According to the FBI in its 2025 IC3 Annual Report, the healthcare industry ranked as the top targeted sector for cyber threats in 2025, with 460 known ransomware attacks and 182 data breaches. Cybercriminals target healthcare because patients’ PHI is central to proper patient care. A single compromise can cause a long list of issues for a healthcare organization, and unluckily, the healthcare industry has numerous threat vectors prime for an attack.

Hackers know that disabling a health network can make it difficult for healthcare organizations to properly treat patients. That’s why it's not unheard of for a covered entity to pay a ransom to have its systems restored, even though there are indications that organizations making ransom payments are changing. Financial gain remains the primary motivation for healthcare data theft due to the opportunities for multiple forms of fraud. Criminal marketplace pricing clearly demonstrates the demand: a driver’s license reportedly sells for about $20, while a complete identity package can sell for $1,000. Stolen PHI can be used for identity theft and to impersonate patients needing medical services.

 

What is a healthcare vendor?

The Health Insurance Portability and Accountability Act (HIPAA) sets national standards that safeguard the privacy and security of PHI. The legislation applies to healthcare organizations, called covered entities, as well as their vendors, called business associates. HIPAA compliance is a legal requirement that protects patients’ privacy and ultimately lets providers focus on patient care.

According to the U.S. Department of Health & Human Services (HHS), a business associate is a person or entity that performs certain functions or activities that involve the use or disclosure of PHI for a covered entity. The department further states that “the Privacy Rule allows covered providers and health plans to disclose [PHI] to these ‘business associates’ if the providers or plans obtain satisfactory assurances that the business associate will use the information only for the purposes for which it was engaged by the covered entity, will safeguard the information from misuse, and will help the covered entity comply with some of the covered entity’s duties under the Privacy Rule.” Vendors must implement strong privacy and security measures, recognizing their direct obligation to adhere to HIPAA and the potential consequences associated with noncompliance.

 

Healthcare vendors in 2026

Healthcare vendors are following the same trends as other companies, adopting advanced technologies to further protect themselves and the healthcare companies that employ them. Such modernization has occurred over the past few years due to changes in technologies, financial pressures, workforce transformations and growing issues, and new cyber risks. Accordingly, vendors can modernize by employing:

  • AI integration
  • Vendor consolidation
  • Enhanced supply chain visibility (i.e., transparency)
  • Cybersecurity included in contracts
  • Automation
  • Stronger third-party risk management
  • Advanced digital procurement strategies

It should be noted that the HIPAA Security Rule is undergoing a rewrite due to such changes in technology and how healthcare entities use them. For example, once enacted, both healthcare providers and vendors will be required to maintain and annually update a technology asset inventory and network map, conduct detailed security risk analyses tied to those inventories, and enforce access controls.

Accordingly, the rule imposes new verification requirements on vendors, making them directly liable for HIPAA compliance and requiring them to confirm adherence to safeguards and contingency plans.

 

The growth of advanced cyberattacks in healthcare

Many major healthcare breaches occurred in 2025 alone, affecting more than 35 million individuals. The primary motivation behind healthcare cyberattacks remains financial gain, given the value of PHI to hackers. Given such lucrative information, cyberattacks against healthcare providers have become more sophisticated, fueled by the growth in technologies to exploit, such as AI.

A recent article recounted that “the number of reported AI-enabled cyber attacks rose by 47% globally in 2025,” also noting that “healthcare, a critical sector, saw a 76% rise in targeted AI attacks in 2025, largely attributed to the automation of ransomware deployment.” An immediate AI-related concern is how threat actors embrace AI to enhance their criminal operations. Artificial intelligence helps hackers take advantage of unsecured systems and untrained staff to target healthcare organizations for cyber fraud.

Traditional warning signs of cyber threats are becoming less obvious, and distinguishing between legitimate requests and advanced attacks is increasingly challenging given new and advanced tools. Threat actors embrace advanced technologies by using different tools to enhance their malicious operations as much as healthcare organizations do to enhance patient care.

