top of page
Search

Why Is Healthcare Data Targeted by Hacker?

  • 2 days ago
  • 16 min read
Why Is Healthcare Data Targeted by Hacker?

Healthcare has been the most expensive industry for data breaches for fourteen consecutive years, and the reasons go well beyond weak passwords or outdated firewalls. IBM's Cost of a Data Breach Report 2025 puts the average healthcare breach at $7.42 million, still the highest of any sector even after a rare year-over-year decline. In the United States specifically, breach costs climbed to a record $10.22 million per incident, according to the same report.


This guide explains, in plain business terms, why hospitals, clinics, health plans, and their vendors remain a preferred target for cybercriminals and, increasingly, nation-state actors. It walks through the mechanics of medical record value, the operational and regulatory pressure that makes healthcare organizations easier to extort, and the specific structural weaknesses, including legacy medical devices, shadow IT, fragmented vendor ecosystems, and merger-driven complexity, that widen the attack surface. Six verified breach case studies illustrate how these risks play out in the real world, from the 2017 WannaCry attack on the NHS to the 2024 ransomware attack on Change Healthcare that exposed the protected health information of roughly 192.7 million people, according to HHS Office for Civil Rights records.


The article closes with practical checklists for executives and security teams, a comparison of healthcare compliance frameworks, and a look at how knowing precisely where sensitive patient data lives, across file servers, cloud drives, and unmanaged shares, shapes the speed and accuracy of a post-incident investigation.


Introduction: A Sector Under Sustained Attack

Ask a hospital CISO what keeps them up at night, and ransomware usually tops the list. But ransomware is a symptom of a deeper problem: healthcare organizations sit on some of the richest, longest-lived, and least protected data in any industry, and they run that data through an unusually complex web of legacy systems, third-party vendors, and connected medical devices.


Verizon's 2025 Data Breach Investigations Report recorded 1,710 security incidents in healthcare, with 1,542 confirmed data disclosures. System intrusion, driven largely by ransomware, overtook miscellaneous errors as the leading cause of healthcare breaches for the first time. Ninety percent of these attacks were financially motivated, but Verizon also flagged a sharp rise in espionage-driven activity, jumping from about one percent of healthcare breaches in the prior year to sixteen percent, a signal that state-linked actors are taking a growing interest in clinical and research data, not just patient billing records.


The HHS Office for Civil Rights breach portal tells a similar story from the regulatory side. In 2024, 725 large healthcare data breaches were reported, exposing an estimated 289 million records, the worst year on record, driven overwhelmingly by the single Change Healthcare ransomware attack. Hacking and IT incidents accounted for 81 percent of all reported breaches and 99.45 percent of affected individuals that year, according to OCR's own report to Congress.


Large healthcare Data Breaches reported to HHS OCR, 2018 - 2025

Why Healthcare Data Is So Valuable to Criminals

The simplest explanation for why hackers target healthcare data is durability. Financial data is valuable but perishable: a stolen credit card number can be cancelled within a day, and a compromised bank account can be frozen almost as quickly. A medical record cannot be reissued. A patient's diagnosis history, insurance identifiers, Social Security number, and treatment records remain accurate and usable for fraud for years, sometimes for the rest of that person's life.


That durability is compounded by breadth. A single stolen medical record commonly bundles together a patient's full name, date of birth, Social Security number, insurance member ID, home address, and clinical history in one file, everything a criminal needs to open fraudulent credit lines, submit fake insurance claims, or obtain prescription medication under someone else's identity. Financial records, by comparison, tend to hold a narrower set of reusable fields.


Healthcare Data vs. Financial Data

Attribute

Healthcare Data (PHI)

Financial Data

Shelf life of value

Years to a lifetime

Days to weeks after detection

Ease of invalidation

Very difficult; a diagnosis or SSN cannot be reissued

Simple; card or account can be cancelled quickly

Breadth of fraud enabled

Identity theft, insurance fraud, prescription fraud, blackmail

Primarily payment card and account fraud

Regulatory exposure

HIPAA, HITECH, state breach laws, GDPR where applicable

PCI DSS, state breach laws

Average breach cost (2025)

$7.42 million (highest of all industries)

$5.56 million (financial services)

Types of Medical Records Criminals Target

Not every field in a patient record carries the same resale value or fraud utility. Understanding which data elements are most attractive helps security and compliance teams prioritize where discovery and classification efforts should start.

