Why Is Healthcare Data Targeted by Hacker?
- 2 days ago
- 16 min read

Healthcare has been the most expensive industry for data breaches for fourteen consecutive years, and the reasons go well beyond weak passwords or outdated firewalls. IBM's Cost of a Data Breach Report 2025 puts the average healthcare breach at $7.42 million, still the highest of any sector even after a rare year-over-year decline. In the United States specifically, breach costs climbed to a record $10.22 million per incident, according to the same report.
This guide explains, in plain business terms, why hospitals, clinics, health plans, and their vendors remain a preferred target for cybercriminals and, increasingly, nation-state actors. It walks through the mechanics of medical record value, the operational and regulatory pressure that makes healthcare organizations easier to extort, and the specific structural weaknesses, including legacy medical devices, shadow IT, fragmented vendor ecosystems, and merger-driven complexity, that widen the attack surface. Six verified breach case studies illustrate how these risks play out in the real world, from the 2017 WannaCry attack on the NHS to the 2024 ransomware attack on Change Healthcare that exposed the protected health information of roughly 192.7 million people, according to HHS Office for Civil Rights records.
The article closes with practical checklists for executives and security teams, a comparison of healthcare compliance frameworks, and a look at how knowing precisely where sensitive patient data lives, across file servers, cloud drives, and unmanaged shares, shapes the speed and accuracy of a post-incident investigation.
Introduction: A Sector Under Sustained Attack
Ask a hospital CISO what keeps them up at night, and ransomware usually tops the list. But ransomware is a symptom of a deeper problem: healthcare organizations sit on some of the richest, longest-lived, and least protected data in any industry, and they run that data through an unusually complex web of legacy systems, third-party vendors, and connected medical devices.
Verizon's 2025 Data Breach Investigations Report recorded 1,710 security incidents in healthcare, with 1,542 confirmed data disclosures. System intrusion, driven largely by ransomware, overtook miscellaneous errors as the leading cause of healthcare breaches for the first time. Ninety percent of these attacks were financially motivated, but Verizon also flagged a sharp rise in espionage-driven activity, jumping from about one percent of healthcare breaches in the prior year to sixteen percent, a signal that state-linked actors are taking a growing interest in clinical and research data, not just patient billing records.
The HHS Office for Civil Rights breach portal tells a similar story from the regulatory side. In 2024, 725 large healthcare data breaches were reported, exposing an estimated 289 million records, the worst year on record, driven overwhelmingly by the single Change Healthcare ransomware attack. Hacking and IT incidents accounted for 81 percent of all reported breaches and 99.45 percent of affected individuals that year, according to OCR's own report to Congress.

Why Healthcare Data Is So Valuable to Criminals
The simplest explanation for why hackers target healthcare data is durability. Financial data is valuable but perishable: a stolen credit card number can be cancelled within a day, and a compromised bank account can be frozen almost as quickly. A medical record cannot be reissued. A patient's diagnosis history, insurance identifiers, Social Security number, and treatment records remain accurate and usable for fraud for years, sometimes for the rest of that person's life.
That durability is compounded by breadth. A single stolen medical record commonly bundles together a patient's full name, date of birth, Social Security number, insurance member ID, home address, and clinical history in one file, everything a criminal needs to open fraudulent credit lines, submit fake insurance claims, or obtain prescription medication under someone else's identity. Financial records, by comparison, tend to hold a narrower set of reusable fields.
Healthcare Data vs. Financial Data
Attribute | Healthcare Data (PHI) | Financial Data |
Shelf life of value | Years to a lifetime | Days to weeks after detection |
Ease of invalidation | Very difficult; a diagnosis or SSN cannot be reissued | Simple; card or account can be cancelled quickly |
Breadth of fraud enabled | Identity theft, insurance fraud, prescription fraud, blackmail | Primarily payment card and account fraud |
Regulatory exposure | HIPAA, HITECH, state breach laws, GDPR where applicable | PCI DSS, state breach laws |
Average breach cost (2025) | $7.42 million (highest of all industries) | $5.56 million (financial services) |
Types of Medical Records Criminals Target
Not every field in a patient record carries the same resale value or fraud utility. Understanding which data elements are most attractive helps security and compliance teams prioritize where discovery and classification efforts should start.
