AI-FIRST CYBERSECURITY · Always Wise. Always Ahead. +91-95851-60363 info@semperwise.com DOVER, DE, USA

Healthcare cybersecurity

When the network stops, the wards go to paper.

Healthcare is the one sector where a cyber incident is also a clinical incident. Ransomware cancels procedures; a leaked database puts patient records on a public website. And the obligations run on different clocks — CERT-In in six hours, the DPDP Act in seventy-two, HIPAA in sixty days — often for the same event.

Reviewed 23 September 2026 · 17 sources cited

The short answer

Healthcare cybersecurity is patient-safety work: an attack that stops the HIS, the lab system or PACS stops care. In India, report incidents to CERT-In within six hours and, from about 13 May 2027, tell the Data Protection Board and affected patients without delay, with a detailed report in 72 hours. US-facing BPOs also answer to HIPAA through their agreements. Start with an inventory that includes medical devices, separate clinical and office networks, and backups you have restored.

Why healthcare

In a hospital, downtime is a clinical event.

Most sectors count an outage in lost revenue. A hospital counts it in cancelled procedures and diverted patients. When Medusa ransomware hit the University of Mississippi Medical Center in February 2026, appointments were cancelled from 19 February to 2 March, and the attackers followed up with an $800,000 demand for the data they had taken. Comparitech counted 410 ransomware attacks on the healthcare sector worldwide in the first half of 2026 — more than two a day — and the steepest rise anywhere was in attacks on Indian providers: up 700% on the previous six months.

In India, the incident that reaches the news is as often a leak as a lock-out. In August 2026 Star Hospitals in Hyderabad found patient records, employee data and internal documents on a website called “warehouse.diy”, with login details for it circulating on WhatsApp; the Telangana Cyber Security Bureau registered a case. Check Point’s 2025 data put Indian healthcare organisations at 8,614 attacks a week each — the most of any sector.

The rulebook is unusually crowded. A hospital answers to CERT-In today and to the Data Protection Board from May 2027. A health-tech company answers to the hospitals, insurers and platforms it integrates with as well. And an Indian billing, coding or revenue-cycle company working for US providers answers to HIPAA through its business associate agreement, whether or not anyone in India enforces it. Each regime runs its own clock, and one incident can start all of them.

That makes the job specific: know every connected device, keep clinical and biomedical networks apart from the office, test without disturbing care, and be able to prove — with evidence, on a deadline — what happened and what you did about it. The rest of this page takes those in turn.

Evidence

What the data says about healthcare

Global figures from IBM and Comparitech, Indian figures from Check Point and DSCI, US figures from HIPAA Journal’s analysis of HHS data. Each is linked in the sources.

$7.42M Average cost of a healthcare data breach in 2025 — the costliest industry IBM studies, for 14 years running [1]
279 days Average time to identify and contain a healthcare breach, five weeks longer than the global average [1]
8,614 Attacks a week on each Indian healthcare organisation — the most of any sector in Check Point’s 2025 data [4]
21.82% Share of attacks in India that hit healthcare, the most-attacked sector in the DSCI–Seqrite threat report [5]
+700% Rise in ransomware attacks on Indian healthcare providers from the second half of 2025 to the first half of 2026 [2]
35.8% Of 2025 US healthcare data breaches happened at business associates rather than providers [7]

IBM’s figure is global and in US dollars. Its 2026 India study put the average breach across all sectors at ₹25.5 crore, and found penetration testing and red teaming to be the single largest cost reducer.

Hour by hour

The first 72 hours of a hospital ransomware attack

One incident, several clocks. This is the sequence worth rehearsing before the night it happens, with the duty that opens at each step. The DPDP duties apply from about 13 May 2027; the others apply now.

  1. 02:00

    Encryption starts

    The HIS stops answering at the nursing stations, PACS images will not load and the lab queue fails. The night team moves the wards to paper. The clock started when someone noticed — not when IT confirmed it.

