Healthcare ransomware now spreads through the vendors hospitals depend on.
Network Security   Jul 20, 2026

Healthcare Cyberattacks Just Doubled. The Hospitals Aren’t Even the Soft Target Anymore.

Last week we wrote about the 47.4% of IT teams flying blind on Shadow AI. This week, Comparitech and Dark Reading put a number on the target that’s getting hit hardest because of that gap: healthcare.

In February, a ransomware attack on the University of Mississippi Medical Center (UMMC) disrupted operations for more than two weeks. The hospital is the only Level 1 trauma center in the state. Surgeries were rescheduled. Cancer patients had to be diverted. The CEO called it “the most significant operational challenge in our history.” It was not a one-off. Comparitech, tracking incidents across the healthcare sector through the first half of 2026, found that attacks against healthcare businesses — not the hospitals themselves, but the vendors, billing providers, and clearinghouses behind them — more than doubled year over year. The 110% surge is the headline. The mechanism is the part that should keep a CIO up at night.

Why the Vendor Becomes the Bullseye

Rebecca Moody, head of data research at Comparitech, said the obvious thing out loud: “Through one central hub, you’re targeting multiple healthcare organizations that often have huge databases or were providing third-party services to hundreds of hospitals.”

The German medical-billing company Unimed learned this in March. Unimed processes billing for roughly 95% of Germany’s university hospitals and more than half of its larger clinics. One intrusion. Tens of thousands of patient records out. The same shape played out in February at TriZetto Provider Solutions, where a breach exposed the data of 3.4 million patients across the company’s healthcare-provider customers. QualDerm Partners disclosed in February that a December 2025 attack had compromised 3.1 million patient records.

Notice the pattern. None of those headlines name a hospital. They name the company the hospitals depend on. The attackers aren’t picking locks anymore. They’re picking the lockmaker.

The small-clinic version of this is real. The 40-physician orthopedic group that outsources its billing to a clearinghouse, the regional imaging center that uses a third-party transcription service, the dental practice that hands its claims processing to a SaaS vendor — every one of those is a single breach away from having to notify tens of thousands of patients they never treated. The vendor may not even tell you before the press release goes out.

Legacy, Always-On, and Underfunded

The other half of the equation is the hospital itself. The FBI’s Internet Crime Complaint Center said in April 2026 that healthcare was the most-attacked critical-infrastructure sector in all of 2025. That is not a new finding. It is the same finding the FBI has published every year for the past decade. What changed in 2026 is the gap between attacker capability and defender capacity stopped closing.

Errol Weiss, chief security officer at the Health Information Sharing and Analysis Center (Health-ISAC), described the structural trap in plain language: legacy medical-device complexity, always-on clinical operations, and heavy third-party dependence, all under the budget pressure of a 60% gross margin business that the government reimburses below cost. Hospital CISOs are taking the threats seriously. They are also losing the hiring war to payers, pharma, and the vendors they already depend on.

The Shadow AI thread from last week lands directly here. When an overworked nurse pastes a medication list into ChatGPT at 2 a.m. to make sense of a discharge summary, and when a billing clerk uploads a denial letter to Claude to draft an appeal, the data has left the building. There is no DLP rule in the world that catches that on a personal phone on the hospital Wi-Fi. Most hospitals have not even tried.

Empty hospital operating room with connected medical equipment
When vendor systems fail, the disruption reaches clinical operations long before contracts catch up.

Scattered Spider’s Healthcare Trail

On July 16, 2026, Owen Flowers (18) and Thalha Jubair (20) were each sentenced to five and a half years in a UK court for the 2024 ransomware attack on Transport for London. The Transport for London case was the headline. The healthcare part of the plea is the part that matters for this article.

Flowers was arrested at home on September 6, 2024 — three days after the TfL intrusion ended. The NCA says officers caught him mid-attack on two U.S. healthcare organizations: SSM Health Care Corporation and Sutter Health. Search warrants turned up devices holding proof of all three intrusions. In chats that prosecutors entered into evidence, Flowers acknowledged that locking those systems down “might kill some 90-year-old on life support.” The arrest is what stopped him.

