Last week we wrote about the 47.4% of IT teams flying blind on Shadow AI. This week, Comparitech and Dark Reading put a number on the target that’s getting hit hardest because of that gap: healthcare.

In February, a ransomware attack on the University of Mississippi Medical Center (UMMC) disrupted operations for more than two weeks. The hospital is the only Level 1 trauma center in the state. Surgeries were rescheduled. Cancer patients had to be diverted. The CEO called it “the most significant operational challenge in our history.” It was not a one-off. Comparitech, tracking incidents across the healthcare sector through the first half of 2026, found that attacks against healthcare businesses — not the hospitals themselves, but the vendors, billing providers, and clearinghouses behind them — more than doubled year over year. The 110% surge is the headline. The mechanism is the part that should keep a CIO up at night.

Why the Vendor Becomes the Bullseye

Rebecca Moody, head of data research at Comparitech, said the obvious thing out loud: “Through one central hub, you’re targeting multiple healthcare organizations that often have huge databases or were providing third-party services to hundreds of hospitals.”

The German medical-billing company Unimed learned this in March. Unimed processes billing for roughly 95% of Germany’s university hospitals and more than half of its larger clinics. One intrusion. Tens of thousands of patient records out. The same shape played out in February at TriZetto Provider Solutions, where a breach exposed the data of 3.4 million patients across the company’s healthcare-provider customers. QualDerm Partners disclosed in February that a December 2025 attack had compromised 3.1 million patient records.

Notice the pattern. None of those headlines name a hospital. They name the company the hospitals depend on. The attackers aren’t picking locks anymore. They’re picking the lockmaker.

The small-clinic version of this is real. The 40-physician orthopedic group that outsources its billing to a clearinghouse, the regional imaging center that uses a third-party transcription service, the dental practice that hands its claims processing to a SaaS vendor — every one of those is a single breach away from having to notify tens of thousands of patients they never treated. The vendor may not even tell you before the press release goes out.

Legacy, Always-On, and Underfunded

The other half of the equation is the hospital itself. The FBI’s Internet Crime Complaint Center said in April 2026 that healthcare was the most-attacked critical-infrastructure sector in all of 2025. That is not a new finding. It is the same finding the FBI has published every year for the past decade. What changed in 2026 is the gap between attacker capability and defender capacity stopped closing.

Errol Weiss, chief security officer at the Health Information Sharing and Analysis Center (Health-ISAC), described the structural trap in plain language: legacy medical-device complexity, always-on clinical operations, and heavy third-party dependence, all under the budget pressure of a 60% gross margin business that the government reimburses below cost. Hospital CISOs are taking the threats seriously. They are also losing the hiring war to payers, pharma, and the vendors they already depend on.

The Shadow AI thread from last week lands directly here. When an overworked nurse pastes a medication list into ChatGPT at 2 a.m. to make sense of a discharge summary, and when a billing clerk uploads a denial letter to Claude to draft an appeal, the data has left the building. There is no DLP rule in the world that catches that on a personal phone on the hospital Wi-Fi. Most hospitals have not even tried.

Empty hospital operating room with connected medical equipment
When vendor systems fail, the disruption reaches clinical operations long before contracts catch up.

Scattered Spider’s Healthcare Trail

On July 16, 2026, Owen Flowers (18) and Thalha Jubair (20) were each sentenced to five and a half years in a UK court for the 2024 ransomware attack on Transport for London. The Transport for London case was the headline. The healthcare part of the plea is the part that matters for this article.

Flowers was arrested at home on September 6, 2024 — three days after the TfL intrusion ended. The NCA says officers caught him mid-attack on two U.S. healthcare organizations: SSM Health Care Corporation and Sutter Health. Search warrants turned up devices holding proof of all three intrusions. In chats that prosecutors entered into evidence, Flowers acknowledged that locking those systems down “might kill some 90-year-old on life support.” The arrest is what stopped him.

The DOJ’s September 2025 indictment against Jubair, still untested in court, ties the broader Scattered Spider crew to roughly 120 intrusions, at least 47 U.S. victims, and more than $115 million in ransom payments between May 2022 and September 2025. Healthcare was not a side project. It was a quarter of the work. Scattered Spider’s tradecraft — SIM swap, voice phishing, MFA bypass via the carrier — works against hospitals because hospitals answer the phone and accept SMS codes, the same way every other enterprise does.

What Actually Moves the Needle

For a small hospital, a regional clinic network, or a healthcare-adjacent vendor, the work is unglamorous and the order matters.

