When an organization has a security breach, it can cause significant financial, reputational and logistical damage. But in healthcare, where patient lives are on the line, the consequences can be much more catastrophic.
KnowBe4’s latest whitepaper on healthcare cybersecurity, “Hacking the Healers: How the Digital Workforce Became Cybersecurity's Frontline,” examines how decentralized clinical operations, remote staff and autonomous AI agents have dissolved traditional network perimeters, leaving healthcare organizations and patient safety vulnerable to targeted cyberattacks.
The rise of the digital workforce, which includes humans and AI agents, has significantly expanded the attack surface. And the evolution of job roles in healthcare from remote medical coders to telehealth clinicians to decentralized administrators have become a significant challenge for those in cybersecurity responsible for protecting healthcare organizations. Beyond job roles, interconnected medical devices and systems present new attack vectors for cybercriminals to exploit.
The healthcare industry is heavily targeted due to the high value of patient data, with medical records selling on the dark web for 10 to 40 times more than credit card numbers. This is evident in the increasing number of cybersecurity breaches in the industry. In 2025, healthcare experienced record-high breaches, leading global industries for 14 straight years with costs averaging $7.42 million globally and $9.8 million in the U.S. Healthcare breaches remain the most costly and slowest to resolve across all global industries, resulting in devastating financial fallout, widespread data exposure and severe risks to patient survival.
Some concerning findings from the whitepaper include:
- Long Resolution Time: Breaches take an average of 279 days to identify and contain.
- Spike in Patient Mortality: Ransomware attacks correlate with an immediate 34% to 38% increase in in-hospital mortality for admitted patients.
- High Phishing Risk: Healthcare organizations recorded a 44% baseline Phish-Prone™ Percentage (PPP), spiking to 54.9% in large enterprises.
- Emerging AI Threats: While 69% of executives adopt AI for operational agility, 53% cite cybersecurity as their top challenge amid threats like prompt injection and permission creep.
Healthcare staff operate in environments defined by rapid decision-making, and cybercriminals systematically exploit this to bypass critical judgment. Building resilience requires a strategic approach that addresses technology, workflows and clinical behavior. Some of the measures that organizations can take to better protect themselves and the patients they serve include embedding friction by design into clinical workflows, protecting and monitoring the digital ecosystem and securing the digital workforce.
Furthermore, organizations must build behavioral resilience across human and AI agent workforces to protect patient care. With a continuous model of security awareness and real-time support, and active behavioral monitoring for both humans and AI agents, healthcare institutions can build a strong security culture. The ultimate goal is to foster an environment where clinical excellence and digital defense operate in alignment, turning a vulnerable workforce into an organization's best line of defense.
Read more in KnowBe4’s latest healthcare cybersecurity whitepaper “Hacking the Healers: How the Digital Workforce Became Cybersecurity's Frontline.” The whitepaper shows that vulnerabilities in healthcare can be dramatically mitigated through sustained training. After 90 days of training, overall PPP fell to 20.7%, and enterprise organizations dropped to 3% after one year—a 94% reduction.
