Healthcare Cybersecurity Alert: 385M Patient Records Exposed, Experts Urge Stronger Defenses
The healthcare industry faces increased cyberattack risks due to the widespread adoption of electronic records and digital services. Federal data shows that 385 million patient records have been exposed from 2010 to 2022. Experts urge organizations to strengthen security and call on regulators to raise standards.

Healthcare organizations are increasingly using electronic records and digital services, which creates more opportunities for cybercriminals—who have already exposed the private medical information of millions of patients—and experts say this further highlights the need for the industry to prioritize security.
Federal records show that between 2010 and 2022, data breaches in the healthcare industry exposed 385 million patient records, but individual patient records may have been counted multiple times.
Over the past five years, hacking incidents at healthcare organizations—a type of breach—have surged, with cybercriminals demanding ransom payments in exchange for restoring access to sensitive medical data.
Hacking or IT incidents are the most common type of breach
Other types include unauthorized access/disclosure, theft, loss, and improper disclosure. Experts told Healthcare Dive that given the increase in breaches and cyberattacks, healthcare organizations must improve cybersecurity, while regulators also need to raise cybersecurity standards.
"Can these organizations do better? Absolutely," said Jim Trainor, a former assistant director of the FBI's Cyber Division and now a senior vice president at Aon Cyber Solutions, a global professional services firm.
Disrupting any of the 16 critical infrastructure sectors in the U.S., including healthcare, poses a national security threat. According to the U.S. Cybersecurity and Infrastructure Security Agency (CISA), these sectors are vital to the daily lives of millions of Americans, and paralyzing them would have a "debilitating effect" on society.
Cyberattacks that disrupt hospital operations can put patients' lives at risk. The FBI says the healthcare industry suffered the most severe ransomware attacks in 2021 compared to other critical infrastructure. The threat comes as hospitals face staffing shortages and financial pressures exacerbated by the COVID-19 pandemic.
Last year, following a ransomware attack on one of the largest hospital operators in the U.S., Healthcare Dive analyzed more than 5,000 breaches reported to the HHS Office for Civil Rights over the past 13 years. That agency enforces privacy and security laws in the healthcare industry.
A breach is a broad term referring to the improper disclosure or use of identifiable patient protected health information. According to HHS, hacking or IT incidents are a type of breach involving technical intrusion and are just one of the breach types tracked by the agency.
Since reporting began in 2009, the number of breaches has increased almost every year. Healthcare Dive's analysis is limited to breaches affecting more than 500 individuals each.
- The number of breaches reported annually increased from nearly 200 in 2010 (the first full year data was available) to over 700 in 2022, more than tripling.
- In 2022, the private health information of more than 52 million people* was exposed in over 700 breaches, compared to about 6 million in 2010.*An individual may be counted multiple times if exposed in multiple breaches.
- If the 2015 Anthem breach is excluded, the upward trend is even more pronounced.
- Since 2018, the size of each breach (i.e., the median number of people affected per incident) has also risen significantly. The median is the midpoint between the largest and smallest breaches and is less affected by outliers.
- Last year, the median breach affected more than 6,200 people, more than double the median breach size in 2018.
Breaches can vary greatly in the number of people affected.
The vast majority of reported breaches affect fewer than 65,000 people. The second-largest breach disclosed since reporting began in late 2009 affected 11.5 million people. The largest breach occurred in 2015, exposing the private health information of nearly 79 million people through a cyberattack on Anthem, one of the largest insurers in the U.S. Regulators found that Anthem (now named Elevance) did not have adequate protections to defend against cyberattacks. Anthem later agreed to a $16 million settlement with HHS OCR.
Cyber attackers infiltrated Anthem's IT systems through spear-phishing emails sent to an Anthem subsidiary. According to HHS OCR, the attackers stole patient information, including full names, Social Security numbers, addresses, dates of birth, email addresses, and employment information.
Health insurers, providers, clearinghouses, and business associates must notify HHS OCR when a breach occurs. If a breach affects the private health information of more than 500 people, covered entities have 60 days to notify regulators.
The increase in breaches coincides with the healthcare industry's growing adoption of digital services over the past decade and greater reliance on health information technology. In particular, hospital use of electronic health records (EHRs) has surged since 2010, when providers began leveraging federal incentive programs that provided billions of dollars to institutions that chose to adopt EHRs.
However, this connectivity can lead to network vulnerabilities and create pathways for accessing protected data, experts say.
During a single care process, multiple entities may access patient information, including doctors, hospitals, X-ray facilities, and insurers, said Trainor of Aon Cyber Solutions. "The network complexity that facilitates these events is incredible," Trainor said.
The rise of remote work provides more entry points for attackers
During the pandemic, hospital departments became more vulnerable, which greatly accelerated the use of networks and internet-connected devices, said John Riggi, cybersecurity advisor for the American Hospital Association. As non-clinical staff shifted to working from home, hospitals increased their reliance on third-party and cloud services.
This led to an "expanded digital attack surface," said Riggi, who previously served as an FBI division chief responsible for cyber issues. Hospitals' reliance on third-party technology also makes them more vulnerable because they cannot fully control the security of third-party tools. As a result, hospitals must wait for vendors to send patches for connected medical devices and cannot fix problems themselves.