Record Type

Why It Is Targeted

Demographic and identity data (name, DOB, SSN, address)

Foundation for identity theft and new-account fraud

Insurance and payer information

Used for medical insurance fraud and fraudulent billing

Prescription and pharmacy records

Enables prescription fraud, particularly for controlled substances

Diagnosis and treatment history

Used for blackmail, targeted phishing, and social engineering

Clinical trial and research data

High value to competitors and nation-state actors pursuing IP

Payment and billing records

Direct financial fraud and card-not-present transactions

Login credentials for patient portals

Credential stuffing and further lateral access into systems

Healthcare Threat Actors

Healthcare organizations do not face a single type of adversary. Financially motivated ransomware crews, opportunistic data brokers, and, increasingly, state-linked espionage groups all have distinct reasons to be interested in a hospital network.

Threat Actor Type

Primary Motivation

Typical Method

Ransomware groups (e.g., BlackCat/ALPHV, Qilin)

Financial extortion

Encrypt systems and exfiltrate data, then demand payment

Organized data brokers

Resale of PHI on dark web markets

Exploit stolen credentials or vulnerable remote access

Nation-state or state-linked groups

Espionage, research theft

Targeted intrusion into research institutions and health agencies

Malicious or negligent insiders

Financial gain or error

Misuse of legitimate access; accidental disclosure

Business email compromise actors

Fraudulent payment redirection

Impersonation of vendors, executives, or payers

The Structural Risk Factors Most Healthcare Leaders Overlook

Beyond the raw value of patient data, healthcare organizations carry a set of structural weaknesses that are specific to how the industry operates. Executives who understand these factors are better equipped to ask their security teams the right questions.


Why Healthcare Records Remain Valuable Years After Theft

Unlike a payment card number, a medical record cannot be reset. A diagnosis, a Social Security number tied to a patient chart, or a family medical history remains accurate indefinitely. This means stolen healthcare data continues to circulate on criminal marketplaces long after the original breach has faded from headlines, and victims can face fraud attempts years later with no clear link back to the original incident.


How Healthcare Supply Chains Increase Attack Surface

A modern hospital does not operate as a single, self-contained IT environment. It relies on claims clearinghouses, laboratory partners, medical billing companies, staffing agencies, imaging vendors, and software providers, each with its own access into hospital systems or its own copy of patient data. The Change Healthcare attack demonstrated this vividly: a single vendor's compromise disrupted claims processing for thousands of downstream providers across the country. HHS OCR's own reporting notes that business associates were involved in roughly a third of major healthcare breaches in 2024, and those vendor-related incidents accounted for about seventy-five percent of all individuals affected that year.


Why Mergers and Acquisitions Create Hidden Security Risks

Healthcare consolidation is common, and every merger or acquisition brings together previously separate networks, file shares, electronic health record systems, and data governance practices. In the months following a merger, security teams are often still mapping which systems exist, who has access to them, and where sensitive files were left behind by the acquired organization. Attackers are aware of this integration window and frequently target newly merged entities where visibility is weakest.


The Impact of Legacy Medical Equipment

Connected medical devices, from infusion pumps to imaging systems, often run on operating systems that can no longer be patched, and many were never designed with modern network security in mind. Replacing this equipment is expensive and clinically disruptive, so hospitals frequently continue operating known-vulnerable devices for years, creating a persistent foothold that attackers can use to move laterally once inside the network.


Shadow IT Inside Hospitals

Clinical staff under pressure to move quickly will sometimes adopt unsanctioned tools, personal cloud storage, messaging apps, or file-sharing services, to get their work done, especially when approved systems feel slow or cumbersome. Each of these unmanaged tools can become a repository of unencrypted patient data that IT and security teams do not know exists, and therefore cannot protect or monitor.


