Federal agencies have been issuing cybersecurity warnings to healthcare organizations for years, but something about the volume and urgency of those warnings has changed over the past twelve months. The alerts are coming more frequently, they are naming specific adversaries more directly, and the underlying message is no longer just about data protection. It is about whether hospitals can keep delivering care when their systems go down.
The change in tone tracks with a change of the threat. What was primarily a financially motivated criminal problem has taken on geopolitical dimensions that most healthcare security teams were not built to address.
The geopolitical layer
In March 2026, CISA, the FBI, and other federal agencies issued an advisory warning that Iranian groups could be seeking to attack critical infrastructure, including the healthcare sector, in response to deteriorating relations between the United States and Iran. The warning was not abstract. An Iran-linked group called Handala had recently claimed credit for an attack on Stryker, a medical technology company specializing in surgical equipment and orthopedic implants, stating it had wiped data from more than 200,000 servers, mobile devices, and other systems across the organization. Stryker reported full recovery by the end of the month, but the attack was a reminder that healthcare's exposure runs well beyond criminal ransomware groups.
Iranian actors have been targeting healthcare for longer than most organizations realize. A joint advisory from CISA, the FBI, the NSA, and international partners documented that since October 2023, Iranian cyber actors had been using brute force techniques including password spraying and MFA push bombing to compromise user accounts across the healthcare and public health sector. Their likely objective was obtaining credentials that could then be sold to enable access by other criminal actors, functioning as initial access brokers for future ransomware deployments.
The Chinese dimension is more recent and more structurally intricate. In April 2026, CISA and the UK National Cyber Security Centre issued a joint advisory on Chinese government-linked covert networks, describing how actors including Volt Typhoon and Flax Typhoon had been using large networks of hijacked consumer and small-office devices, known as botnets, to hide their identity while conducting reconnaissance, delivering malware, and exfiltrating data from critical infrastructure organizations. As the advisory put it directly, "the use of covert networks of compromised devices to facilitate malicious cyber activity is not new, but China-nexus cyber actors are now using them strategically, and at scale." For healthcare organizations, the significance is that the entry point is often not a sophisticated exploit but an unmanaged connected device sitting quietly on the network.
According to Paubox's 2025 Healthcare Email Security Report, ransomware attacks on healthcare have surged 264% since 2018, and the FBI's 2025 Internet Crime Report confirmed healthcare as the most targeted critical infrastructure sector for the second consecutive year.
Read more: What is ransomware? | What is phishing?
Fox Tempest and the malware-signing supply chain
In May 2026, Microsoft announced it had disrupted Fox Tempest, a threat actor operating a malware-signing-as-a-service platform that cybercriminals were using to deploy malicious code including ransomware across healthcare, education, and other sectors. The significance of a malware-signing service is specific. Security tools often use digital signatures to verify that software is legitimate. A service that signs malware with trusted certificates effectively lets malicious code wear the credentials of legitimate software, bypassing defenses that would otherwise flag it as suspicious.
The Fox Tempest disruption is the kind of upstream action that rarely makes headlines inside hospital IT departments but has direct consequences for every organization using endpoint security tools that rely on signature validation. It also shows a pattern visible across multiple federal advisories this year where attackers are targeting the infrastructure that defenses depend on rather than attacking target organizations directly.
Read also: What is Malware-as-a-Service?
The industry's response
Federal warnings have historically been more consistent than organizational action in response to them. Healthcare institutions face genuine resource constraints, and the gap between what advisories recommend and what most organizations can actually implement has been a persistent problem. Two recent initiatives suggest the industry may be trying to close that gap through collective action rather than expecting individual organizations to absorb the full burden alone.
