Top 3 Healthcare Cyber Threats in 2026
Breadcrumb
Cyberattacks against hospitals are growing in scale and sophistication, putting patient care, critical infrastructure, and millions of healthcare records at risk. In this conversation, the American Hospital Association's John Riggi, national advisor for cybersecurity and risk, and Scott Gee, deputy national advisor for cybersecurity and risk, break down the three biggest cyber threats facing healthcare organizations in 2026: geopolitical cyber activity, third-party and supply chain vulnerabilities, and the rapidly evolving risks of artificial intelligence.
View Transcript
00:00:00:06 - 00:00:22:06
Tom Hederal
Welcome to Advancing Health. Cyber attacks from criminal and nation-state hackers directed against health care continues to grow, leading to care delivery disruption and risks to patient safety. In this podcast, two AHA experts discuss today's healthcare cyber threats and what the field should know to defend against cyber attacks.
00:00:22:08 - 00:00:52:22
John Riggi
Welcome to Advancing Health. I'm John Riggi, national advisor for cybersecurity and risk at the American Hospital Association. Since 2020, there have been an enormous amount of cyber attacks against US healthcare. In the period from 2020 to 2025, there are over 3400 breaches reported to HHS Office of Civil Rights, impacting the health care records of 730 million Americans.
00:00:52:22 - 00:01:28:27
John Riggi
I know what you're thinking folks, there's only 330 million Americans. That's right. Statistically speaking, everyone in this country has had their healthcare records stolen or compromised in full or part, at least two times. We believe that at least one third of these reported attacks are actually ransomware attacks, which resulted in the encryption of data and networks, causing significant disruption and delay to health care delivery, posing a direct risk to patient care and safety. But also posing a direct threat to the entire community
00:01:28:27 - 00:01:53:08
John Riggi
that depends on the availability of their nearest hospital in the event of a life threatening emergency. Folks, let's be clear: these type of attacks are not data theft crimes. They are threat to life crimes. And we need to be ready. Joining me today, very pleased to have my colleague Scott Gee, deputy national advisor for Cyber and Risk at the American Hospital Association.
00:01:53:12 - 00:02:10:00
John Riggi
Scott, I spoke a lot about the trends from 2020 to 2025 in general, but there are really some specific patterns from that data about third parties and where the data is actually being stolen from. Can you talk to us a little bit about that, and what are you seeing for 2026?
00:02:10:07 - 00:02:41:10
Scott Gee
Sure, John. So over the 2020 to 2025 period, about 12% of the phi that was stolen was stolen from hospitals or health care systems. The rest was stolen from third party providers or non hospital health care providers. That trend is continuing today. So far in 2026, we're at 11%, roughly, actually about 10.7% of the reported phi has been stolen from hospitals and health care providers.
00:02:41:12 - 00:03:09:16
Scott Gee
The rest has been stolen from third parties. So 376 incidents reported and about 49.9 million people impacted this year alone. So that's on top of the numbers from 2020 through 2025, John. This is going to be a record setting year because we have a couple of major breaches that have been reported in the news, but haven't quite made the OCR statistics yet.
00:03:09:16 - 00:03:11:19
Scott Gee
And that's where this data comes from.
00:03:11:21 - 00:03:33:26
John Riggi
Yeah. Appreciate that, Scott. You know, when you and I chat and we present, as we do quite often and we say in 2026 there's only 50 million Americans who have had their healthcare records stolen. It's just really preposterous that we've become used to these massive data breaches targeting so many Americans. Scott, you and I have been doing this for a long time.
00:03:33:27 - 00:03:56:15
John Riggi
I will say perhaps even longer than we'd like to admit. Decades. We've witnessed the increase sophistication of cyber attacks and cyber threats. Each year in the field really needs to be aware of these key cyber threats so they can better prepare for an attack when their organization occurs. So let's talk about what we see as the three current and very real cyber threats to hospitals.
00:03:56:15 - 00:04:30:25
John Riggi
And really I always start the list with geopolitical tensions. The vast, vast majority of cyber attacks that we face in healthcare originate from foreign nations, specifically our adversarial nations Russia, China, North Korea and Iran. And they're either providing safe harbor for the bad guys, criminal organizations to attack us, to steal our data, to encrypt our networks, to extort us for stolen data, and/or working with nation states to plant potentially destructive malware on a critical infrastructure.