  1. Map your third parties before your attackers do. You cannot manage a risk you have not named. Get a written list of every vendor with read or write access to patient data, and what data classification each one handles. This is the actual HIPAA Security Rule Risk Analysis requirement that 70% of providers fail on their first attempt.
  2. Require breach-notification language that actually works. Your vendor contracts need a contractual obligation to notify you within hours, not the 60-day HIPAA grace period. Push for it in renewals. The vendors who refuse are the ones whose contracts you should not renew.
  3. Move MFA off SMS and voice. Scattered Spider built its healthcare track record by SIM-swapping hospital help-desk staff. Hardware security keys (FIDO2) and platform passkeys are not exotic. They are cheap, they survive a phone-port attack, and they are the single highest-ROI control a small hospital can deploy this quarter.
  4. Run one ransomware tabletop a year. Pick a realistic scenario — Unimed billing is down, your claims queue is frozen, you cannot post charges — and walk through who decides to pay or not pay, who calls HHS, who calls OCR, who calls the press. The first time you do this exercise, you will discover three gaps in your runbook you did not know existed.
  5. Lock the AI tools your clinicians are already using. Last week’s Bitdefender stat said 47.4% of IT teams have partial or no visibility into AI usage. In a hospital, that is a HIPAA problem waiting to be a breach report. Publish the approved list, block the rest, and write down what “approved for PHI” means.

The Honest Take

The 110% surge is not a peak. It is the new floor. Healthcare is the most attacked critical-infrastructure sector in the United States for the fifteenth year running, the ransomware crews have learned that vendors are a multiplier, and the people behind Scattered Spider are in court because they tried it on SSM Health and got caught. Next time they may not get caught. The hospitals that handle the next eighteen months well are not the ones with the best vendor security questionnaire. They are the ones who accepted early that the lockmaker is the target, not the lock.

Healthcare professional using a smartphone with a stethoscope around their neck
Phishing-resistant MFA blocks the SIM-swap and help-desk attacks Scattered Spider depends on.

The December 2024 NPRM ends the “addressable vs. required” loophole. Here’s what healthcare IT teams need to do in the next 90 days.

In February 2024, a single ransomware group compromised Change Healthcare and walked away with the medical records of 192.7 million Americans. That’s more than half the country. The attack vector was almost embarrassingly simple: a Citrix portal without multi-factor authentication.

The company paid a $22 million ransom. UnitedHealth Group, Change’s parent, has since reported breach-related costs north of $3 billion. And yet — until very recently — the federal baseline for protecting patient data hadn’t meaningfully changed since 2013.

That’s about to change. And a lot of healthcare organizations are nowhere near ready.

What’s actually in the proposed Security Rule

HHS published a Notice of Proposed Rulemaking on December 27, 2024. Public comments closed in early 2025. The final rule is expected sometime this year, with a compliance window of 6–12 months after publication. The changes are the most significant to the Security Rule in over a decade.

The biggest shift is the end of the “addressable” vs. “required” loophole. Under the current rule, a safeguard can be marked “addressable” — meaning you can skip it if you document a reasonable alternative. In practice, that became an excuse to skip encryption, MFA, and other things organizations didn’t want to budget for. The NPRM basically eliminates that distinction. Things that were “addressable” become required, full stop.

The requirements getting teeth:

If you’re reading that list and feeling a bit of acid reflux, you’re not alone.

The threat landscape changed faster than the rule

The 2013 rule was written for a world of Windows XP workstations on flat networks and clinicians logging in from a single office. The attackers of 2026 are not playing by those rules.

Three patterns define the modern healthcare threat:

Third-party vendors are the new front door. The Change Healthcare breach wasn’t a hospital being hacked. It was a clearinghouse used by virtually every US provider. Ascension’s May 2024 ransomware incident started with a contractor downloading a malicious file. When a single vendor handles billing, scheduling, or credentialing for thousands of practices, that vendor’s security posture becomes your security posture.

Medical devices are a soft target. A 2022–2024 wave of FDA safety communications flagged vulnerabilities in devices from Medtronic, BD, Illumina, and others. Many run outdated embedded operating systems, have hardcoded credentials, and can’t be patched without taking the device offline. The new rule will require device inventories, SBOMs (software bills of materials), and a documented plan for addressing known vulnerabilities.

Initial access brokers are running a SaaS model. Groups like Scattered Spider, BlackCat/ALPHV, and LockBit-affiliated crews specialize in selling access rather than running ransomware themselves. Healthcare organizations with exposed RDP, unpatched VPN appliances, and help desks that don’t do callback verification are paying the price.

Modern hospital operating room illustrating medical device network security
Medical devices are a soft target — many run outdated embedded OSes with hardcoded credentials.

What to do in the next 90 days

You don’t have to wait for the final rule. The practices that get ahead of this now will be the ones that pass their next OCR audit with a handshake instead of a subpoena.

  1. Inventory everything that touches ePHI. Laptops, phones, printers, fax servers, imaging systems, infusion pumps, badge readers that store biometric templates — all of it. If you can’t list it, you can’t protect it.

  2. MFA everywhere, no exceptions. This is the single highest-ROI change. The Change Healthcare attackers walked in through a single Citrix account with no MFA. Don’t let that be your story.

  3. Review your BAAs, then actually test the vendors. A signed Business Associate Agreement is not a security posture. Ask your clearinghouses, billing vendors, and EHR hosting providers for SOC 2 Type II reports and recent penetration test summaries.

  4. Run an actual tabletop exercise. Pretend your EHR is down for 48 hours. Who calls whom? What’s the manual fallback for prescriptions and lab orders? How do you notify patients? Write it down. Then test it again in six months.

