A new mid-year analysis found hospitals are discovering security problems six times faster than they are fixing them, with vendor risk and outdated administrator passwords named as the two biggest gaps.
What happened
Healthcare organizations fixed only 6% of the security risks identified in the first half of 2026, a steep decline from the 23% of risks addressed during the same period in 2025. According to Cybersecurity Dive, researchers found the average healthcare organization encountered 60 percent more critical or high-severity vulnerabilities during the first half of 2026 than during the same period the year before, meaning providers are finding far more problems than their security teams have the capacity to resolve. The analysis identified two areas causing the most difficulty for healthcare providers. Organizations identified six times more supply chain-related risks compared to the first half of 2025, with nearly two-thirds of those risks rated critical or high severity. Identity and access management, the processes organizations use to confirm who is logging into their systems and control what those accounts can do, produced four times more identified vulnerabilities over the same period.
Going deeper
Researchers found that 92% of healthcare network domains had at least one administrator account whose password had not been changed in more than three years. An administrator account carries broad access across an organization's systems, and researchers described identity maintenance as unglamorous but necessary work that closes off one of the most common paths attackers use to move through a network once they gain initial access. The report also addressed legacy medical equipment, such as older MRI machines that cannot be easily replaced or updated, recommending that healthcare organizations place that equipment behind dedicated firewalls and avoid ever running it using accounts that carry administrator-level privileges across the wider network. Researchers described a single forgotten piece of over-privileged legacy equipment as enough on its own to give an attacker a path to move across an entire healthcare network.
What was said
Researchers stated in their report, cited by Cybersecurity Dive, that "this isn't the story of a single catastrophic breach. It's the story of visibility outpacing capacity." On the identity gap specifically, researchers wrote: "Identity maintenance will never be the exciting part of cybersecurity. It is a quiet, extremely critical part of it, though. It closes the doors most attackers walk through." Researchers also framed incident readiness in terms familiar to clinical staff, writing that "emergency responders understand something deeply important: probability does not change responsibility. Eventually, a serious incident will occur. The only question is whether the organization is operationally prepared when it happens."
In the know
The supply chain findings in this report echo what the Change Healthcare breach demonstrated at scale in 2024, when a single vendor's compromise disrupted claims processing and pharmacy operations across the entire US healthcare system. According to the Verizon 2026 Data Breach Investigations Report, third-party involvement in breaches rose 60% year over year and now appears in nearly half of all confirmed breaches, a trend consistent with researchers' finding six times more supply chain risks identified in healthcare specifically during the same period.
The big picture
A remediation rate that fell from 23% to 6% in a single year is not primarily a story about healthcare organizations becoming less capable. It proves that security teams gain more visibility into their own environments through better scanning and assessment tools, then find themselves unable to keep pace with the volume of problems that visibility reveals. For hospital IT and compliance leaders, the practical lesson is that discovering more vulnerabilities without a corresponding increase in remediation capacity does not improve security posture. It documents a widening gap between what an organization knows about its own risk and what it can actually fix, a gap that an attacker exploits regardless of whether the organization was aware the vulnerability existed. According to Paubox's What Healthcare Gets Wrong About HIPAA and Email Security report, many healthcare organizations treat a completed risk assessment as a permanent compliance status rather than the starting point for an ongoing remediation process, a pattern that maps directly onto the growing gap this new data describes.
FAQs
Why would identifying more security risks lead to fewer of them being fixed?
Discovering more vulnerabilities does not automatically come with more staff or budget to address them. When the volume of identified problems grows faster than an organization's security team can grow, the remediation rate falls even if the team is working just as hard, because there are simply more items competing for the same limited capacity.
Why does a three-year-old administrator password matter so much to overall security?
An administrator account has broad access across an organization's network. A password that has not been changed in three years has had far more time to be exposed through data breaches at other services, guessed through automated attacks, or shared inappropriately, all while carrying the same level of access it always had.
Why is legacy medical equipment treated as a specific security category rather than a general IT problem?
Equipment such as older MRI machines often cannot be patched or updated the way a standard computer can, either because the manufacturer no longer supports it or because modifying it could affect its clinical function. That means the standard defense of applying security updates is unavailable, making network isolation and restricted account privileges the primary tools for managing the risk instead.
What does "operational muscle memory" mean in the context of incident response?
It refers to the idea that responding effectively to a crisis requires practiced coordination developed before the crisis happens, not decisions made for the first time during the actual event. Fire departments train and drill even for large fires they may never experience, so that when one does occur, the response is automatic rather than improvised under pressure.
How does the supply chain risk finding connect to the Change Healthcare breach?
The Change Healthcare incident showed how a single vendor's security failure can disrupt an entire industry's operations, since so many hospitals and pharmacies depended on that one company's systems for claims processing. The sharp increase in identified supply chain risks in this report suggests healthcare organizations are only now beginning to systematically assess how many similar single points of failure exist across their own vendor relationships.
