For years, healthcare security conversations have started with the same assumption: attackers want patient data because it is valuable.
That is still true, but it is not the whole story anymore.
For some attacks, operational downtime can create leverage, alongside or without the theft of patient data. According to data cited by Dark Reading, cyberattacks targeting healthcare organizations increased 14% in the first half of 2026, compared with an 11% increase across industries overall.
That dependency is now part of healthcare’s threat model. A hospital is not just an enterprise with unusually sensitive databases. It is a service environment where care depends on electronic health records, imaging, scheduling, communications, identity systems, and the clinical workflows that connect them.
When those systems stop working, the impact is not abstract. Clinicians lose access to the tools and context they need to keep care moving.
Attackers understand this imbalance. A retailer may be able to take an application offline while engineers investigate suspicious activity. A hospital has to weigh the same decision against delayed appointments, inaccessible records, and clinical staff being pushed onto slower manual processes. When containment itself can disrupt care, attackers gain leverage before they encrypt a single machine.
Downtime is the new extortion pressure point
Ransomware has always relied on creating chaos, but healthcare offers an unusually effective pressure point: time. An organization can replace a stolen password or investigate exposed data. It cannot recover the hours lost to delayed procedures, interrupted workflows, or clinicians being locked out of critical systems.
Recent incidents show how quickly destructive attacks can move beyond data theft. The cyberattack against Stryker earlier this year reportedly wiped systems and devices across the company, forcing a large-scale recovery effort. In incidents like that, the work is not limited to restoring lost files. Teams have to rebuild trust across identities, endpoints, and systems before normal operations can safely resume.
The Stryker attack shows how disruptive a cyber incident can be across the medical technology that supports care delivery. For hospitals, the same recovery challenge comes with even greater urgency. Every additional hour a provider spends validating systems competes with the need to keep care moving.
Security planning cannot revolve solely around keeping attackers out. Healthcare organizations also need to determine how much damage one successful intrusion can cause before it’s contained.
A hospital’s attack surface doesn’t end at the hospital
Interdependence gives attackers another way to cause disruption.
Modern healthcare operates within an interconnected ecosystem of laboratories, pharmacies, insurers, physician groups, medical device manufacturers, cloud platforms, and billing services. Many exchange sensitive information or maintain trusted connections into one another’s environments. An incident at any of them can disrupt essential hospital workflows, even when the hospital’s own network is never breached.
A breach at a shared provider need not affect a hospital’s network to cause real disruption. Teams may still need to rotate credentials, examine exposed records, monitor for phishing, validate integrations, and determine whether previously trusted connections remain safe. Smaller healthcare providers are especially vulnerable to these ripple effects because the same people responding to the incident are often the ones keeping day-to-day technology running.
Healthcare organizations shouldn’t treat a vendor compromise as somebody else’s cleanup. They need to ask themselves: If one partner, account, or endpoint is compromised, where can the attacker go next?
Build for a smaller blast radius
Traditional prevention is still important and effective. Phishing-resistant authentication, patching, endpoint protection, monitoring, and good access controls all reduce the likelihood of an intrusion. That said, prevention cannot carry the entire security strategy because no control eliminates the possibility of a successful intrusion.
Segmentation should separate clinical systems from corporate networks and unnecessary vendor pathways. Privileged access should be narrow enough that compromising a single administrator does not grant an attacker access to the entire environment. The goal is not just to stop the first foothold; it is to make sure that foothold cannot become enterprise-wide access.
Healthcare organizations need an accurate map of critical systems, privileged accounts, third-party connections, and the dependencies between clinical and corporate environments. They should know where sensitive data is stored, who can access it, which systems support patient-facing workflows, and what would break if a connection were severed. Trying to build that map after an intrusion has already started wastes time organizations cannot afford.
Too many tabletop exercises focus on whether the initial access can be detected. They should also test how far a compromise can spread within minutes and whether teams can contain it without disrupting care. If one access point can expose most of the organization, the real problem is the blast radius behind that first foothold.
Recovery needs to keep care moving
Healthcare also needs a broader definition of recovery. Immutable backups are essential, but restoring data is not the same as restoring operations. Identity, device access, privileged controls, and system trust often have to be re-established before clinical workflows can safely come back online.
Recovery plans should account for how clinical operations continue while technical work is underway. Which systems come back first? How long can specific workflows run manually? How will staff communicate if normal channels disappear? Who has the authority to isolate a system when the security decision could affect patient care?
Those questions are much easier to answer during a proactive tabletop exercise than at 3 a.m. in the midst of an active ransomware event.
Cyber resilience is becoming part of patient care
Healthcare will always have characteristics attackers can exploit. Sensitive information has to be collected. Older medical technology can’t always be patched on a convenient schedule. Third parties aren’t going away. Hospitals can’t close whenever cyber risk rises.
Security programs have to work within those realities. The organizations best prepared for the next wave of healthcare attacks won’t be the ones promising that nothing will ever get through. They’ll know where an intrusion can spread, how quickly they can isolate it, and how to keep essential operations running during recovery.
Healthcare security programs have to protect continuity as deliberately as they protect data. The next successful intrusion should not be able to decide whether care continues.
Also read: For more on how cyberattacks can disrupt patient care, read about the UMMC ransomware attack.





