Menu Close

Cyber Attacks on Healthcare: Why Smaller Practices Are Next

Non-hospital healthcare providers are the growing target for cyber attacks.

The Australian Signals Directorate’s Cyber Security Centre found that malicious actors succeeded in 95% of healthcare sector incidents it responded to in FY2024–25, compared to just under 52% across all sectors on average (ASD’s ACSC, 2025), and that ransomware incidents against the sector doubled over the same period. That gap does not reflect an unlucky sector; it reflects where attackers already know the easier target sits. 

Why the target moved to smaller practices 

Hospitals typically carry larger security teams and years of dedicated security budget behind them. Smaller practices hold the same category of valuable data, patient records, imaging, referral historiesand billing details, without anything close to that scale of protection sitting behind it. 

Attackers are not choosing hospitals less often because hospitals hold less, they are choosing them less often because hospitals are more expensive to breach. The economics point towards smaller providers being targeted. 

There is a second factor behind the gap: rapid digitisation across the sector has outpaced security maturity in many areas. That mismatch builds up technical debt and legacy systems, and attackers actively look for exactly that. A practice that has added new software, devices or online booking systems over the past few years, without a matching upgrade in how those systems are secured, fits that pattern. 

Where that gap shows up 

A vulnerability is a known flaw in a piece of software, and the maker has usually already published a fix for it. That fix is called a patch and until it is applied, the flaw sits there, documented and searchable by anyone who knows where to look. 

Hospitals with dedicated IT teams tend to close those gaps quickly. Many smaller practices do not, not because they are careless, but because nobody owns the job and there is rarely enough time in a clinic day to apply it. That difference alone accounts for a meaningful share of the gap ASD’s ACSC has recorded between healthcare and every other sector. 

Questions the gap should prompt at your practice 

  • Are patches applied on a schedule, or only noticed after something has already gone wrong 
  • Who is responsible for tracking what is out of date across every system in the practice 
  • What does proactive monitoring look like in an ordinary week, not just after an incident 

“We haven’t been breached yet” feels like reassurance, but it’s a timing problem rather than proof of security. It only tells you that an incident hasn’t happened yet, not that the practice is protected. Many breaches go undetected for months before anyone notices, so the absence of an incident so far says very little about where a practice’s patches and monitoring stand. 

None of this is about scaring a practice into overspending on security. It is about recognising that this gap is not random, and closing it starts with knowing exactly where patches and monitoring stand today. 

Knowing that attacks on healthcare succeed far more often than in most other sectors, is your provider treating that risk proactively, or only after something breaks? 

You can read more about the Health IT approach to security here, or our resent update on the importance of Multi-Factor Authentication here.