
How healthcare organizations can defend against rising ransomware and AI-driven phishing attacks
IC3 and Verizon data show 642 ransomware and data breach incidents hit healthcare in 2025, as AI-fueled phishing and a pending HIPAA Security Rule overhaul raise the stakes for providers.
Healthcare and public health continues to rank highest for cybercrime among 16 critical infrastructure sectors reviewed in the 2025 Internet Crime Report from the FBI's Internet Crime Complaint Center (IC3). The annual review shows there were 460 ransomware events and 182 data breaches in the health sector, for a combined 642 incidents in 2025. That's up from 444 the year before.
The 2025 Verizon Data Breach Investigations Report reveals some of the ways that attackers gain initial access. For example, third party involvement in breaches doubled to 30% year over year. Exploitation of vulnerabilities as an initial access vector jumped 34% to account for 20% of breaches, nearly overtaking credential abuse. Additionally, ransomware appeared in 44% of breaches (a 37% increase). Attackers are targeting the healthcare ecosystem at its greatest points of vulnerability: vendors, perimeter devices and time pressed staff.
The latest ransomware tactics
A key to being vigilant about protecting against cyberattacks is being aware of new tactics. These include exploited vulnerabilities on the perimeter, whereby attackers rapidly weaponize flaws in edge and virtual private network (VPN) devices. Organizations remediated only about half (54%) of perimeter device vulnerabilities last year, with a median remediation time of roughly a month (32 days), an exposure window that adversaries actively exploit.
"Extortion only" attacks are on the rise. In this scenario, healthcare providers report a growing share of incidents where data theft and leak threats occur without encrypting systems, an adaptation to stronger endpoint defenses and backups. And there's what known as the supply chain multiplier, whereby a single vendor incident involving, for example, a clearinghouse, EHR module, or billing cloud, can disrupt thousands of providers and pharmacies.
The significant growth of phishing
Phishing is often a first access point for a ransomware attack. And it's another rapidly growing category of cybercrime. IC3's 2025 Internet Crime Report shows that phishing/spoofing top the list of crime type by number of complaints at 191,561. That's more than double the second highest number of complaints in the category of extortion.
What's driving the growth in the number of phishing incidents? In large measure, AI is creating more successful
- Generally, AI is making phishing emails and communications more convincing to the recipient and more difficult to detect by security tools.
- Phishing attempts are no longer grammatically incorrect or obviously spotted as they once were. That's because AI is used to craft content and messages that look real and often appear to be internal to an organization.
- Phishing attacks can now be easily personalized at scale with AI, allowing people in positions across an organization such as clinicians, admins, revenue cycle, human resources, leadership, and more to be targeted with unique phishing emails.
- AI enables highly targeted spear-phishing attacks against healthcare executives and clinicians. Publicly available information from social media, provider directories, press releases, and healthcare websites can be rapidly analyzed by AI tools to generate customized messages that appear authentic. This reduces the effort required for attackers while increasing the likelihood of successful compromise.
- Attackers can now impersonate executives, physicians or trusted vendors through realistic voice messages and virtual meeting content, making employee verification processes more challenging and increasing the chance of fraudulent actions being taken.
The bottom line is that AI has provided just about anyone the ability to be an expert at social engineering and phishing. And with healthcare already serving as a major target of cyberattacks, this only makes the risk that these types of attacks will succeed even greater.
Actions to help prevent cyberattacks
The numbers of cyberattacks are daunting and the need to maximize protection against malicious actors is greater than ever. Here are steps and actions to consider to safeguard healthcare facilities:
- Deploy phishing resistant MFA (e.g., passkeys) wherever feasible, including clinician workflows on shared workstations via fast unlock methods.
- Elevate privileged access management for admins and vendors; enforce least privilege and time bound access for EHR, imaging and remote support.
- Establish a maximum 14 day patch window for firewalls, VPNs and remote access gateways; add continuous external attack surface discovery to catch shadow assets.
- Segment clinical networks (EHR, imaging, lab, pharmacy) and medical devices from corporate IT; require MFA for all admin access.
- Ensure Endpoint Detection and Response (EDR) and/or Extended Detection and Response is deployed on servers and critical workstations; tune for ransomware precursors such as beaconing, Remote Monitoring and Management (RMM) abuse and backup tampering.
- Maintain immutable, offline backups and test directory restores quarterly.
- Run a ransomware tabletop that simulates both encryption and extortion only scenarios, with a special track for clinical continuity.
- Bake minimum controls into business associate agreements and master service agreements including MFA everywhere, EDR, 24/7 monitoring, recovery time objective/recovery point objective commitments and breach notification (less than 24 hours).
Rise in cybercrime drives new HIPAA security rule
Ensuring proper safeguards against cyberattacks are in place is the focus of a new compliance issue. Federal regulators are preparing the first major
The proposed HIPAA Security Rule update will affect most hospitals, medical practices, and other HIPAA-covered healthcare organizations, as well as their business associates. At a high level, the proposed rule would require hospitals and business associates to:
- Complete a formal compliance audit every 12 months to validate adherence to all Security Rule requirements.
- Maintain complete technology asset inventories and network maps, giving leadership a clear view of cyber risk across their environment.
- Obtain annual written verification that vendors and subcontractors have deployed required safeguards, therein significantly tightening third party oversight.
- Update business associate agreements (BAA) to mandate rapid reporting (within 24 hours) of incidents affecting contingency plans, improving visibility into emerging threats.
- Strengthen workforce security practices and ensure that access to systems and data is removed promptly when staff leave or change roles.
The Notice of Proposed Rulemaking eliminates the long standing distinction between required and addressable implementation specification. Under the proposal, all specifications become mandatory, unless a narrow exception applies. This is one of the most significant shifts in HIPAA since 2013. As of July 2026, implementation has been
Healthcare's targeting isn't about hype; it's about economics (data value, extortion leverage), exposure (edge flaws and vendors), and consequences (patient care). But the sector is improving: more attacks are blocked before encryption, ransom payments are down and recovery times are shortening. Achieving these results requires board owned governance, faster edge patching, identity management that clinicians can live with, segmented networks, resilient recovery and real vendor accountability. The result is not just better information security; it's safer patient care.
Brandon Agostinelli is a Principal with the