Cloud Collaboration Risks

The same collaboration platforms that improve care coordination, shared drives, messaging tools, and telehealth platforms, also multiply the number of places sensitive files can end up. A spreadsheet containing patient identifiers can be copied into a shared drive, forwarded by email, or synced to a personal device in seconds, often without anyone tracking that a sensitive file now exists in a new location.


Third-Party Healthcare Vendors

Billing services, transcription companies, cloud EHR hosts, and IT support contractors routinely need some level of access to patient information. Each vendor relationship is a potential entry point, and a breach at any one of them can expose data belonging to every healthcare organization that vendor serves, as the Change Healthcare and Synnovis incidents both illustrated at very different scales.


Insider Risks

Not every incident originates outside the organization. Employees with legitimate access can misuse patient records out of curiosity, financial motive, or simple negligence, such as sending a file to the wrong recipient. Verizon's 2025 DBIR found that internal actors were involved in roughly thirty percent of healthcare breaches, a notably higher share than in most other industries.


Nation-State Targeting of Healthcare and Research Data

Hospitals affiliated with universities, and standalone research institutions, hold clinical trial data, vaccine and drug research, and genomic datasets that can be commercially or strategically valuable to a foreign government. Verizon's 2025 report noted a sharp jump in espionage-motivated healthcare breaches, underscoring that state-linked groups are no longer focused solely on financial institutions and defense contractors.


Business Email Compromise in Healthcare

Healthcare finance departments manage large volumes of vendor and insurer payments, making them attractive targets for business email compromise schemes, where an attacker impersonates a known vendor or executive to redirect a payment. These attacks do not always involve a data breach in the traditional sense, but they exploit the same trust relationships that make the healthcare supply chain hard to secure.


How Stolen Healthcare Data Turns Into Fraud


Identity Theft Using Medical Records

Because a medical record typically contains a patient's full identity profile in one place, it gives criminals everything needed to open credit accounts, file fraudulent tax returns, or take out loans in the victim's name. Unlike a stolen card number, this kind of identity theft can be difficult for the victim to detect until the damage is well underway.


Medical Insurance Fraud

Stolen insurance identifiers can be used to submit fraudulent claims for services never rendered, or to obtain medical care under someone else's coverage. This form of fraud can also corrupt the victim's own medical record with someone else's treatment history, creating downstream risks to patient safety if the erroneous information influences future care decisions.

Prescription Fraud


Patient and prescriber information stolen from a healthcare organization can be used to obtain controlled substances fraudulently, either by forging prescriptions or by using stolen identities to obtain refills. This is one of the more clinically dangerous forms of medical record misuse, since it can also mask patterns of drug diversion.


Clinical Trial and Research Data Theft

Pharmaceutical and academic research partners generate enormous volumes of trial data, much of which has significant commercial value long before a drug or therapy reaches market. Theft of this data can undermine years of investment and, in cases involving state-linked actors, has clear strategic implications beyond ordinary financial crime.


Six Verified Healthcare Breach Case Studies

The following incidents are among the most consequential healthcare cyberattacks on record. Each illustrates a different combination of the risk factors described above, and each carries lessons for how visibility into where sensitive data resides can change the course of an investigation.


1. Change Healthcare (2024)

Timeline: The BlackCat/ALPHV ransomware group gained access to a Change Healthcare Citrix portal on February 12, 2024, using compromised credentials on an account that lacked multi-factor authentication. The company disclosed the attack on February 21, 2024. HHS OCR was later notified, in July 2025, that the breach ultimately affected approximately 192.7 million individuals, according to OCR's own incident FAQ.


Attack Method: Ransomware deployed after initial access through a single unprotected remote access account, followed by data exfiltration before encryption.


Business Impact: UnitedHealth Group reported the cost of the incident had reached approximately $2.457 billion by its Q3 2024 earnings report. Claims processing was disrupted nationwide for weeks, affecting pharmacies, hospitals, and physician practices that relied on Change Healthcare's clearinghouse services.