Record Type | Why It Is Targeted |
Demographic and identity data (name, DOB, SSN, address) | Foundation for identity theft and new-account fraud |
Insurance and payer information | Used for medical insurance fraud and fraudulent billing |
Prescription and pharmacy records | Enables prescription fraud, particularly for controlled substances |
Diagnosis and treatment history | Used for blackmail, targeted phishing, and social engineering |
Clinical trial and research data | High value to competitors and nation-state actors pursuing IP |
Payment and billing records | Direct financial fraud and card-not-present transactions |
Login credentials for patient portals | Credential stuffing and further lateral access into systems |
Healthcare Threat Actors
Healthcare organizations do not face a single type of adversary. Financially motivated ransomware crews, opportunistic data brokers, and, increasingly, state-linked espionage groups all have distinct reasons to be interested in a hospital network.
Threat Actor Type | Primary Motivation | Typical Method |
Ransomware groups (e.g., BlackCat/ALPHV, Qilin) | Financial extortion | Encrypt systems and exfiltrate data, then demand payment |
Organized data brokers | Resale of PHI on dark web markets | Exploit stolen credentials or vulnerable remote access |
Nation-state or state-linked groups | Espionage, research theft | Targeted intrusion into research institutions and health agencies |
Malicious or negligent insiders | Financial gain or error | Misuse of legitimate access; accidental disclosure |
Business email compromise actors | Fraudulent payment redirection | Impersonation of vendors, executives, or payers |
The Structural Risk Factors Most Healthcare Leaders Overlook
Beyond the raw value of patient data, healthcare organizations carry a set of structural weaknesses that are specific to how the industry operates. Executives who understand these factors are better equipped to ask their security teams the right questions.
Why Healthcare Records Remain Valuable Years After Theft
Unlike a payment card number, a medical record cannot be reset. A diagnosis, a Social Security number tied to a patient chart, or a family medical history remains accurate indefinitely. This means stolen healthcare data continues to circulate on criminal marketplaces long after the original breach has faded from headlines, and victims can face fraud attempts years later with no clear link back to the original incident.
How Healthcare Supply Chains Increase Attack Surface
A modern hospital does not operate as a single, self-contained IT environment. It relies on claims clearinghouses, laboratory partners, medical billing companies, staffing agencies, imaging vendors, and software providers, each with its own access into hospital systems or its own copy of patient data. The Change Healthcare attack demonstrated this vividly: a single vendor's compromise disrupted claims processing for thousands of downstream providers across the country. HHS OCR's own reporting notes that business associates were involved in roughly a third of major healthcare breaches in 2024, and those vendor-related incidents accounted for about seventy-five percent of all individuals affected that year.
Why Mergers and Acquisitions Create Hidden Security Risks
Healthcare consolidation is common, and every merger or acquisition brings together previously separate networks, file shares, electronic health record systems, and data governance practices. In the months following a merger, security teams are often still mapping which systems exist, who has access to them, and where sensitive files were left behind by the acquired organization. Attackers are aware of this integration window and frequently target newly merged entities where visibility is weakest.
The Impact of Legacy Medical Equipment
Connected medical devices, from infusion pumps to imaging systems, often run on operating systems that can no longer be patched, and many were never designed with modern network security in mind. Replacing this equipment is expensive and clinically disruptive, so hospitals frequently continue operating known-vulnerable devices for years, creating a persistent foothold that attackers can use to move laterally once inside the network.
Shadow IT Inside Hospitals
Clinical staff under pressure to move quickly will sometimes adopt unsanctioned tools, personal cloud storage, messaging apps, or file-sharing services, to get their work done, especially when approved systems feel slow or cumbersome. Each of these unmanaged tools can become a repository of unencrypted patient data that IT and security teams do not know exists, and therefore cannot protect or monitor.
