Omdia: the healthcare sector suffered more cyberattacks than any other sector between January and September 2023, with 241 publicly disclosed attacks
The vast amount of information held by health services makes them a prime target for cyber criminals — An increase in cyber attacks …
Context & Ripple Effects
Healthcare had already emerged in related coverage as a weak point within critical infrastructure: EU reporting recorded a sharp rise in attacks on hospitals as broader attacks on critical sectors more than doubled in 2020. Separate reporting also associated cyberattacks with increased patient mortality at some providers, underscoring that the stakes extend beyond data exposure at affected healthcare organizations.
Omdia's tally makes the sector's exposure measurable across the first nine months of 2023, placing healthcare above all other sectors in publicly disclosed incidents. That ranking matters because health services combine high-value information with operational systems whose disruption can directly affect care delivery.
First-order effects
- Healthcare providers face the highest disclosed cyberattack volume in Omdia's tracking, increasing the immediate priority of protecting patient data and maintaining clinical operations.
- Omdia's sector ranking gives healthcare boards, security teams and public-sector health operators a clearer benchmark for treating cyber risk as an operational concern rather than solely a compliance issue.
Second-order effects
- Technology and service vendors connected to health providers are likely to face greater scrutiny, since provider resilience depends on security across interconnected systems rather than on a hospital's perimeter alone.
- Security spending and procurement can shift toward capabilities that limit disruption and speed recovery, as the sector's incident concentration makes downtime risk more salient to customers and insurers.
Third-order effects
- If the pattern persists, healthcare cybersecurity will increasingly be managed as an ecosystem-resilience problem involving providers, suppliers and public agencies, not as isolated breach response.
- The sector's combination of sensitive information and care-delivery dependence may sustain pressure for stronger shared security standards and incident coordination, though the disclosed-attack count alone cannot establish which interventions will follow.
The trend: Healthcare is becoming a focal point of ecosystem cyber defense as attacks increasingly target data-rich, operationally critical services.