Regulatory Impact: HHS OCR opened a HIPAA compliance investigation, an unusually early move for the agency given what it described as the unprecedented scale of the incident. Multiple state attorneys general, including Nebraska, filed suit, and the case was consolidated in multidistrict litigation.


Lesson: The scale of this breach was driven not just by the intrusion itself but by how much sensitive data the organization did not know it needed to review. A clear, current inventory of where PHI resided across systems would have accelerated the months-long process of determining exactly whose data was affected and what it contained.


2. CommonSpirit Health (2022)

Timeline: Attackers had access to CommonSpirit Health's network between September 16 and October 3, 2022. The organization detected the ransomware attack on October 2, 2022, and confirmed patient data theft in December 2022.


Attack Method: Ransomware attack that led to data theft from file servers before systems were taken offline. More than 164 facilities across 13 states were affected.


Business Impact: CommonSpirit estimated the total cost of the attack at approximately $160 million, contributing to a $1.4 billion operating loss for fiscal year 2023.


Regulatory Impact: CommonSpirit reported the breach to HHS OCR as affecting 623,774 individuals and faced a class-action lawsuit alleging negligent security practices.


Lesson: The attackers stole data from only two file servers rather than the full medical record system, but pinpointing exactly what those servers held, and which patients across a sprawling, multi-state health system were implicated, still took months. Faster, more precise data discovery on those specific servers could have shortened the notification timeline considerably.

3. Universal Health Services (2020)

Timeline: UHS was hit by Ryuk ransomware on September 27, 2020, forcing more than 250 US hospitals and behavioral health facilities to shift to manual, paper-based operations.


Attack Method: Ryuk ransomware, typically delivered through prior Emotet or BazarLoader infections, encrypted systems across the enterprise network. UHS did not pay the ransom and restored operations from backups.


Business Impact: UHS reported an aggregate pre-tax impact of approximately $67 million for the year, driven mainly by lost patient activity during the recovery period, according to its own financial disclosures.


Regulatory Impact: The incident drew scrutiny from federal agencies and became a widely cited case in FBI and CISA warnings about ransomware targeting the healthcare sector during the COVID-19 pandemic.


Lesson: Because electronic health records were largely unaffected, the incident centered on operational disruption rather than a confirmed large-scale PHI exposure. It illustrates why discovery efforts should extend beyond the primary EHR to the surrounding systems, workstations, and file shares that also touch patient information.

4. Synnovis / NHS (2024)

Timeline: The Qilin ransomware group attacked Synnovis, a pathology services provider for several London NHS trusts, on June 3, 2024. The NHS declared its first-ever critical incident for a cyberattack the following day.


Attack Method: Attackers gained access through a service account that lacked multi-factor authentication, then exfiltrated data before encrypting Synnovis systems.


Business Impact: More than 10,000 outpatient appointments and over 1,700 operations were cancelled or postponed. London hospitals faced a critical shortage of O-negative blood as a direct result of the disruption to pathology services.


Regulatory Impact: King's College Hospital NHS Foundation Trust confirmed in 2025 that the cyberattack was a contributing factor in a patient's death, one of the first formally documented cases linking a ransomware attack to a patient fatality. Synnovis took roughly eighteen months to complete its forensic review before notifying affected organizations, citing how unstructured and fragmented the stolen data was.


Lesson: Synnovis itself described the stolen data as unstructured, incomplete, and fragmented, which is precisely why the investigation took so long. This case is a direct illustration of why knowing, in advance, where sensitive files live and what they contain is not just a compliance nicety but a factor that can directly affect how quickly patients and partner organizations learn they were affected.


5. Scripps Health (2021)

Timeline: Attackers accessed Scripps Health's network beginning around April 29, 2021, and deployed ransomware that crippled systems for close to a month.


Attack Method: Ransomware attack that resulted in theft of unencrypted files containing patient health information, Social Security numbers, and driver's license numbers.


Business Impact: Scripps reported approximately $113 million in lost revenue for May 2021 alone, along with the operational burden of reverting to paper-based patient records during the outage.