The American Hospital Association (AHA) and the Joint Commission announced the Cyber Resilience Readiness program in May 2026, designed to help hospitals assess and strengthen their ability to maintain clinical continuity during cyber-related technology outages for 30 days or longer. The framing is deliberately patient-centered rather than IT-centered: the program focuses on whether organizations can sustain safe clinical operations during a significant cyber incident, not just whether they can restore systems. It addresses coordination between clinical, operational, and leadership teams during downtime, and measures readiness to maintain patient care when connected systems are unavailable. The program is voluntary and modular, with components that organizations of different sizes can apply based on their current capabilities.
The AHA also named Rubrik as a preferred cybersecurity provider, adding it to a roster of vendors the organization recommends for cybersecurity services, with a specific focus on helping hospitals recover from attacks more quickly. The partnership indicates a recognition that resilience, the ability to recover fast enough to limit patient harm, has become as important as prevention.
What the warnings actually require
The federal advisories from 2026 converge on a consistent set of technical recommendations, and they are not particularly exotic. Strong passwords on all accounts. MFA on all remote access. Patching of internet-facing devices and known vulnerabilities. Network monitoring for anomalous activity. Audit logging that enables post-incident investigation. None of these requires specialized knowledge of nation-state tactics to implement.
What they do require is the organizational discipline to apply them consistently across every system, including the ones that seem too old or too embedded in clinical workflows to update. The Chinese botnet advisory is explicit that the entry points being exploited are often unmanaged connected devices, the kind of IoT equipment and legacy infrastructure that healthcare environments accumulate over years of growth and consolidation.
Email remains the most consistently documented initial access vector across both criminal and state-aligned attacks against healthcare. Paubox's 2026 Healthcare Email Security Report found that attacks evading native email defenses rose 47% in 2025, and phishing emails increased 17%. The Iranian actor advisory documented specifically that these groups have been using MFA push bombing against healthcare accounts, which means that even organizations with MFA in place are being targeted through the specific weaknesses of push notification-based authentication. Pre-delivery email filtering that removes phishing attempts before staff encounters them addresses the entry point before any authentication decision is required. Paubox Inbound Email Security uses AI to analyze sender behavior, message intent, and contextual signals, detecting phishing attempts that bypass signature-based systems before they reach clinical and administrative staff.
Learn more: Paubox Inbound Email Security
FAQs
Why are federal agencies issuing more cybersecurity warnings to healthcare now?
The volume of warnings tracks the volume and complexity of threats. Healthcare has been the most targeted critical infrastructure sector in the United States for the second consecutive year, and the addition of state-sponsored Iranian and Chinese threat activity on top of established criminal ransomware operations has created a more complex environment than prior years. Advisories have also become more specific, naming particular threat groups and techniques rather than offering general guidance.
What is the Cyber Resilience Readiness program and who is it for?
The Cyber Resilience Readiness program is a voluntary initiative from the AHA and the Joint Commission designed to help hospitals assess and strengthen their ability to maintain clinical operations during extended cyber-related technology outages. It is modular and available to healthcare organizations of all sizes, with components that can be selected based on an organization's current readiness level and resources.
How do Iranian and Chinese cyber threats differ from ransomware groups?
Criminal ransomware groups are primarily financially motivated, seeking payment in exchange for restoring access or not publishing stolen data. Iranian actors have been using credential theft and MFA push bombing to sell network access to other criminal groups. Chinese state-sponsored actors are conducting long-term access campaigns focused on intelligence gathering and infrastructure mapping, using compromised consumer devices to obscure their activity. All three categories are targeting healthcare, sometimes in ways that overlap, as when Iranian actors sell access that ransomware groups then exploit.
What is a botnet and why does it matter for healthcare?
A botnet is a network of compromised devices, often home routers, IoT equipment, or other low-security connected devices, that attackers control remotely and use to conduct malicious activity while disguising their location. China-linked actors have been using botnets at scale to conduct reconnaissance on critical infrastructure networks, deliver malware, and exfiltrate data in ways that are difficult to attribute. For healthcare organizations, the concern is that unmanaged connected devices on hospital networks, medical equipment, visitor Wi-Fi infrastructure, and legacy systems can be recruited into these networks without any visible indication.