Cloud Collaboration Risks
The same collaboration platforms that improve care coordination, shared drives, messaging tools, and telehealth platforms, also multiply the number of places sensitive files can end up. A spreadsheet containing patient identifiers can be copied into a shared drive, forwarded by email, or synced to a personal device in seconds, often without anyone tracking that a sensitive file now exists in a new location.
Third-Party Healthcare Vendors
Billing services, transcription companies, cloud EHR hosts, and IT support contractors routinely need some level of access to patient information. Each vendor relationship is a potential entry point, and a breach at any one of them can expose data belonging to every healthcare organization that vendor serves, as the Change Healthcare and Synnovis incidents both illustrated at very different scales.
Insider Risks
Not every incident originates outside the organization. Employees with legitimate access can misuse patient records out of curiosity, financial motive, or simple negligence, such as sending a file to the wrong recipient. Verizon's 2025 DBIR found that internal actors were involved in roughly thirty percent of healthcare breaches, a notably higher share than in most other industries.
Nation-State Targeting of Healthcare and Research Data
Hospitals affiliated with universities, and standalone research institutions, hold clinical trial data, vaccine and drug research, and genomic datasets that can be commercially or strategically valuable to a foreign government. Verizon's 2025 report noted a sharp jump in espionage-motivated healthcare breaches, underscoring that state-linked groups are no longer focused solely on financial institutions and defense contractors.
Business Email Compromise in Healthcare
Healthcare finance departments manage large volumes of vendor and insurer payments, making them attractive targets for business email compromise schemes, where an attacker impersonates a known vendor or executive to redirect a payment. These attacks do not always involve a data breach in the traditional sense, but they exploit the same trust relationships that make the healthcare supply chain hard to secure.
How Stolen Healthcare Data Turns Into Fraud
Identity Theft Using Medical Records
Because a medical record typically contains a patient's full identity profile in one place, it gives criminals everything needed to open credit accounts, file fraudulent tax returns, or take out loans in the victim's name. Unlike a stolen card number, this kind of identity theft can be difficult for the victim to detect until the damage is well underway.
Medical Insurance Fraud
Stolen insurance identifiers can be used to submit fraudulent claims for services never rendered, or to obtain medical care under someone else's coverage. This form of fraud can also corrupt the victim's own medical record with someone else's treatment history, creating downstream risks to patient safety if the erroneous information influences future care decisions.
Prescription Fraud
Patient and prescriber information stolen from a healthcare organization can be used to obtain controlled substances fraudulently, either by forging prescriptions or by using stolen identities to obtain refills. This is one of the more clinically dangerous forms of medical record misuse, since it can also mask patterns of drug diversion.
Clinical Trial and Research Data Theft
Pharmaceutical and academic research partners generate enormous volumes of trial data, much of which has significant commercial value long before a drug or therapy reaches market. Theft of this data can undermine years of investment and, in cases involving state-linked actors, has clear strategic implications beyond ordinary financial crime.
Six Verified Healthcare Breach Case Studies
The following incidents are among the most consequential healthcare cyberattacks on record. Each illustrates a different combination of the risk factors described above, and each carries lessons for how visibility into where sensitive data resides can change the course of an investigation.
1. Change Healthcare (2024)
Timeline: The BlackCat/ALPHV ransomware group gained access to a Change Healthcare Citrix portal on February 12, 2024, using compromised credentials on an account that lacked multi-factor authentication. The company disclosed the attack on February 21, 2024. HHS OCR was later notified, in July 2025, that the breach ultimately affected approximately 192.7 million individuals, according to OCR's own incident FAQ.
Attack Method: Ransomware deployed after initial access through a single unprotected remote access account, followed by data exfiltration before encryption.
Business Impact: UnitedHealth Group reported the cost of the incident had reached approximately $2.457 billion by its Q3 2024 earnings report. Claims processing was disrupted nationwide for weeks, affecting pharmacies, hospitals, and physician practices that relied on Change Healthcare's clearinghouse services.