Regulatory Impact: The breach was reported to HHS as affecting 147,267 individuals; a related consolidated class action was later settled for more than $3.5 million.


Lesson: The fact that stolen files were stored in non-encrypted form was central to the litigation against Scripps. Locating and classifying sensitive files that are stored without adequate protection, before an attacker finds them, remains one of the highest-value steps a healthcare organization can take.


6. WannaCry and the NHS (2017)

Timeline: The WannaCry ransomware worm spread globally starting May 12, 2017, and infected at least 81 of 236 NHS trusts in England along with 603 primary care organizations, according to the UK National Audit Office.


Attack Method: A self-propagating worm that exploited a known Windows vulnerability for which a patch had already been available for weeks before the attack.


Business Impact: The Department of Health and Social Care estimated the total cost to the NHS at approximately £92 million, including roughly £20 million in lost output and £72 million in IT recovery costs. Around 19,000 appointments and operations were cancelled.


Regulatory Impact: The National Audit Office concluded the attack could have been prevented through basic IT security practices, and the UK Parliament's Committee of Public Accounts described the incident as a wake-up call for the health service.


Lesson: NHS Digital stated it believed no patient data was stolen in this incident, but the operational impact alone was severe. WannaCry remains the clearest illustration that healthcare's exposure is not limited to data theft; unpatched, unmanaged systems can bring patient care to a halt even without a single record being exfiltrated.


Healthcare Compliance Comparison

Healthcare organizations operating internationally, or handling data for patients in multiple jurisdictions, must navigate overlapping and sometimes inconsistent compliance regimes. The table below summarizes the frameworks most relevant to healthcare data protection.

Framework

Jurisdiction

Core Focus

Breach Notification Standard

HIPAA / HITECH

United States

Protection of PHI held by covered entities and business associates

Notify HHS and affected individuals without unreasonable delay, no later than 60 days

GDPR

European Union

Protection of personal data, including special category health data

Notify supervisory authority within 72 hours where feasible

UK GDPR / Data Protection Act

United Kingdom

Protection of personal and special category data, overseen by the ICO

Notify the ICO within 72 hours of becoming aware

India DPDP Act

India

Protection of digital personal data, including health information

Notify the Data Protection Board and affected individuals per Board rules

State breach notification laws

United States (state level)

Supplement HIPAA with state-specific timelines and definitions

Varies by state, commonly 30 to 60 days

Business Impacts of Healthcare Breaches

Impact Category

Example From Case Studies

Direct financial cost

Change Healthcare: approximately $2.457 billion (UnitedHealth Group, Q3 2024 earnings)

Operating losses

CommonSpirit Health: $1.4 billion operating loss, fiscal year 2023

Litigation and settlements

Scripps Health: $3.5 million class-action settlement

Regulatory investigation

Change Healthcare: HIPAA compliance investigation opened by HHS OCR

Patient safety impact

Synnovis / NHS: cyberattack formally linked to a patient death

National-level disruption

WannaCry: approximately £92 million cost to the NHS and 19,000 cancelled appointments


Post-Incident Investigation: Why Data Discovery Matters

Every case study in this article shares a common thread: the length and difficulty of the investigation was directly tied to how well the organization understood where its sensitive data actually lived. Synnovis needed roughly eighteen months to determine which patients were affected because the stolen data was unstructured and scattered. Change Healthcare's individual notification process stretched across most of a year. These are not failures of intent; they are the predictable result of not having a current map of sensitive data across file servers, cloud drives, and endpoints before an incident occurs.

What Many Healthcare Leaders Overlook

  • Sensitive data discovery is treated as a one-time compliance exercise rather than an ongoing practice.

  • File shares and cloud drives created for a single project often outlive their original purpose and are forgotten.

  • Departing employees and completed vendor contracts frequently leave sensitive files behind in shared locations.

  • Data classification is applied inconsistently across on-premises servers, SharePoint, OneDrive, and Google Drive.


Questions Every Hospital Should Ask

  1. Do we know, right now, every location where files containing protected health information are stored?

  2. Could we tell a regulator, within days rather than months, roughly how many patient records were present on a specific compromised server?

