Hackers Are Targeting the Companies Behind Your Hospital, Not Just the Hospital Itself

Attacks on healthcare vendors and billing firms surged 110% in a year. Criminals have worked out that one breach can reach hundreds of hospitals at once.

ThreatVectr NewsdeskAI-assistedPublished Updated · Editor: Lee Brown· 3 min read
Illustration: Interior of a modern hospital server room bathed in cool blue LED light
Illustration made with AI. Not a photograph of the events described.
Share

Key points

  • Cyberattacks on the healthcare sector rose 14% in the first half of 2026 compared with the same period in 2025, according to technology research firm Comparitech.
  • Attacks on healthcare vendors and suppliers jumped 110% year-on-year and 35% compared with the second half of 2025.
  • A ransomware attack in February 2026 forced the University of Mississippi Medical Center to shut down network access across all 35 of its facilities.
  • In February 2026, TriZetto Provider Solutions disclosed a data breach affecting 3.4 million patients at its customers' hospitals and clinics.
  • The FBI's Internet Crime Complaint Center reported in April 2026 that healthcare was the most attacked critical-infrastructure sector in the United States in 2025.

Criminals who target hospitals have found a smarter shortcut: go after the companies that service them instead.

Medical billing firms and IT vendors sit at the centre of healthcare networks, often holding data for hundreds of hospitals at once. That calculation is reshaping where ransomware attacks, where criminals use malicious software to lock a victim's files and demand payment for the key, are landing.

According to Comparitech, a technology research firm that tracks publicly reported breaches, attacks on healthcare vendors surged 110% in the first half of 2026 compared with the same six months of 2025. Healthcare providers saw 247 confirmed or suspected attacks in that period; healthcare businesses saw 163. The providers' numbers are larger, but it's the vendors whose count more than doubled in a year.

Why are suppliers being targeted instead of hospitals?

One breach can do more damage. Rebecca Moody, head of data research at Comparitech, put it plainly: through a single central supplier, criminals reach multiple healthcare organisations holding enormous databases or providing third-party services to hundreds of hospitals. More stolen data means more pressure to pay, which means a bigger payday.

The ransomware-as-a-service model, where criminal groups rent their attack tools to other criminals in exchange for a cut of any ransom, has widened the pool of people capable of running these attacks. Barriers to entry are lower than they've ever been.

Hospitals remain attractive for a specific reason: the consequences of refusing to pay are uniquely severe. A 2024 Microsoft study found that a ransomware attack at a hospital typically increases patient volume by 15%, stretches waiting-room time by nearly 50%, and is associated with a 113% rise in confirmed strokes and an 81% rise in cardiac arrests in affected areas. Researchers call deaths linked to care disruptions "excess deaths." That pressure makes hospitals more likely to pay, which draws more criminals in.

Errol Weiss, chief security officer at Health-ISAC, an information-sharing body for the healthcare industry, says weak remote-access controls and missing multi-factor authentication, where a login requires a second proof of identity such as a text-message code, still give attackers easy ways in. Legacy medical devices, equipment running outdated software that can't easily be updated, add to the problem. Our coverage of the ShinyHunters breach at Medtronic on 3 July showed exactly how a single vendor compromise translates into millions of patient records exposed.

Should you worry?

If you're a patient, watch for letters or emails from a hospital or billing company telling you that your personal or health information was exposed. Placing a free fraud alert with a credit bureau is a straightforward first step. You can't stop a hospital supplier from being attacked, but acting quickly if your data surfaces somewhere it shouldn't still matters.

The pattern here is the one worth watching: as long as one vendor breach can reach hundreds of hospitals at once, attackers have every reason to keep pulling on that thread rather than knocking on each hospital's door individually.

© 2026 Threat Vectr