Healthcare industry continues to face supply chain security and identity management challenges
Cybersecurity firm Fortified Health Security released a mid-year report indicating that the healthcare industry is being overwhelmed by growing cyber threats, with the risk remediation rate dropping sharply from 23% in the same period last year to 6% in the first half of 2026, making supply chain security and identity management two major persistent problems.

Key Takeaways
- The pace of cybersecurity threats is overwhelming healthcare organizations, leaving them especially vulnerable to supply chain attacks—according to security firm Fortified Health Security in its latest mid-year report.。
- Hospitals and other healthcare providers remediated only 6% of risks in the first half of 2026, a sharp decline from 23% in the same period in 2025.
- Fortified's new report focuses on the biggest pain points for healthcare organizations, emphasizing the need for preparedness and outlining the U.S. Department of Health and Human Services'updated Health Insurance Portability and Accountability Act (HIPAA) Security Rulenew requirements.
In-Depth Analysis
Healthcare organizations facesome of the largest cyberattacks in critical infrastructure, and these breaches can also becomethe most costly security incidents. Fortified's new data paints a picture of a healthcare industry struggling against ransomware and other security intrusions.
The report shows that in the first half of 2026, the average healthcare organization encountered 60% more vulnerabilities rated as "high" or "critical" severity compared to the same period in 2025. Organizations are discovering far more issues than they can remediate. The researchers write: "This is not a story of a single catastrophic breach, but one where visibility outpaces processing capacity."
Two areas in cybersecurity continue to plague healthcare organizations: supply chain risk management, and identity management and access control.
Fortified says the number of supply chain risks identified by organizations in the first half of 2026 was six times higher than in the same period in 2025, with nearly two-thirds being high or critical severity vulnerabilities. Hospitals and other healthcare facilities rely ondozens of technology vendors, from hardware manufacturers to software developers, and the Change Healthcare incident has proven that a breach at any single vendor can trigger ripple effects across the entire industry. The report states: "Assessments are exposing third-party risk gaps that many healthcare organizations currently have no response plans for, and once discovered, they struggle to remediate them."
Protecting user accounts from compromise and abuse is also an anxiety-inducing challenge for healthcare organizations. Many organizations lack sufficient security personnel to carefully track employee onboarding and offboarding, and to activate or deactivate their accounts accordingly. Traveling nurses and contract physicians in many healthcare organizations make access control even more difficult, especially for smaller organizations.
According to Fortified's report, the number of identity and access control-related vulnerabilities identified by healthcare organizations in the first six months of 2026 was four times higher than in the same period in 2025.
The researchers write: "We see tangible improvements in organizational processes for identity and access management (IAM), but the underlying work—authenticating users, services, and hardware, as well as protecting, transmitting, and verifying identity assertions—continues to challenge teams."
Fortified notes that in the first half of 2026, 92% of healthcare network domains had at least one administrator account whose password had not been updated in over three years.
While the new report discusses many security challenges, it particularly emphasizes the importance of identity management.
Fortified states: "Identity maintenance will never be the most exciting part of cybersecurity, but it is an extremely critical piece: it closes the door that most attackers use to enter."
The report also covers security mitigation measures forlegacy medical devices. For devices at the end of their lifecycle, such as MRI machines, Fortified recommends: "Isolate those devices that cannot be replaced," urging organizations to place these devices behind strict firewalls and "absolutely never" run outdated devices on domain administrator accounts. "A single forgotten, over-privileged system is enough for an attacker to move laterally to all other systems."
Another key recommendation involves incident response preparedness.
Healthcare organizations are accustomed to handling crises, but responding to cybersecurity incidents requires practice. Fortified says organizations must build "operational muscle memory" before a breach occurs, so they can respond effectively and in a coordinated manner.
Fortified says doctors, nurses, and their teams should conduct cyberattack drills just like firefighters. Even rural fire departments that rarely handle major fires maintain the equipment, staffing, and training standards needed to respond to larger crises. Healthcare organizations should adopt the same approach.
The researchers write: "Emergency responders know a crucial truth: probability does not change responsibility. Ultimately, serious incidents will happen. The only question is whether the organization is operationally prepared when it does."