  3. Are our file servers, SharePoint sites, and cloud drives classified consistently, or does each system use its own ad hoc labeling?

  4. When a vendor relationship ends, do we verify that sensitive files shared with that vendor have been located and removed?

  5. If a single laptop or file share were compromised tomorrow, how long would it take to determine what sensitive data it contained?


Sensitive Data Discovery Workflow

Step

Description

1. Connect

Connect to file servers, SharePoint, OneDrive, Google Drive, and local storage repositories

2. Scan

Scan files across connected repositories to identify content that may contain sensitive information

3. Classify

Classify identified files based on the type of sensitive data they contain

4. Report

Generate reports showing where sensitive files reside and which repositories carry the greatest concentration of risk

5. Support Investigation

Provide investigators and compliance teams with a searchable inventory to accelerate breach scoping


Investigation Workflow

Phase

Typical Activities

Detection

Identify unusual system behavior, alerts, or ransom notes; confirm the incident

Containment

Isolate affected systems; disable compromised accounts; preserve forensic evidence

Scoping

Determine which systems and files were accessed, and what sensitive data they contained

Notification

Prepare and issue notifications to regulators, affected individuals, and business partners

Remediation

Patch vulnerabilities, rebuild affected systems, and strengthen access controls

Review

Conduct a post-incident review and update data governance and discovery practices

Healthcare Breach Response Timeline

Timeframe

Typical Regulatory Milestone (HIPAA)

Day 0

Breach discovered; internal incident response begins

Within 60 days

Notification to HHS OCR and affected individuals required under the HIPAA Breach Notification Rule

Ongoing

Media notification required if the breach affects 500 or more residents of a state or jurisdiction

Annual

Breaches affecting fewer than 500 individuals may be reported to HHS OCR on an annual basis


Checklists


Incident Checklist (Security Team)

  • Isolate affected systems and preserve logs before making changes

  • Identify the initial access vector and whether it remains open

  • Determine which repositories the attacker could have reached

  • Run sensitive data discovery against affected and adjacent repositories to scope PHI exposure

  • Coordinate with legal and compliance on notification obligations and timelines

  • Document findings for regulators, cyber insurance carriers, and executive leadership


Executive Checklist (Leadership Team)

  • Confirm the organization has a current inventory of where sensitive patient data is stored

  • Verify that third-party vendors with access to PHI are contractually required to notify you promptly of their own incidents

  • Review cyber insurance coverage against realistic breach cost benchmarks for the healthcare sector

  • Ensure legacy and connected medical devices are included in the organization's risk register

  • Confirm a communication plan exists for patients, staff, media, and regulators before an incident occurs


Expert Insight: Executive and Compliance Perspectives


Executive Perspective

Boards increasingly ask not just whether an organization was breached, but how quickly it could tell patients and regulators what was taken. That answer depends less on the sophistication of the attacker and more on whether the organization already knew where its sensitive data lived.


Compliance Perspective

HIPAA's 60-day notification clock does not pause for a complicated investigation. Organizations that can quickly scope which files and which patients were affected are in a far stronger position to meet that deadline, and to avoid the kind of open-ended regulatory scrutiny seen in the Change Healthcare case.

Key Takeaways

  • Healthcare data is targeted because it is durable, cannot be reissued, and enables multiple types of fraud from a single stolen record.

  • Healthcare has recorded the highest average data breach cost of any industry for fourteen consecutive years, reaching $7.42 million globally and $10.22 million in the United States in 2025, per IBM.

  • Structural factors, including vendor sprawl, legacy medical devices, shadow IT, and merger-driven complexity, widen the attack surface well beyond the hospital's own network perimeter.

  • Every major case study in this article shows that investigation speed and accuracy depend heavily on how well the organization understood where sensitive data was stored before the incident occurred.

  • Sensitive data discovery is a distinct capability from prevention or detection. It supports investigation, compliance reporting, and remediation, and works best as an ongoing practice rather than a reactive one.

 
 
 

Comments


bottom of page