Regulatory Impact: HHS OCR opened a HIPAA compliance investigation, an unusually early move for the agency given what it described as the unprecedented scale of the incident. Multiple state attorneys general, including Nebraska, filed suit, and the case was consolidated in multidistrict litigation.
Lesson: The scale of this breach was driven not just by the intrusion itself but by how much sensitive data the organization did not know it needed to review. A clear, current inventory of where PHI resided across systems would have accelerated the months-long process of determining exactly whose data was affected and what it contained.
2. CommonSpirit Health (2022)
Timeline: Attackers had access to CommonSpirit Health's network between September 16 and October 3, 2022. The organization detected the ransomware attack on October 2, 2022, and confirmed patient data theft in December 2022.
Attack Method: Ransomware attack that led to data theft from file servers before systems were taken offline. More than 164 facilities across 13 states were affected.
Business Impact: CommonSpirit estimated the total cost of the attack at approximately $160 million, contributing to a $1.4 billion operating loss for fiscal year 2023.
Regulatory Impact: CommonSpirit reported the breach to HHS OCR as affecting 623,774 individuals and faced a class-action lawsuit alleging negligent security practices.
Lesson: The attackers stole data from only two file servers rather than the full medical record system, but pinpointing exactly what those servers held, and which patients across a sprawling, multi-state health system were implicated, still took months. Faster, more precise data discovery on those specific servers could have shortened the notification timeline considerably.
3. Universal Health Services (2020)
Timeline: UHS was hit by Ryuk ransomware on September 27, 2020, forcing more than 250 US hospitals and behavioral health facilities to shift to manual, paper-based operations.
Attack Method: Ryuk ransomware, typically delivered through prior Emotet or BazarLoader infections, encrypted systems across the enterprise network. UHS did not pay the ransom and restored operations from backups.
Business Impact: UHS reported an aggregate pre-tax impact of approximately $67 million for the year, driven mainly by lost patient activity during the recovery period, according to its own financial disclosures.
Regulatory Impact: The incident drew scrutiny from federal agencies and became a widely cited case in FBI and CISA warnings about ransomware targeting the healthcare sector during the COVID-19 pandemic.
Lesson: Because electronic health records were largely unaffected, the incident centered on operational disruption rather than a confirmed large-scale PHI exposure. It illustrates why discovery efforts should extend beyond the primary EHR to the surrounding systems, workstations, and file shares that also touch patient information.
4. Synnovis / NHS (2024)
Timeline: The Qilin ransomware group attacked Synnovis, a pathology services provider for several London NHS trusts, on June 3, 2024. The NHS declared its first-ever critical incident for a cyberattack the following day.
Attack Method: Attackers gained access through a service account that lacked multi-factor authentication, then exfiltrated data before encrypting Synnovis systems.
Business Impact: More than 10,000 outpatient appointments and over 1,700 operations were cancelled or postponed. London hospitals faced a critical shortage of O-negative blood as a direct result of the disruption to pathology services.
Regulatory Impact: King's College Hospital NHS Foundation Trust confirmed in 2025 that the cyberattack was a contributing factor in a patient's death, one of the first formally documented cases linking a ransomware attack to a patient fatality. Synnovis took roughly eighteen months to complete its forensic review before notifying affected organizations, citing how unstructured and fragmented the stolen data was.
Lesson: Synnovis itself described the stolen data as unstructured, incomplete, and fragmented, which is precisely why the investigation took so long. This case is a direct illustration of why knowing, in advance, where sensitive files live and what they contain is not just a compliance nicety but a factor that can directly affect how quickly patients and partner organizations learn they were affected.
5. Scripps Health (2021)
Timeline: Attackers accessed Scripps Health's network beginning around April 29, 2021, and deployed ransomware that crippled systems for close to a month.
Attack Method: Ransomware attack that resulted in theft of unencrypted files containing patient health information, Social Security numbers, and driver's license numbers.
Business Impact: Scripps reported approximately $113 million in lost revenue for May 2021 alone, along with the operational burden of reverting to paper-based patient records during the outage.
