Full Report
These are the top cybersecurity threats in healthcare, according to Huntress’s 2025 survey of IT pros. Read the full report and learn how to avoid them.
Analysis Summary
# Incident Report: 2025 Healthcare Sector Threat Landscape
## Executive Summary
Healthcare organizations are facing a surge in cyberattacks driven by the high value of sensitive, unchangeable patient data (e.g., SSNs and medical histories). While IT professionals identify data breaches as their primary concern, phishing remains the most frequent attack vector. The primary impact is the significant disruption of patient care and long-term identity theft risks for affected individuals.
## Incident Details
- **Discovery Date:** March 4, 2025 (Report Publication)
- **Incident Date:** Survey covering 2024–2025 trends
- **Affected Organization:** Multiple (Aggregated survey of 500+ IT professionals)
- **Sector:** Healthcare
- **Geography:** Global/North America
## Timeline of Events
### Initial Access
- **Date/Time:** Ongoing (Reported over the last 12 months)
- **Vector:** Phishing (reported by 40% of organizations)
- **Details:** Attackers leverage deceptive emails to harvest credentials or deliver malware payloads to healthcare staff.
### Lateral Movement
- **Details:** While specific technical logs are not detailed in the summary, the report notes that decentralized data across smartphones, medical devices, and online portals provides a broad attack surface for movement after initial compromise.
### Data Exfiltration/Impact
- **Details:** Significant historical impacts cited include the 2024 Change Healthcare breach (190M individuals) and the Kaiser incident (13.4M individuals). Impact involves the theft of SSNs, test results, and medical conditions.
### Detection & Response
- **How it was discovered:** Managed security monitoring and internal IT audits.
- **Response actions taken:** 37% of organizations are prioritizing enhanced employee training for 2025 to mitigate the human element of these attacks.
## Attack Methodology
- **Initial Access:** Phishing (40%), Denial-of-Service (12%)
- **Persistence:** Not explicitly detailed; likely via credential theft.
- **Privilege Escalation:** Exploiting administrative credentials gained through phishing.
- **Defense Evasion:** Use of legitimate remote work tools and decentralized platforms to blend in with normal traffic.
- **Credential Access:** Phishing and harvesting from unauthorized access incidents.
- **Discovery:** Scanning decentralized data platforms and smartphones.
- **Lateral Movement:** Moving from administrative/IT systems to patient record databases.
- **Collection:** Gathering highly personal, unchangeable sensitive information (SSNs, medical history).
- **Exfiltration:** Unauthorized access to cloud platforms and patient portals.
- **Impact:** Disruption of patient care (Top impact), ransomware, and long-term identity theft.
## Impact Assessment
- **Financial:** High; historical incidents (Change Healthcare) cost billions in operational losses and recovery.
- **Data Breach:** Massive volumes (9.2M to 190M records per major incident).
- **Operational:** Disruption of prescription fillings, virtual appointments, and clinical safety.
- **Reputational:** High risk due to the sensitive and private nature of medical information.
## Indicators of Compromise
- **Network indicators:** Unusual traffic to unauthorized cloud storage or external domains (e.g., [.]io or [.]com extensions from internal medical devices).
- **File indicators:** Malware infections (reported by 19% of organizations).
- **Behavioral indicators:** Surge in login attempts on patient portals; unauthorized access to SSN-containing databases.
## Response Actions
- **Containment measures:** Isolation of compromised remote work environments and identity verification resets.
- **Eradication steps:** Removal of malware payloads and decommissioning of unauthorized access points.
- **Recovery actions:** Implementation of the Health Infrastructure Security and Accountability Act standards.
## Lessons Learned
- **Key takeaways:** Decentralized data increases the attack surface; employee training is the most critical missing link.
- **What could have been done better:** Better management of supply chain risks (only 5% of professionals were concerned despite high actual risk) and more consistent security across mobile/remote devices.
## Recommendations
- **Prevention measures:**
- Implement mandatory multi-factor authentication (MFA) to combat phishing.
- Conduct frequent, specialized cybersecurity awareness training for all healthcare staff.
- Centralize data monitoring to ensure consistent security policy enforcement across all devices.
- Adopt the new HHS guidelines for healthcare infrastructure security.