Vulnerabilities in personal devices can have serious consequences for healthcare providers and patients, along with their protected health information (PHI). In fact, with the advancement of new technologies, such as artificial intelligence (AI), personal device attacks have become more troublesome to hospitals and clinics. Modern attacks are considered to be more sophisticated, faster, and more scalable. Healthcare organizations need to understand how cyberattackers are maliciously using personal device attacks in 2026 in order to block and prevent potential consequences properly.

Related: HIPAA compliant email: The definitive guide (2026 update)

 

Healthcare: the most targeted sector

According to the FBI in its 2025 IC3 Annual Report, the healthcare industry ranked as the top targeted sector for cyber threats in 2025, with 460 known ransomware attacks and 182 data breaches. Cybercriminals target healthcare because patients’ PHI is central to proper patient care. A single compromise can cause a long list of issues for a healthcare organization, and unfortunately, the healthcare industry has numerous threat vectors prime for an attack, such as personal devices.

Hackers know that disabling a health network can make it difficult for healthcare organizations to properly treat patients. That’s why it's not unheard of for a covered entity to pay a ransom to have its systems restored, even though there are signs that organizations making ransom payments is changing.

Financial gain remains the primary motivation behind healthcare data theft because of the opportunity for multiple forms of fraud. Criminal marketplace pricing clearly demonstrates the demand: a driver’s license reportedly sells for about $20, while a complete identity package can sell for $1,000. Stolen PHI can be used for identity theft and to impersonate patients needing medical services.

 

Known security challenges of mobile devices

According to IBM, there are several security challenges users face on their personal mobile devices. Examples include:

  • Easily connected to open, public networks
  • Lack of routine updating
  • Inconsistent security
  • Apps downloaded but not screened for privacy or security concerns
  • Unsecured storage of both personal and professional data

These challenges become even more of a concern because mobile devices routinely face breaches, device loss or theft, malware, and viruses.

Learn more: Why unsupported software is a risk to healthcare organizations

 

Personal device use in healthcare today

In today’s technological environment, mobile devices are essential tools for communication and productivity. A recent study examining smartphone use among healthcare workers revealed that 98.3% of physicians use their phones at work. Of these workers, only 4.5% received their mobile devices from their employers.

Cybernews has shown that the Bring-Your-Own-Device (BYOD) trend has even expanded beyond smartphones to include laptops and personal computers. Additionally, healthcare workers use mobile devices for more than personal needs. They also use them for looking up medical-related information, communicating with their team or patients, and managing their schedule.

Accordingly, personal devices used by healthcare staff are considered gateways to healthcare networks and PHI, making them especially vulnerable to data breaches and unauthorized access. Unfortunately, many healthcare organizations do not prioritize personal device security, whether due to ability or costs, even though devices require strong management and HIPAA compliant security controls.

Read more: Security practices for remote healthcare workers

 

How do cybercriminals attack personal devices in healthcare?

Cyberattackers know that healthcare organizations rely on technology and electronics for health operations, making them prime targets for cyberattacks and cybercrimes. Moreover, they understand that (personal) mobile devices are easy access points to get into a health network to steal and/or encrypt PHI. Personal devices typically lack proper HIPAA compliant security, such as encryption, firewalls, and antivirus software, making them easy targets.

Furthermore, healthcare staff remain a problem for keeping healthcare organizations secure. Reports show that many breaches can be traced back to employee actions. Common issues include employees falling for phishing messages, reusing passwords, downloading malware, forwarding PHI to personal accounts, or misconfiguring databases and cloud storage.

They may also be too tired and stressed to handle security properly. Attackers exploit devices and staff weaknesses in healthcare ultimately to access an organization’s network and disrupt healthcare operations. Once in a system, a hacker can hunt for a wide range of sensitive information, including PHI, starting with medical records that contain patient data, health histories, diagnoses, treatments, and medications.

 

What is new about personal device attacks?

The technological landscape has improved significantly over the past decade and continuously evolves. The rapid adoption of wireless and remote technologies, and the continued use of legacy devices, has expanded healthcare attacks against mobile devices. Organizations face the dual challenges of maintaining productivity while securing a distributed workforce that relies on their personal gadgets.

Of course, AI and advanced technology have made people more susceptible to attacks. Today’s cyber threats are faster, automated, and more personalized; AI-driven attacks are more common. Scammers can create emails, texts, and alerts that sound natural using AI technology. Even worse, criminals now have their own AI platforms, such as WormGPT and FraudGPT, to create solid impersonation and identity theft schemes.

Increased attack surfaces provide more opportunities for hackers to infiltrate systems and enable them to use even more vicious attack methods. Additionally, more devices today are connected (e.g., house/business security to phones to smart watches) than ever before, making it easier for cyberattackers to access more than one device at once during an attack.

