Healthcare Ransomware Attacks Surge 14%
Healthcare cyberattacks show no sign of slowing in 2026. A new report from Comparitech recorded a 14% rise in healthcare ransomware attacks, from 360 in the second half of 2025 to 410 in the first half of 2026, averaging 2.3 attacks per day worldwide.
Of the 410 recorded attacks, 247 targeted hospitals, clinics, and other direct care providers, while 163 hit other healthcare businesses such as pharmaceutical manufacturers, health tech companies, and medical billing providers.
The overall increase was driven mainly by attacks on healthcare businesses and vendors rather than care providers themselves. Attacks on healthcare providers worldwide rose just 3% from the second half of 2025, while attacks on healthcare businesses jumped 36%. In the US specifically, attacks on providers actually fell by more than 7%.
Even so, the US recorded the highest number of attacks overall, 225 of the 410 globally. The most active threat groups in the first half of 2026 were Qilin, The Gentlemen, LockBit, and INC, according to the report.
Other research reinforces the trend. A Fortified Health Security report found a 60% increase in critical and high-risk vulnerability findings in the first half of 2026 compared to the prior year. While this suggests organizations are getting better at identifying risks, remediation has lagged badly: only 6.4% of risks were remediated in the first quarter of 2026, down sharply from 23.3% in the same period of 2025.
Adding to the pressure, the NSA and international cybersecurity partners warned on July 13 that Russian state-sponsored hackers are exploiting poorly configured networking devices worldwide, actively compromising critical infrastructure networks, with healthcare named among the sectors most at risk.
Meanwhile, regulatory relief is stalled. A proposed update to the HIPAA Security Rule, which would have mandated annual penetration testing, stricter risk analysis, and multifactor authentication, has been delayed from May 2026 to July 2027, following pushback from over 100 hospital systems and provider associations.
OCR Director Paula Stannard maintained that "there's a very high cost of doing nothing," leaving healthcare organizations to navigate rising threats without updated federal requirements for at least another year.
See What’s Next in Tech With the Fast Forward Newsletter
Tweets From @varindiamag
Nothing to see here - yet
When they Tweet, their Tweets will show up here.