00:04:30:28 - 00:04:47:25
John Riggi
Scott, can you talk to us about really the number two - perhaps number one threat as well - as you talked about third parties? Talk to us a little bit about the cyber risk that originates from insecure third parties, or just our exposure and dependency on third parties.
00:04:47:27 - 00:05:11:13
Scott Gee
John, the thing about third party providers is they are absolutely critical to hospital operations. They're fantastic. They can do things at scale that a hospital couldn't afford to do for themselves necessarily, and they do it very well. The problem is, when we get dependent on those third party providers and they get attacked, it becomes a huge impact to health care delivery, right?
00:05:11:14 - 00:05:38:10
Scott Gee
We don't have to look any further than Change Healthcare or the attack on Stryker, which, by the way, ties into your number one, which was geopolitical tensions. That was Stryker was attacked by a proxy of the Iranian government. And those outages, those third party attacks had effects across the entire healthcare sector. So, you know, it's not just defending your own hospital, defending your own network.
00:05:38:10 - 00:06:00:12
Scott Gee
It's counting on those third parties to be able to defend their networks. And they are facing some incredibly sophisticated attacks. As you often say, the bad guys know where the critical points in our healthcare system are. They know where those weak links are and when they attack them they have significant impact across the sector.
00:06:00:14 - 00:06:35:06
John Riggi
Totally agreed Scott, and thanks for that perspective. You're absolutely right. These aren't happenstance type attacks when Change Healthcare is attacked. And unfortunately, the very significant number of attacks in the news right now as of this recording against mission critical third party providers, the bad guys have mapped our network and they understand our critical third party dependencies. You know, over the years in healthcare, we have moved to third party providers, cloud based providers for very good reasons, certainly improves business sufficiency.
00:06:35:06 - 00:07:04:10
John Riggi
The economics often are better, but it also improves the efficiency of patient care and patient outcomes. So we did this, established this dependency on third parties for very good and noble reasons and really, really not recognizing the potential risk we were creating. And again, the bad guys have mapped our sector. They know who we depend on for key services, supply chain and key technologies.
00:07:04:10 - 00:07:22:18
John Riggi
And speaking about key technologies, let's talk a little bit about what everybody is talking: about artificial intelligence. Scott, can you talk to us a little bit about the threats that we're seeing, the increased risk by the use of artificial intelligence in our networks?
00:07:22:20 - 00:07:49:14
Scott Gee
John, the biggest risk with friendly use of AI, if you will, hospitals and health care systems using AI for their purposes is understanding the data security piece, right? Where is that data actually being stored? Who actually has access to it? Are you contributing to a large language model that is accessible around the world, because you clearly don't want to add sensitive data to something like that.
00:07:49:15 - 00:08:18:10
Scott Gee
The other problem with AI is that the bad guys are using it incredibly well. A couple of months ago, Microsoft published an article about a particular Russian ransomware group, Medusa, using AI, and it was allowing them to develop exploits for published vulnerabilities within 24 hours of that vulnerability being published. That process used to take weeks. They're doing it in a day now.
00:08:18:10 - 00:08:48:13
Scott Gee
So the exponential increase in bad guy capability and what the adversary can do thanks to AI is a significant problem. AI is also being used to really enhance network and internet scanning, so they can scan systems, find those vulnerabilities, and exploit them at machine speed now. That is an adversarial evolution that is going to have some profound effects.
00:08:48:14 - 00:09:15:15
Scott Gee
We saw the article from the heads of cyber agencies across the Five Eyes, the friendly intelligence communities, saying that within months, AI had the potential to overwhelm cyber defenses. That's exactly what we're looking at here. AI is also doing wonders for phishing email crafting, for instance. Used to be easy to spot a phishing email because the person that wrote the email didn't necessarily speak English as a primary language.
00:09:15:22 - 00:09:39:04
Scott Gee
AI doesn't have that problem. It can craft some very effective phishing emails and other social engineering attacks, and they're working very well. So we have challenges on the good guys side of implementing AI safely, and then challenges from the adversarial side of defending against a weapon that is really expanded their capabilities.
00:09:39:12 - 00:10:02:00
John Riggi
Totally agreed, Scott, and it's pretty clear from your remarks and things that we talk about all the time. We are not at the beginning, but in the midst of a cyber arms race. Bad guys are using it to discover vulnerabilities and develop exploits in 24 hours. Believe me, I've never heard of a hospital, for good reason, being able to identify a vulnerability and patch within 24 hours.
