Attackers succeed in 95% of Healthcare incidents ASD responds to.
Healthcare is the most-breached sector in Australian OAIC data, with ransomware incidents doubling year-on-year. Over 80% of stolen US health records were taken from third-party vendors and software services — not from hospitals themselves.
Why Healthcare is in the crosshairs
Five shifts shaping the healthcare threat environment — drawn from ASD, OAIC, AHA, Sophos, and Verizon reporting.
Most-targeted in the US, most-breached in Australia — and attackers succeed when they try
The FBI's 2025 Internet Crime Report puts healthcare and public health first among US critical infrastructure sectors for ransomware and data-breach complaints; OAIC data puts health first in Australia; ASD's 95% attacker-success rate against ACSC-responded healthcare incidents is the kill shot. Detection alone is not closing the gap — attackers get in, move, and exfiltrate successfully in nearly every incident serious enough for the ACSC to respond to.
The third-party dependency problem is acute
The AHA's finding that more than 80% of stolen US PHI came from vendors — not hospitals — reframes the defensive picture. A hospital can have strong internal controls and still be exposed by a pathology provider (Synnovis), a claims processor (Change Healthcare), an e-prescription service (MediSecure), or an imaging vendor. Verizon's 2025 DBIR confirms third-party involvement in breaches doubled year-on-year.
Downtime is a life-safety issue
AHA's John Riggi describes ransomware targeting of healthcare as "threat-to-life crime". Hospitals face maximum pressure to pay because operational downtime has immediate patient-safety consequences. King's College Hospital NHS Foundation Trust found the 2024 Synnovis/NHS London attack was a contributing factor in a patient's death, and the 2020 Düsseldorf University Hospital attack forced patient diversions during life-threatening emergencies.
The attack surface keeps expanding
Electronic health records, Internet of Medical Things devices, telehealth platforms, patient portals, genomic databases, and aged care sensor networks have all been added to the attack surface in the last five years. Medical device refresh cycles are slow — so Verizon's edge-device finding (exploitation-via-edge-device breaches rising from 3% to 22%) applies with particular force in healthcare.
Paying is declining — but validation is the next step
Sophos' 2025 data shows ransom payment in healthcare has dropped from 61% in 2022 to 36% in 2025, and recovery costs (excluding any ransom) have fallen 60%. The sector is investing in backups, segmentation, and response preparation. The next step is continuous validation that those investments actually hold under current attacker tradecraft.
What regulators and experts are saying
The Change Healthcare cyberattack is the most significant and consequential incident of its kind against the U.S. healthcare system in history.
The vast majority are perpetrated by foreign ransomware gangs, primarily Russian-speaking groups, which specifically target health care hoping for a big payout. They know these attacks cause disruptions and delays to digitally dependent health care delivery, posing a risk to patient and community safety… These despicable acts are in fact threat-to-life crimes.
Time is of the essence with data breaches. The risk of serious harm often increases as days pass. Timely notification ensures people are informed and can take steps to protect themselves.
Healthcare is a SOCI Act critical infrastructure sector
Hospitals with a general intensive care unit are designated critical infrastructure with risk management program obligations, and ransomware payment reporting is mandatory under the Cyber Security Act 2024
Healthcare entities operating designated critical infrastructure assets are subject to the SOCI Act CIRMP obligations — hospitals with a general intensive care unit, or entities designated by the Minister. The CIRMP must address four hazard vectors: cyber and information security, personnel, supply chain, and physical security. For the cyber hazard vector, entities must adopt one of five approved frameworks. Healthcare entities also face obligations under the Privacy Act 1988 (including the notifiable data breach scheme), the My Health Records Act 2012 for systems connecting to My Health Record, and the National Safety and Quality Health Service (NSQHS) Standards. Not all healthcare entities are SOCI-designated — those that aren't may still adopt the Essential Eight voluntarily as a baseline.
Federal legislation that designates healthcare as a critical infrastructure sector. Entities operating designated hospitals -- those with a general intensive care unit -- must maintain a CIRMP addressing four hazard vectors: cyber, personnel, supply chain, and physical security. NodeZero directly validates controls under the cyber hazard vector across clinical and administrative networks, and tests supplier segmentation under the supply chain vector. For the cyber vector specifically, entities must also adopt one of five approved frameworks which define the detailed technical controls.
Prescriptive and technically focused. Eight specific mitigation strategies with clear pass/fail controls. Common for government-adjacent entities, defence industry, and smaller organisations adopting ASD guidance.
Where NodeZero appliesBroad lifecycle coverage from governance through recovery without mandating specific technologies. Suited to entities operating across jurisdictions or mapping existing controls into a flexible structure.
Where NodeZero appliesInternational management system standard with formal certification. Chosen by larger entities with mature security programs, international operations, or existing ISO certification investment.
Where NodeZero appliesMaturity model assessing organisational capability across 10 domains. Originally built for the US electricity sector. Process and governance oriented -- less about specific controls, more about repeatable capability.
Where NodeZero appliesSector-specific to energy. Derived from C2M2 and NIST CSF with Australian privacy additions. Managed by AEMO. The default for electricity and gas market participants with OT/ICS environments.
Where NodeZero appliesHealthcare providers handle highly sensitive patient information. The Privacy Act and Australian Privacy Principles impose strict obligations on health records.
Where NodeZero appliesApplies to hospitals and health services that process patient billing and payment card transactions.
Where NodeZero appliesRelevant for health technology providers and digital health platforms that manage patient data on behalf of healthcare organisations.
Where NodeZero appliesMandatory ransomware payment reporting for hospital operators and health services classified as critical infrastructure.
Where NodeZero appliesA cascade of new obligations
Multiple new regulatory requirements are hitting simultaneously — each increasing the compliance burden and the consequences of failure.
Cyber Security Act 2024
30 May 2025Mandatory reporting of ransomware payments within 72 hours for entities over $3M turnover. Healthcare organisations are prime ransomware targets — clinical systems cannot wait weeks for recovery. NodeZero identifies ransomware attack paths before real attackers do.
Privacy Act statutory tort
10 Jun 2025Private right of action for serious privacy invasions. Healthcare organisations hold the most sensitive personal information — clinical history, Medicare records, mental health data. A breach triggers both regulatory action and direct litigation.
SOCI Act — Healthcare critical infrastructure
In effectHospitals with a general intensive care unit are designated critical infrastructure. Mandatory risk management programs and incident reporting to the Australian Cyber Security Centre.
Strengthened Aged Care Quality Standards
1 Nov 2025Updated standards from 1 November 2025 emphasise proactive cyber security capability and incident response readiness. Aged care facilities are frequent ransomware targets with low IT maturity.
Find your organisation
See how the changes affect you specifically
Public hospital networks
State-funded hospital networks under SOCI Act obligations, managing distributed clinical environments across dozens of facilities.
View details →Private hospital groups
Large operators like Ramsay Health Care and Healthscope face shareholder pressure, rising cyber insurance premiums, and Privacy Act breach notification obligations.
View details →Aged care facilities
Frequently targeted by ransomware with low IT maturity. New Strengthened Aged Care Quality Standards emphasise proactive cyber security capability.
View details →The only autonomous pentesting platform that is:
Prove your healthcare security posture before the next assessment
See how NodeZero maps to SOCI Act, Privacy Act, and ADHA requirements in your environment