The DOJ’s September 2025 indictment against Jubair, still untested in court, ties the broader Scattered Spider crew to roughly 120 intrusions, at least 47 U.S. victims, and more than $115 million in ransom payments between May 2022 and September 2025. Healthcare was not a side project. It was a quarter of the work. Scattered Spider’s tradecraft — SIM swap, voice phishing, MFA bypass via the carrier — works against hospitals because hospitals answer the phone and accept SMS codes, the same way every other enterprise does.

What Actually Moves the Needle

For a small hospital, a regional clinic network, or a healthcare-adjacent vendor, the work is unglamorous and the order matters.

  1. Map your third parties before your attackers do. You cannot manage a risk you have not named. Get a written list of every vendor with read or write access to patient data, and what data classification each one handles. This is the actual HIPAA Security Rule Risk Analysis requirement that 70% of providers fail on their first attempt.
  2. Require breach-notification language that actually works. Your vendor contracts need a contractual obligation to notify you within hours, not the 60-day HIPAA grace period. Push for it in renewals. The vendors who refuse are the ones whose contracts you should not renew.
  3. Move MFA off SMS and voice. Scattered Spider built its healthcare track record by SIM-swapping hospital help-desk staff. Hardware security keys (FIDO2) and platform passkeys are not exotic. They are cheap, they survive a phone-port attack, and they are the single highest-ROI control a small hospital can deploy this quarter.
  4. Run one ransomware tabletop a year. Pick a realistic scenario — Unimed billing is down, your claims queue is frozen, you cannot post charges — and walk through who decides to pay or not pay, who calls HHS, who calls OCR, who calls the press. The first time you do this exercise, you will discover three gaps in your runbook you did not know existed.
  5. Lock the AI tools your clinicians are already using. Last week’s Bitdefender stat said 47.4% of IT teams have partial or no visibility into AI usage. In a hospital, that is a HIPAA problem waiting to be a breach report. Publish the approved list, block the rest, and write down what “approved for PHI” means.

The Honest Take

The 110% surge is not a peak. It is the new floor. Healthcare is the most attacked critical-infrastructure sector in the United States for the fifteenth year running, the ransomware crews have learned that vendors are a multiplier, and the people behind Scattered Spider are in court because they tried it on SSM Health and got caught. Next time they may not get caught. The hospitals that handle the next eighteen months well are not the ones with the best vendor security questionnaire. They are the ones who accepted early that the lockmaker is the target, not the lock.

Healthcare professional using a smartphone with a stethoscope around their neck
Phishing-resistant MFA blocks the SIM-swap and help-desk attacks Scattered Spider depends on.
Healthcare ransomware now spreads through the vendors hospitals depend on.
~/other/posts

Keep Reading

Shadow AI Is Already Inside Your Company. The Hard Part Is Finding It.
Jul 14, 2026 Uncategorized

Shadow AI Is Already Inside Your Company. The Hard Part Is Finding It.

Last week’s Bitdefender numbers said 47.4% of IT teams have only partial or no visibility into the AI tools their employees are using. That is the polite version of the problem. A sales rep pastes a contract into ChatGPT to “summarize the legalese.” An engineer feeds a production stack trace into a chatbot to debug […]

Awareness Isn’t Working: The 2026 Hardening Problem Nobody Wants to Own Up To
Jul 6, 2026 Hardening

Awareness Isn’t Working: The 2026 Hardening Problem Nobody Wants to Own Up To

The first week of July handed IT teams a worst-case scenario. The interesting part is that the survey data said this was coming. On Wednesday, CISA added a high-severity SharePoint flaw to its Known Exploited Vulnerabilities catalog. By Thursday, threat actors were actively probing a critical (CVSS 9.8) bug in the official Gitea Docker image, […]

Your Software Vendor Is Now Your Biggest Cybersecurity Risk
Jun 29, 2026 Uncategorized

Your Software Vendor Is Now Your Biggest Cybersecurity Risk

The part no one wants to say out loud: you can’t audit them all. Last week, a security research firm named Novee published a finding that should make every CIO in the country uncomfortable. A class of vulnerabilities they’re calling Cordyceps — embedded in GitHub Actions workflows — exposed more than 300 public repositories (including […]