00:10:02:01 - 00:10:27:15
John Riggi
Unless it's super, super critical because they have to test the patch. They have to make sure it doesn't cause a malfunction in a patient connected medical device. With all that, though, we really understand the need, despite all the threats in the risk to move to AI, improve patient outcomes, improve the economics of providing health care under this enormously intense financial pressure that hospitals are facing.
00:10:27:15 - 00:11:04:27
John Riggi
And of course, we do know the good guys us, the network defenders, are using AI to help detect and defend against these attacks. Really quickly here, Scott, one of the other emerging threats that we have seen and we talk about every day now, are threats to operational technology. The Iranians in particular, have a long history of demonstrating their intent and capability to attack operational technology that affects water treatment plants, as we just saw a couple of weeks ago, and really exploiting these, what we call vulnerable programable logic controllers.
00:11:05:00 - 00:11:31:26
John Riggi
Programable logic controllers are a piece of hardware that's generally internet connected that governs a mechanical function, like opening a water valve or controlling the water flow or level of chemicals in a water treatment or your HVAC system. So not only are these in present and critical infrastructure, they are present in our hospitals. And Scott, we just as of today, have warned the healthcare field about a particular threat.
00:11:31:27 - 00:11:39:02
John Riggi
Can you talk to us a little bit about PLCs in healthcare and what the threat in mitigation might be?
00:11:39:04 - 00:12:04:09
Scott Gee
The alert is very specific to one particular product, but it's important to understand that those PLCs, as you mentioned, are everywhere in healthcare. Not only are they in water treatment facilities and power facilities and things like that, they're running elevators, they're running HVAC systems, they're running pneumatic tube systems. They're everywhere in a hospital network that has devices that are connected technology.
00:12:04:15 - 00:12:38:24
Scott Gee
The way to defend those, first and foremost is having a cohesive, comprehensive inventory of what you actually have in your network. Sometimes we have run across disconnects between the facilities folks who are hanging technology on the network, and the IT folks who don't realize that that technology is on their network. And there needs to be a joining at the hip of those two teams and get cybersecurity involved to understand the threats that those devices may pose.
00:12:38:25 - 00:13:02:12
Scott Gee
It's not that they shouldn't be there. They're serving incredibly valuable purposes. They're entirely legitimate technology, but they have to be defended. And the best way to defend them, first and foremost, is not connecting them to the outside internet, if possible. If you can put them on a segregated Vlan or something along those lines, keep them away from the outside world.
00:13:02:12 - 00:13:30:13
Scott Gee
That's the first step in defending PLCs. There's really not much of a reason they need to be exposed to the internet in most cases, so that should be an easy, easy fix. But the first step is identified what they are in the network. Once you've identified them, isolated them, then you can talk about patching and maintaining those just like all of the other connected devices on the network.
00:13:30:13 - 00:13:40:03
Scott Gee
So it's a multi-stage problem, but it has to start with identifying those, those devices and where they are and what they're doing.
00:13:40:04 - 00:14:07:25
John Riggi
Yeah. Totally agreed. And you know, all the facility managers you and I speak to, they say but John, Scott, it's so much easier for us to view and control operational technology from our remote iPads and our phones. And it's not just convenience. It really does help quite a bit on the building management systems. But when we're talking fire and safety systems as well, really life critical systems. But they have to understand that the bad guys can see it often, just as they can see it.
00:14:07:25 - 00:14:31:24
John Riggi
And it has provided a pathway by the Iranians targeting hospitals. They have a history of this, so they have to understand it. I think, as we always say, for whatever the issue is, good governance starts with good governance. Setting those policies that operational technology visibility at least should be merged with cybersecurity folks. They should have good inventory visibility and network monitoring.
00:14:31:24 - 00:14:52:25
John Riggi
So we covered quite a bit here. I think in a relatively short time. We just want to thank our listeners really for tuning in today and again, continuing to do what they do every day to defend networks, care for their patients and serve their community. Scott, thanks again for joining me. Thanks for your assistance here to help defend the field.
00:14:52:26 - 00:15:03:09
John Riggi
This has been John Riggi, your national advisor for Cybersecurity and Risk with Scott Gee, deputy national advisor for Cybersecurity and Risk. Thanks, everybody. Stay safe.
00:15:03:12 - 00:15:12:04
Tom Haederle
Thanks for listening to Advancing Health. Please subscribe and rate us five stars on Apple Podcasts, Spotify, or wherever you get your podcasts.