 

The impact of personal device attacks

Once a smartphone or tablet connected to a healthcare network falls into the wrong hands, the risk of unauthorized access to sensitive information increases exponentially. Hackers can hold PHI for ransom or even sell the data on the dark web. With the shifting cyber threat landscape, attackers aren’t simply decrypting information anymore.

They often steal and then extort, threatening to make the data public if not paid. They may also want to get into a system solely for creating havoc or harming individual patients. The damage can go beyond monetary costs (e.g., loss from a ransom or cyberattack recovery), with other costs including:

  • Hacked, changed, and unusable devices
  • Loss of confidence from patients and stakeholders
  • Compromised healthcare data
  • Patients hit by identity theft or blackmail themselves
  • Disruption of services

The consequences of a successful breach can be severe, even leading to business and financial losses. For healthcare organizations, a data breach can also lead to compromised patient information and even patient death.

 

Cybersecurity strategies for HIPAA compliance

HIPAA requires healthcare organizations and individuals associated with them to implement specific security measures when using technology to receive, transmit, or store electronic PHI (ePHI). There are several tactics that could be used effectively by healthcare organizations when creating a layered, consolidated security system.

  1. Establishing up-to-date policies and procedures
  2. Furnishing employees with tablets to use while at work
  3. Keeping systems, software, and security features aligned with advanced technologies
  4. Creating a BYOD program to identify and install needed security
  5. Using continuous employee awareness training, including on personal device use
  6. Ensuring proper technological safeguards, such as data encryption
  7. Employing extra firewalls and endpoint security
  8. Utilizing strong access controls
  9. Keeping devices (physically) in secure, controlled locations
  10. Connecting devices to private and encrypted networks and avoiding unsecured Wi-Fi
  11. Creating data backup and disaster recovery plans in case of an incident
  12. Regularly auditing and monitoring systems
  13. Having an incident response plan ready in case it is needed

HIPAA compliance regulations aim to protect health information. Adhering to HIPAA standards with a defensive approach helps providers protect privacy, leading to stronger systems and better patient outcomes.

 

Bring-Your-Own-Device programs

In healthcare, using devices with outdated operating systems, inadequate authentication practices, and/or sharing personal devices with others exposes data to potential breaches and HIPAA violations. This is why researchers stress the need for healthcare facilities to implement technical and organizational measures through a BYOD program. Such policies specify security requirements for personally owned devices used to access sensitive data, such as PHI.

A BYOD program would lessen potential risks associated with personal device use in healthcare. Such programs may include mobile device management (MDM) software, enforcing encryption and authentication policies, and restricting access to certain applications or data based on device compliance. Such programs should include risk assessments along with routine configuration, testing, and updates.

They also need to include regular monitoring of device use along with staff training on the proper handling of PHI when using mobile devices. The solution is not to ban personal devices, but to allow their use in healthcare in a safe, HIPAA compliant way.

 

Learn more about HIPAA and BYOD programs

Leveraging advanced cybersecurity strategies

By embracing mobile technology responsibly, healthcare organizations can leverage its benefits while ensuring the privacy of sensitive information. The advent of advanced technologies has paved the way for that technology to work hand in hand with patient privacy.

Advanced technologies, such as AI and machine learning (ML), can play a significant role in enhancing cybersecurity defenses while also contributing to their vulnerabilities. Generative AI is a ML model that can create new outputs based on patterns learned from existing data. While criminals can exploit weaknesses with advanced technology, healthcare organizations can also invest in solutions that provide real-time threat detection and quick response capabilities.

In healthcare, generative AI allows advanced data analysis, predictive modeling, and automation. Implementing tools such as generative AI can help healthcare organizations use the benefits of advanced technologies without compromising patient privacy.

 

Further info:

FAQs

How does HIPAA apply to mobile devices?

HIPAA applies to any mobile device that stores, accesses, or transmits PHI. Healthcare providers must ensure these devices are secure to prevent unauthorized access.

 

What are the steps for securing mobile devices under HIPAA?

Steps include encrypting data, using strong passwords, enabling remote wipe capabilities, and ensuring regular security updates to protect PHI on mobile devices.

 

What are the risks of using personal mobile devices in healthcare settings?

The risks include potential loss or theft of devices, unauthorized access to PHI, and insecure data transmission, all of which can lead to HIPAA violations.

 

Can healthcare workers use personal mobile devices for work?

Yes, but they must follow HIPAA guidelines, which include securing the device with encryption, using secure communication tools, and ensuring that PHI is not accessed by unauthorized individuals.

 

How can we keep track of which employees have access to PHI on personal devices?

Use an MDM system or maintain a secure, up-to-date log of approved devices and authorized users to streamline tracking and access management.

 

What should I do if a personal device with PHI is lost or stolen?

Immediately report the incident to your compliance officer, activate any remote wipe capabilities, and follow your organization’s breach response protocol to limit exposure.