  5. Patch the worst things first. CISA’s Known Exploited Vulnerabilities catalog is a free, opinionated list. Work through it. The 15-day SLA for critical flaws isn’t aspirational under the new rule.

The small practice reality

If you’re a solo practitioner or a small group, the list above is intimidating. You’re running a medical practice, not a security operations center. The good news: HHS has signaled that some new requirements will scale based on size and complexity. The bad news: “we’re small” has not been a winning defense in OCR enforcement actions for years. The 2024 settlement with Plastic Surgery Associates — $500,000, six affected patients — made that point clearly.

Consider a vCISO arrangement (a fractional security officer, typically $3–8k/month) or a managed detection and response provider that knows healthcare. The per-provider cost is a lot smaller than a breach.

The takeaway

The HIPAA Security Rule is finally catching up to the threats healthcare has been facing for a decade. The final rule will land this year, and the compliance clock will start immediately. The practices that use the next 90 days to get MFA in place, finish their asset inventory, and pressure-test their vendors will spend 2026 focused on patient care. The ones that wait will be explaining to OCR why their Citrix portal didn’t have multi-factor authentication.

Healthcare professional using a smartphone, illustrating mobile access to patient data
MFA on every system that touches ePHI — including the phone in every clinician’s pocket.

In today’s digital landscape, cyber threats are evolving at an unprecedented rate. For businesses and individuals alike, maintaining robust network security is essential. However, even the best defenses can become outdated or develop vulnerabilities over time. That’s where a security audit comes in—a comprehensive health check for your network that helps identify weaknesses and ensures your defenses are up to date. In this blog post, we’ll explore what a security audit entails, why it’s crucial, and how to conduct one effectively.

What is a Security Audit?

A security audit is a systematic evaluation of your network’s security posture. It involves reviewing your security policies, procedures, and controls to ensure they are effective and comply with industry standards and regulations. The audit aims to identify vulnerabilities, assess risk levels, and provide recommendations for improving security.

Why is a Security Audit Important?

Security audits play a critical role in maintaining a secure network environment. Here’s why they are essential:

Types of Security Audits

Security audits can be categorized into different types, each focusing on specific aspects of your network:

Security audit report

How to Conduct a Security Audit

Conducting a security audit involves several steps. Here’s a step-by-step guide to help you get started:

Common Challenges in Security Audits

Security audits can be complex, and organizations often face challenges in conducting them effectively. Here are some common obstacles and how to overcome them:

Team with security checklist

Final Thoughts

A security audit is essential for maintaining the health of your network. By identifying vulnerabilities, ensuring compliance, and improving your security posture, audits help protect your organization from cyber threats. While conducting a security audit can be challenging, the benefits far outweigh the costs.

Regular security audits should be a cornerstone of your network security strategy, no matter how large or small. By staying proactive and continuously improving your defenses, you can safeguard your organization’s assets and build a robust security foundation that withstands the test of time.

Cited Articles

Your router is the heart of your network, pumping data to and from all your devices. But have you ever stopped to think about its security? In this post, we’ll dive into the essentials of router security, from firmware updates to secure configuration, ensuring your network’s heart beats strong.

Why Firmware Updates Matter

Firmware is the software that runs your router, and like any software, it can have bugs and vulnerabilities. Manufacturers regularly release firmware updates to patch security holes, fix bugs, and improve performance. If you’re not regularly updating your router’s firmware, you could be leaving your network exposed to attacks.

How to Update Firmware:

The Importance of Changing Default Settings

When you first set up your router, it comes with default settings that are designed for ease of use, not security. The default SSID (Service Set Identifier) and password are often common across all units of the same model, making them easy targets for hackers.

What to Change:

Setting Up a Secure Admin Interface

The admin interface is where you manage your router’s settings, and it’s crucial to keep this secure. Leaving this interface exposed can give attackers the keys to your entire network.

Security Tips:

Using VLANs for Network Segmentation

VLANs (Virtual Local Area Networks) allow you to segment your network into different parts, which can improve security by isolating certain devices from others. For example, you can have one VLAN for your IoT devices and another for your personal devices, reducing the risk of an attack spreading across your entire network.

Benefits of VLANs:

Network VLAN configuration

Spotting a Compromised Router

Even with all these security measures in place, it’s important to know the signs of a compromised router. Unusual network activity, frequent disconnects, and unknown devices on your network are all red flags.

What to Watch For:

Final Thoughts

Your router is a critical component of your network’s security, and taking the time to secure it can protect you from a range of cyber threats. By updating firmware, changing default settings, securing the admin interface, using VLANs, and staying vigilant for signs of compromise, you can keep your network’s heart beating strong.

Cited Articles:

Zero Trust Security for Small Biz

Zero Trust Security for Small Biz Alright, strap in and grab your digital helmet because we’re about…

User Access: The Gatekeeper to Your Network Security

When it comes to network security, controlling who has access to your systems is as important as…

Security Audit: The Health Check Your Network Needs

In today’s digital landscape, cyber threats are evolving at an unprecedented rate. For businesses…

Router Roulette: Is Your Network’s Heart Secure?

Your router is the heart of your network, pumping data to and from all your devices. But have you…

Router security warning