"The chain is only as strong as its weakest link, and there are too many weak links." — Israel Barak, Chief Information Security Officer at Cybereason
"The key is that we are under attack by foreign adversaries. The vast majority of breached records come from hostile actions, i.e., foreign adversaries that even the FBI cannot reach," Riggi said. "Protecting this expanded attack surface under this intensified attack during the pandemic became very, very difficult," Riggi added.
Israel Barak, Chief Information Security Officer at Boston-based cybersecurity company Cybereason, added that many healthcare organizations lack robust cybersecurity programs. "The chain is only as strong as its weakest link, and there are too many weak links," Barak said. This makes the healthcare industry an easy and profitable target for cyber attackers, he added.
When a breach occurs, "the blast radius is larger due to information sharing," said Christina Powers, a partner at West Monroe who leads the firm's private equity cybersecurity consulting practice. This may explain why the average breach size has surged in recent years, Powers added.
Of course, not all breaches are the result of cyberattacks. The federal government tracks several types of breaches: hacking/IT incidents (which may include cyberattacks), improper disposal, loss, theft, and unauthorized access/disclosure. The second most common type of breach in recent years is unauthorized access or disclosure, which can occur when employees access records outside their job duties. It can also include exposing patient information through misdirected communications. Other types include loss or theft, such as laptops or USB drives being left in public places or stolen.
Data-rich and profitable targets
Ransomware attacks are the top threat facing the industry because healthcare organizations are profitable targets, security experts say. In a ransomware attack, hackers lock and hold hostage a healthcare organization's files and critical information while demanding a ransom payment in exchange for the decryption key to unlock the files.
Cybercriminals know that healthcare organizations will feel pressure to quickly restore access to life-saving systems and technology. When disruption threatens patient care, such as emergency rooms closing or facilities being forced to transfer patients, providers are more likely to pay the ransom, said Trainor of Aon Cyber Solutions. The FBI warns that these attacks can put patients at risk by delaying access to care and vital information.
According to The Wall Street Journal, a newborn allegedly died as a result of a ransomware attack that disabled computers on every floor of an Alabama hospital and drained resources. The report said Teiranni Kidd's daughter died months after a delivery complicated by a nuchal cord.
A 2021 survey of nearly 600 IT and health executives at provider organizations showed that ransomware attacks had a significant impact on patient care. Among institutions that suffered ransomware attacks, most reported longer hospital stays, delays in procedures and tests, and referrals. More than a third of respondents mentioned increased complications, and nearly a quarter noted higher mortality rates.
For ransomware criminals, "it's all about return on investment"
Researchers have found that ransomware attacks against healthcare organizations have increased in frequency and severity since 2016, tracked through the database THREAT (Tracking Healthcare Ransomware Events and Characteristics). "For these criminals, it's all about return on investment," Trainor said.
Moreover, it is difficult to deter bad actors, who can launch attacks from other countries, often beyond the jurisdiction of U.S. law enforcement, security experts say. In September, three Iranians were charged with attempting to launch a cyberattack on Boston Children's Hospital, one of the largest pediatric medical centers in the country. FBI Director Christopher Wray later described the attempted attack as "one of the most despicable cyberattacks I've ever seen."
Although the FBI intervened before the attack was carried out, the incident raised concerns about state-sponsored attacks on U.S. healthcare operators. "I do think we need to be prepared for destructive or devastating attacks that nation-states could launch against the healthcare industry," said Morgan Demboski, a threat intelligence analyst at IronNet, a cybersecurity company based in McLean, Virginia. Attacks could also be for cyber espionage purposes, Demboski added. Some countries aim to steal vaccine-related information and medical research related to COVID-19 to boost their own commercial sectors, Demboski said.
In this threat environment, healthcare organizations should upgrade their cyber readiness and may need a push from federal regulators, security experts say.
"...The level of security across the industry is not yet sufficient to protect patients' medical information." — Jim Trainor, Senior Vice President at Aon Cyber Solutions
On March 1, U.S. President Joe Biden unveiled a comprehensive national cybersecurity strategy aimed at improving the nation's cyber defenses. The policy goals call for establishing minimum cybersecurity standards in critical infrastructure, including the healthcare industry. Although not an executive order, the policy plan will serve as a guide for federal agencies and lawmakers in developing cyber requirements.
Raising cybersecurity standards is crucial for healthcare organizations, security experts say. "I think we need to set higher regulatory standards for healthcare organizations," said Barak of Cybereason. Of course, raising standards could have financial consequences for hospitals and potentially increase healthcare prices, Trainor said. Nevertheless, Trainor added, "the level of security across the industry is not yet sufficient to protect patients' medical information."
Methodology
Healthcare Dive downloaded the health breach dataset from HHS (Archive -> Research Reports) on March 2, 2023. The data serves as a living document, and OCR may update it after each investigation. Covered entities have 60 days to report breaches affecting more than 500 people to OCR. Breaches involving fewer than 500 people may be reported annually and are not included in the downloadable data. The breach dates mentioned in the charts refer to the dates the breach reports were submitted.
News graphics developer Julia Himmel and visuals editor Shaun Lucas also contributed to this article.
