Report: State of Cyber Risk in Healthcare


In this new research report, RiskRecon teamed up with Cyentia Institute and
Health-ISAC to diagnose the digital risk factors facing healthcare providers
and share important results from this research to aid those managing
cyber risk in the healthcare sector.
Key findings include:
- Healthcare boasts one of the highest average rates of severe security findings.
- The rate of severe security findings in the smallest providers is 3x higher than that of the largest providers.
- The industry average rate of severe security exposures in critical cloud-based assets is 10x that of assets hosted on-premises.
Page 9 of the report
A note from Errol Weiss, CSO at H-ISAC
“In 2020, Health-ISAC members across healthcare delivery, big pharma, payers and medical device manufacturers saw increased cyber risks across their evolving and sometimes unfamiliar supply chains. Adjusting to the new operating environment presented by COVID-19 forced healthcare companies to rapidly innovate and adopt solutions like cloud technology that also added risk with an expanded digital footprint to new suppliers and partners with access to sensitive patient data. This report is an important read for any CISO or third-party risk practitioner to gain insights on measuring risk surface in the healthcare industry.”
Read the full report here:
- Related Resources & News
- Healthcare finance trends for 2026: A mid-year update
- Threat Actor Playbook: Conversational Social Engineering in Care Settings
- The Human Risk Layer of AI
- Cybersecurity in the Lab
- Operation Vital Signs: First-of-its-kind exercise stress tests health sector cyber resilience
- What’s in America’s Code?
- Introducing AI Agents to Your Identity Fabric
- Cyberattacks on Healthcare Sector Jumped 14% in First Half of 2026
- What do cybersecurity leaders want in staff? These 3 skills beat certifications and experience
- Continuous attack surface monitoring and sophisticated social engineering assessment