DrochaidHorizon3.ai
NodeZero/Industries/Healthcare
The state of play — Healthcare, 2026

Attackers succeed in 95% of Healthcare incidents ASD responds to.

Healthcare is the most-breached sector in Australian OAIC data, with ransomware incidents doubling year-on-year. Over 80% of stolen US health records were taken from third-party vendors and software services — not from hospitals themselves.

95%
of ACSC-responded healthcare incidents in FY2024–25 saw attackers succeed — compared with 52% across all sectors. Ransomware incidents against Australian healthcare doubled year-on-year.
ASD Annual Cyber Threat Report 2024–25
80%+
of stolen US protected health information records in 2024 were taken from third-party vendors, software services, and business associates — not from hospitals themselves.
American Hospital Association — 2025 Cybersecurity Year in Review
USD $7.42M
average cost of a healthcare data breach in 2025 — the highest of any sector for the 14th consecutive year.
IBM Cost of a Data Breach Report 2025
The trend

Why Healthcare is in the crosshairs

Five shifts shaping the healthcare threat environment — drawn from ASD, OAIC, AHA, Sophos, and Verizon reporting.

Most-targeted in the US, most-breached in Australia — and attackers succeed when they try

The FBI's 2025 Internet Crime Report puts healthcare and public health first among US critical infrastructure sectors for ransomware and data-breach complaints; OAIC data puts health first in Australia; ASD's 95% attacker-success rate against ACSC-responded healthcare incidents is the kill shot. Detection alone is not closing the gap — attackers get in, move, and exfiltrate successfully in nearly every incident serious enough for the ACSC to respond to.

The third-party dependency problem is acute

The AHA's finding that more than 80% of stolen US PHI came from vendors — not hospitals — reframes the defensive picture. A hospital can have strong internal controls and still be exposed by a pathology provider (Synnovis), a claims processor (Change Healthcare), an e-prescription service (MediSecure), or an imaging vendor. Verizon's 2025 DBIR confirms third-party involvement in breaches doubled year-on-year.

Downtime is a life-safety issue

AHA's John Riggi describes ransomware targeting of healthcare as "threat-to-life crime". Hospitals face maximum pressure to pay because operational downtime has immediate patient-safety consequences. King's College Hospital NHS Foundation Trust found the 2024 Synnovis/NHS London attack was a contributing factor in a patient's death, and the 2020 Düsseldorf University Hospital attack forced patient diversions during life-threatening emergencies.

The attack surface keeps expanding

Electronic health records, Internet of Medical Things devices, telehealth platforms, patient portals, genomic databases, and aged care sensor networks have all been added to the attack surface in the last five years. Medical device refresh cycles are slow — so Verizon's edge-device finding (exploitation-via-edge-device breaches rising from 3% to 22%) applies with particular force in healthcare.

Paying is declining — but validation is the next step

Sophos' 2025 data shows ransom payment in healthcare has dropped from 61% in 2022 to 36% in 2025, and recovery costs (excluding any ransom) have fallen 60%. The sector is investing in backups, segmentation, and response preparation. The next step is continuous validation that those investments actually hold under current attacker tradecraft.

On the record

What regulators and experts are saying

The Change Healthcare cyberattack is the most significant and consequential incident of its kind against the U.S. healthcare system in history.
Rick Pollack
President and CEO, American Hospital Association
2024
The vast majority are perpetrated by foreign ransomware gangs, primarily Russian-speaking groups, which specifically target health care hoping for a big payout. They know these attacks cause disruptions and delays to digitally dependent health care delivery, posing a risk to patient and community safety… These despicable acts are in fact threat-to-life crimes.
John Riggi
AHA National Advisor for Cybersecurity and Risk
April 2026
Time is of the essence with data breaches. The risk of serious harm often increases as days pass. Timely notification ensures people are informed and can take steps to protect themselves.
Carly Kind
Privacy Commissioner
2025
What is now required

Healthcare is a SOCI Act critical infrastructure sector

Hospitals with a general intensive care unit are designated critical infrastructure with risk management program obligations, and ransomware payment reporting is mandatory under the Cyber Security Act 2024

Healthcare entities operating designated critical infrastructure assets are subject to the SOCI Act CIRMP obligations — hospitals with a general intensive care unit, or entities designated by the Minister. The CIRMP must address four hazard vectors: cyber and information security, personnel, supply chain, and physical security. For the cyber hazard vector, entities must adopt one of five approved frameworks. Healthcare entities also face obligations under the Privacy Act 1988 (including the notifiable data breach scheme), the My Health Records Act 2012 for systems connecting to My Health Record, and the National Safety and Quality Health Service (NSQHS) Standards. Not all healthcare entities are SOCI-designated — those that aren't may still adopt the Essential Eight voluntarily as a baseline.

Legislation
SOCI Act — Critical Infrastructure Risk Management Program

Federal legislation that designates healthcare as a critical infrastructure sector. Entities operating designated hospitals -- those with a general intensive care unit -- must maintain a CIRMP addressing four hazard vectors: cyber, personnel, supply chain, and physical security. NodeZero directly validates controls under the cyber hazard vector across clinical and administrative networks, and tests supplier segmentation under the supply chain vector. For the cyber vector specifically, entities must also adopt one of five approved frameworks which define the detailed technical controls.

Your chosen CIRMP cyber frameworkSelect one
Also in effect

A cascade of new obligations

Multiple new regulatory requirements are hitting simultaneously — each increasing the compliance burden and the consequences of failure.

Cyber Security Act 2024

30 May 2025

Mandatory reporting of ransomware payments within 72 hours for entities over $3M turnover. Healthcare organisations are prime ransomware targets — clinical systems cannot wait weeks for recovery. NodeZero identifies ransomware attack paths before real attackers do.

Privacy Act statutory tort

10 Jun 2025

Private right of action for serious privacy invasions. Healthcare organisations hold the most sensitive personal information — clinical history, Medicare records, mental health data. A breach triggers both regulatory action and direct litigation.

SOCI Act — Healthcare critical infrastructure

In effect

Hospitals with a general intensive care unit are designated critical infrastructure. Mandatory risk management programs and incident reporting to the Australian Cyber Security Centre.

Strengthened Aged Care Quality Standards

1 Nov 2025

Updated standards from 1 November 2025 emphasise proactive cyber security capability and incident response readiness. Aged care facilities are frequent ransomware targets with low IT maturity.

Platform credentials

The only autonomous pentesting platform that is:

Essential Eight
Mapped ML1–3
ASD baseline
Privacy Act
Reachability proof
My Health Records
Gartner Peer Insights
4.7 / 5
Customers' Choice (Oct 2025)
310,332
Pentests run
7,013 orgs
Trusted by 7,013 organisations worldwide
Powers the NSA's CAPT program310,332 pentests4.7 Gartner

Prove your healthcare security posture before the next assessment

See how NodeZero maps to SOCI Act, Privacy Act, and ADHA requirements in your environment