Regulatory Impact: The breach was reported to HHS as affecting 147,267 individuals; a related consolidated class action was later settled for more than $3.5 million.
Lesson: The fact that stolen files were stored in non-encrypted form was central to the litigation against Scripps. Locating and classifying sensitive files that are stored without adequate protection, before an attacker finds them, remains one of the highest-value steps a healthcare organization can take.
6. WannaCry and the NHS (2017)
Timeline: The WannaCry ransomware worm spread globally starting May 12, 2017, and infected at least 81 of 236 NHS trusts in England along with 603 primary care organizations, according to the UK National Audit Office.
Attack Method: A self-propagating worm that exploited a known Windows vulnerability for which a patch had already been available for weeks before the attack.
Business Impact: The Department of Health and Social Care estimated the total cost to the NHS at approximately £92 million, including roughly £20 million in lost output and £72 million in IT recovery costs. Around 19,000 appointments and operations were cancelled.
Regulatory Impact: The National Audit Office concluded the attack could have been prevented through basic IT security practices, and the UK Parliament's Committee of Public Accounts described the incident as a wake-up call for the health service.
Lesson: NHS Digital stated it believed no patient data was stolen in this incident, but the operational impact alone was severe. WannaCry remains the clearest illustration that healthcare's exposure is not limited to data theft; unpatched, unmanaged systems can bring patient care to a halt even without a single record being exfiltrated.
Healthcare Compliance Comparison
Healthcare organizations operating internationally, or handling data for patients in multiple jurisdictions, must navigate overlapping and sometimes inconsistent compliance regimes. The table below summarizes the frameworks most relevant to healthcare data protection.
Framework | Jurisdiction | Core Focus | Breach Notification Standard |
HIPAA / HITECH | United States | Protection of PHI held by covered entities and business associates | Notify HHS and affected individuals without unreasonable delay, no later than 60 days |
GDPR | European Union | Protection of personal data, including special category health data | Notify supervisory authority within 72 hours where feasible |
UK GDPR / Data Protection Act | United Kingdom | Protection of personal and special category data, overseen by the ICO | Notify the ICO within 72 hours of becoming aware |
India DPDP Act | India | Protection of digital personal data, including health information | Notify the Data Protection Board and affected individuals per Board rules |
State breach notification laws | United States (state level) | Supplement HIPAA with state-specific timelines and definitions | Varies by state, commonly 30 to 60 days |
Business Impacts of Healthcare Breaches
Impact Category | Example From Case Studies |
Direct financial cost | Change Healthcare: approximately $2.457 billion (UnitedHealth Group, Q3 2024 earnings) |
Operating losses | CommonSpirit Health: $1.4 billion operating loss, fiscal year 2023 |
Litigation and settlements | Scripps Health: $3.5 million class-action settlement |
Regulatory investigation | Change Healthcare: HIPAA compliance investigation opened by HHS OCR |
Patient safety impact | Synnovis / NHS: cyberattack formally linked to a patient death |
National-level disruption | WannaCry: approximately £92 million cost to the NHS and 19,000 cancelled appointments |
Post-Incident Investigation: Why Data Discovery Matters
Every case study in this article shares a common thread: the length and difficulty of the investigation was directly tied to how well the organization understood where its sensitive data actually lived. Synnovis needed roughly eighteen months to determine which patients were affected because the stolen data was unstructured and scattered. Change Healthcare's individual notification process stretched across most of a year. These are not failures of intent; they are the predictable result of not having a current map of sensitive data across file servers, cloud drives, and endpoints before an incident occurs.
What Many Healthcare Leaders Overlook
Sensitive data discovery is treated as a one-time compliance exercise rather than an ongoing practice.
File shares and cloud drives created for a single project often outlive their original purpose and are forgotten.
Departing employees and completed vendor contracts frequently leave sensitive files behind in shared locations.
Data classification is applied inconsistently across on-premises servers, SharePoint, OneDrive, and Google Drive.
Questions Every Hospital Should Ask
Do we know, right now, every location where files containing protected health information are stored?