 

Advanced cyberattack tools

  • Malicious AI models: Models designed to write convincing phishing emails or create malware code
  • Shadow AI: Unsanctioned AI tools used without approval or oversight that can lead to risks and leaks
  • Autonomous AI agents: Rapid multistage automated campaigns to scan for vulnerabilities, craft code, and quickly exfiltrate data
  • Deepfake impersonations: Attacks that use fake information, such as voice cloning and/or deepfake videos of doctors and pharmacists
  • AI-enhanced social engineering: Craftier, more personalized messages to make individuals more easily reveal sensitive data
  • Synthetic patient identities: Fabricated patient data merged with real patient data to pass initial insurance checks and commit insurance fraud
  • AI-generated medical records: Realistic clinical notes, imaging, and diagnostic reports to support false claims
  • Counterfeit pharmaceutical scams: Deepfakes that promote and/or sell unsafe medications

 

Vendors and advanced threats in 2026

In 2026, advanced cyberattacks against healthcare vendors have surged as criminal groups shift focus from direct hospitals to vulnerable software, billing, and medical technology supply chains. Omega Systems’ 2026 Healthcare IT Landscape Report found that 85% of healthcare organizations experienced at least one third-party or “vendor-of-a-vendor” disruption in the past year (of those surveyed, the report also found that 63% of providers do not continuously monitor digital supply chains). Attacks on healthcare vendors rose nearly 35% worldwide, with cyberattackers focusing on general supply-chain compromises using AI-amplified social engineering and zero-day exploits.

The result of increased vendor threats and advanced risks is a lack of confidence in vendors' cybersecurity. Furthermore, healthcare organizations remain accountable for many vendor failures. Given how rapidly such attacks can occur against multiple vendors, traditional cybersecurity can easily fail. The HIPAA Act is designed to protect patients’ PHI and keep confidential data from being disclosed without a patient’s consent or knowledge.

 

Vendor-related cybersecurity strategies for HIPAA compliance

HIPAA requires healthcare organizations and individuals associated with them to implement specific security measures when using technology to receive, transmit, or store PHI. Vendors can use numerous effective tactics when creating a layered, consolidated security system.

  1. Establishing up-to-date policies and procedures
  2. Keeping systems, software, and security features aligned with advanced technologies
  3. Keeping covered entities informed of issues and updates
  4. Using continuous employee awareness training about PHI and HIPAA
  5. Ensuring proper technological safeguards, such as data encryption
  6. Employing extra firewalls and endpoint security
  7. Utilizing strong access controls
  8. Keeping devices (physically) in secure, controlled locations
  9. Creating data backup and disaster recovery plans in case of an incident
  10. Regularly auditing and monitoring systems
  11. Having an incident response plan ready in case it is needed

HIPAA compliance regulations aim to protect health information. Adhering to HIPAA standards with a defensive approach helps vendors (and providers) protect privacy, leading to stronger systems and better patient outcomes.

See also: What should be in a healthcare AI vendor security review

 

Best practices for working with vendors in 2026

The key to finding a HIPAA compliant vendor in 2026 is to carefully examine the company’s activities and how it interacts with advanced technologies and protects PHI. Healthcare providers should evaluate a vendor’s security certifications, compliance history, data protection measures, incident response capabilities, and training agendas. Moreover, they should look for vendors that:

  1. Sign a BAA and mention HIPAA compliance
  2. Provide written verification at least annually of technical safeguards (2027 update)
  3. Utilize security measures that comply with HIPAA’s technical, physical, and administrative safeguards
  4. Understand and can answer questions about HIPAA
  5. Have HIPAA-related policies and procedures available
  6. Provide reviews, testimonials, and case studies from other healthcare organizations
  7. Deliver staff training on HIPAA and PHI security
  8. Conduct comprehensive risk analyses
  9. Continuously update their security based on new laws and new issues

If a vendor refuses to do any of the above, a healthcare organization should find an alternative, HIPAA compliant solution. Sharing PHI with a vendor that does not demonstrate compliance puts an organization at risk of breaches, HIPAA violations, and fines.

 

FAQs

Are business associates directly liable under HIPAA?

Yes. HHS OCR explains that business associates are directly liable for certain HIPAA violations.

 

Can a covered entity use a vendor without a BAA?

No, not when the vendor is acting as a business associate. Guidance says covered entities and business associates must enter into HIPAA compliant business associate contracts with vendors that create, receive, maintain, or transmit PHI on their behalf.

 

Does a business associate need agreements with its subcontractors?

Yes. A business associate must ensure that subcontractors with access to protected health information agree to the same restrictions and conditions that apply to the business associate.

 

How must a business associate secure PHI?

Business associates must implement a multifaceted approach with physical, administrative, and technical safeguards to secure PHI:

  • Physical safeguards involve controlling physical access to data storage
  • Administrative safeguards include robust policies and procedures
  • Technical safeguards employ encryption, access controls, and secure technologies to prevent unauthorized access or disclosure