Crime Complaint Center said in April 2026 that healthcare was the most-attacked critical-infrastructure sector in all of 2025. That is not a new finding. It is the same finding the FBI has published every year for the past decade. What changed in 2026 is the gap between attacker capability and defender capacity stopped closing.
Errol Weiss, chief security officer at the Health Information Sharing and Analysis Center (Health-ISAC), described the structural trap in plain language: legacy medical-device complexity, always-on clinical operations, and heavy third-party dependence, all under the budget pressure of a 60% gross margin business that the government reimburses below cost. Hospital CISOs are taking the threats seriously. They are also losing the hiring war to payers, pharma, and the vendors they already depend on.
The Shadow AI thread from last week lands directly here. When an overworked nurse pastes a medication list into ChatGPT at 2 a.m. to make sense of a discharge summary, and when a billing clerk uploads a denial letter to Claude to draft an appeal, the data has left the building. There is no DLP rule in the world that catches that on a personal phone on the hospital Wi-Fi. Most hospitals have not even tried.

Scattered Spider’s Healthcare Trail
On July 16, 2026, Owen Flowers (18) and Thalha Jubair (20) were each sentenced to five and a half years in a UK court for the 2024 ransomware attack on Transport for London. The Transport for London case was the headline. The healthcare part of the plea is the part that matters for this article.
Flowers was arrested at home on September 6, 2024 — three days after the TfL intrusion ended. The NCA says officers caught him mid-attack on two U.S. healthcare organizations: SSM Health Care Corporation and Sutter Health. Search warrants turned up devices holding proof of all three intrusions. In chats that prosecutors entered into evidence, Flowers acknowledged that locking those systems down “might kill some 90-year-old on life support.” The arrest is what stopped him.
The DOJ’s September 2025 indictment against Jubair, still untested in court, ties the broader Scattered Spider crew to roughly 120 intrusions, at least 47 U.S. victims, and more than $115 million in ransom payments between May 2022 and September 2025. Healthcare was not a side project. It was a quarter of the work. Scattered Spider’s tradecraft — SIM swap, voice phishing, MFA bypass via the carrier — works against hospitals because hospitals answer the phone and accept SMS codes, the same way every other enterprise does.
What Actually Moves the Needle
For a small hospital, a regional clinic network, or a healthcare-adjacent vendor, the work is unglamorous and the order matters.
- Map your third parties before your attackers do. You cannot manage a risk you have not named. Get a written list of every vendor with read or write access to patient data, and what data classification each one handles. This is the actual HIPAA Security Rule Risk Analysis requirement that 70% of providers fail on their first attempt.
- Require breach-notification language that actually works. Your vendor contracts need a contractual obligation to notify you within hours, not the 60-day HIPAA grace period. Push for it in renewals. The vendors who refuse are the ones whose contracts you should not renew.
- Move MFA off SMS and voice. Scattered Spider built its healthcare track record by SIM-swapping hospital help-desk staff. Hardware security keys (FIDO2) and platform passkeys are not exotic. They are cheap, they survive a phone-port attack, and they are the single highest-ROI control a small hospital can deploy this quarter.
- Run one ransomware tabletop a year. Pick a realistic scenario — Unimed billing is down, your claims queue is frozen, you cannot post charges — and walk through who decides to pay or not pay, who calls HHS, who calls OCR, who calls the press. The first time you do this exercise, you will discover three gaps in your runbook you did not know existed.
- Lock the AI tools your clinicians are already using. Last week’s Bitdefender stat said 47.4% of IT teams have partial or no visibility into AI usage. In a hospital, that is a HIPAA problem waiting to be a breach report. Publish the approved list, block the rest, and write down what “approved for PHI” means.
The Honest Take
The 110% surge is not a peak. It is the new floor. Healthcare is the most attacked critical-infrastructure sector in the United States for the fifteenth year running, the ransomware crews have learned that vendors are a multiplier, and the people behind Scattered Spider are in court because they tried it on SSM Health and got caught. Next time they may not get caught. The hospitals that handle the next eighteen months well are not the ones with the best vendor security questionnaire. They are the ones who accepted early that the lockmaker is the target, not the lock.