Could we tell a regulator, within days rather than months, roughly how many patient records were present on a specific compromised server?
Are our file servers, SharePoint sites, and cloud drives classified consistently, or does each system use its own ad hoc labeling?
When a vendor relationship ends, do we verify that sensitive files shared with that vendor have been located and removed?
If a single laptop or file share were compromised tomorrow, how long would it take to determine what sensitive data it contained?
Sensitive Data Discovery Workflow
Step | Description |
1. Connect | Connect to file servers, SharePoint, OneDrive, Google Drive, and local storage repositories |
2. Scan | Scan files across connected repositories to identify content that may contain sensitive information |
3. Classify | Classify identified files based on the type of sensitive data they contain |
4. Report | Generate reports showing where sensitive files reside and which repositories carry the greatest concentration of risk |
5. Support Investigation | Provide investigators and compliance teams with a searchable inventory to accelerate breach scoping |
Investigation Workflow
Phase | Typical Activities |
Detection | Identify unusual system behavior, alerts, or ransom notes; confirm the incident |
Containment | Isolate affected systems; disable compromised accounts; preserve forensic evidence |
Scoping | Determine which systems and files were accessed, and what sensitive data they contained |
Notification | Prepare and issue notifications to regulators, affected individuals, and business partners |
Remediation | Patch vulnerabilities, rebuild affected systems, and strengthen access controls |
Review | Conduct a post-incident review and update data governance and discovery practices |
Healthcare Breach Response Timeline
Timeframe | Typical Regulatory Milestone (HIPAA) |
Day 0 | Breach discovered; internal incident response begins |
Within 60 days | Notification to HHS OCR and affected individuals required under the HIPAA Breach Notification Rule |
Ongoing | Media notification required if the breach affects 500 or more residents of a state or jurisdiction |
Annual | Breaches affecting fewer than 500 individuals may be reported to HHS OCR on an annual basis |
Checklists
Incident Checklist (Security Team)
Isolate affected systems and preserve logs before making changes
Identify the initial access vector and whether it remains open
Determine which repositories the attacker could have reached
Run sensitive data discovery against affected and adjacent repositories to scope PHI exposure
Coordinate with legal and compliance on notification obligations and timelines
Document findings for regulators, cyber insurance carriers, and executive leadership
Executive Checklist (Leadership Team)
Confirm the organization has a current inventory of where sensitive patient data is stored
Verify that third-party vendors with access to PHI are contractually required to notify you promptly of their own incidents
Review cyber insurance coverage against realistic breach cost benchmarks for the healthcare sector
Ensure legacy and connected medical devices are included in the organization's risk register
Confirm a communication plan exists for patients, staff, media, and regulators before an incident occurs
Expert Insight: Executive and Compliance Perspectives
Executive Perspective
Boards increasingly ask not just whether an organization was breached, but how quickly it could tell patients and regulators what was taken. That answer depends less on the sophistication of the attacker and more on whether the organization already knew where its sensitive data lived.
Compliance Perspective
HIPAA's 60-day notification clock does not pause for a complicated investigation. Organizations that can quickly scope which files and which patients were affected are in a far stronger position to meet that deadline, and to avoid the kind of open-ended regulatory scrutiny seen in the Change Healthcare case.
Key Takeaways
Healthcare data is targeted because it is durable, cannot be reissued, and enables multiple types of fraud from a single stolen record.
Healthcare has recorded the highest average data breach cost of any industry for fourteen consecutive years, reaching $7.42 million globally and $10.22 million in the United States in 2025, per IBM.
Structural factors, including vendor sprawl, legacy medical devices, shadow IT, and merger-driven complexity, widen the attack surface well beyond the hospital's own network perimeter.
Every major case study in this article shows that investigation speed and accuracy depend heavily on how well the organization understood where sensitive data was stored before the incident occurred.
Sensitive data discovery is a distinct capability from prevention or detection. It supports investigation, compliance reporting, and remediation, and works best as an ongoing practice rather than a reactive one.




Comments