Healthcare fixed just 6% of cyber risks in 2026

WASHINGTON, UNITED STATES — Healthcare organizations are finding more cybersecurity vulnerabilities than ever — and fixing fewer of them, Cybersecurity Dive reports.
A mid-year report from Fortified Health Security finds the sector’s remediation rate collapsed in the first half of 2026, raising questions about whether visibility improvements are translating into meaningful risk reduction.
Identity and supply chain risks surge
The Fortified Health Security Mid-Year 2026 Report, published July 14, found that healthcare organizations identified four times more identity and access control vulnerabilities in H1 2026 compared to H1 2025.
Supply chain exposures scaled even faster — organizations flagged six times more supply-chain risks year over year, with nearly two-thirds classified as critical or high-severity.
According to the report, “Assessments are exposing third-party risk gaps that many healthcare organizations have no current program to address.”
92% of healthcare network domains had administrator accounts with passwords unchanged for three or more years — leaving a foundational attack surface largely unaddressed across the industry.
Fortified researchers noted that identity maintenance ‘closes the doors most attackers walk through,’ even as it remains a low-priority function within most health system security programs.
Visibility outpaces capacity to fix risks
Average healthcare organizations encountered 60% more critical and high-severity vulnerabilities in H1 2026 than in the same period last year.
Yet the remediation rate fell from 23% in H1 2025 to just 6% — a collapse that suggests security teams are being buried by the volume of what they can now see. “This isn’t the story of a single catastrophic breach,” the report states.
“It’s the story of visibility outpacing capacity.” Healthcare organizations remediated just 6% of identified risks in H1 2026, down from 23% in H1 2025 — a drop that points to assessment breadth growing faster than the teams available to act on findings.
The report draws on assessment data across Fortified Health Security‘s healthcare client base, giving it direct visibility into operational security postures rather than breach-level outcomes alone.
For healthcare outsourcing providers, the Fortified findings map onto a clear operational gap. Identity and access management, third-party vendor risk tracking, and vulnerability triage are among the most labor-intensive functions in a healthcare security program — and among the most under resourced.
Offshore managed security services and cybersecurity support teams offer health systems a scalable path to closing the gap between what assessments surface and what gets remediated.
As HIPAA Security Rule enforcement approaches and regulatory pressure on identity controls intensifies, the capacity to fix vulnerabilities — not just detect them — becomes the differentiating factor.

Independent