    CERT-In: the 6-hour reporting window opens when the incident is noticed

  2. T+1h

    Contain, and keep the evidence

    Isolate affected segments without powering everything down: the logs are now the only record of how the attackers got in. Clinical leadership decides which services divert. Nobody pays or negotiates on the first night.

    CERT-In Directions: logs must already be kept for 180 days, in India

  3. T+6h

    CERT-In report filed

    The report goes in with what is known so far — systems affected, when it was noticed, what has been done. It does not wait for a root cause.

    CERT-In Directions: report within 6 hours of noticing

  4. T+12h

    Patients and the Data Protection Board

    With modern ransomware, data has usually been taken before anything is encrypted. The DPDP Rules require the hospital to tell the Board and each affected patient without delay, in plain language, through their registered contact details.

    DPDP Rules, 2025, Rule 7: intimate the Board and every affected person without delay

  5. T+24h

    Clients, partners and overseas duties

    A US business associate starts notifying its covered-entity clients under the terms of its agreements. A provider with EU operations owes its national authority an early warning under NIS2.

    NIS2: early warning within 24 hours for EU healthcare providers

  6. T+72h

    The detailed report

    The Board receives the updated, detailed account: facts, mitigation, the likely cause, and what has been done for the people affected. A general hospital in New York State owes its health department notice by now too.

    DPDP Rule 7: detailed report within 72 hours · New York 10 NYCRR 405.46: 72 hours

  7. Day 60

    HIPAA notices, at the latest

    For US patients’ protected health information, notices to affected individuals are due without unreasonable delay and no later than 60 days after discovery. A business associate owes its covered entity notice within the same limit.

    HIPAA Breach Notification Rule: 60 days at the outside

Summarised from the instruments listed in the sources. Where a contract or a regulator’s direction sets a shorter period, the shorter one applies. General information, not legal advice.

Attack paths

Six ways into a hospital — and what we test for each

Built from the incidents above and from the systems hospitals, laboratories and health BPOs actually run.

01

The vendor-hosted HMS portal

  1. Way inAn admin panel or API reachable from the internet, with a flaw that lets one logged-in user read another’s records, or with passwords reused from an old breach.
  2. ThenBulk export of patient data, then publication on a leak site.
  3. CostA six-hour CERT-In report, DPDP breach duties from 2027, a police case and the headlines — the shape of the Star Hospitals leak.

What we test: Authenticated testing of the HMS web application and its APIs for broken access control — see web application testing.

02

The unpatched VPN

  1. Way inAn internet-facing VPN or firewall with a known flaw nobody patched.
  2. ThenDomain administrator within hours, then ransomware pushed to the HIS, the lab system and PACS together.
  3. CostPaper downtime, cancelled procedures and diverted patients — the pattern behind the UMMC shutdown.

What we test: The external perimeter and Active Directory — see network penetration testing.

03

The PACS viewer anyone can reach

  1. Way inA DICOM listener or web image viewer exposed to the internet, with weak authentication or none.
  2. ThenImages and patient demographics harvested; in the worst case, images altered.
  3. CostA privacy breach and a clinical-integrity risk: a radiologist can only read the image in front of them.

What we test: Discovery of exposed imaging services, then authentication and access testing of the viewer itself.

04

The flat biomedical network

  1. Way inOne infected office workstation on the same network as imaging modalities and patient monitors.
  2. ThenLateral movement to devices running operating systems that can no longer be patched.
  3. CostDevice downtime, and the possibility of a patient-safety event.

What we test: Segmentation between office and clinical networks — passive-only on the devices themselves unless you instruct otherwise in writing.

05

The US-facing billing or coding desk

  1. Way inA phished medical coder, worn down into approving an MFA prompt.
  2. ThenA remote session into client EHRs and clearinghouse portals, then data taken across many clients at once.
  3. CostBusiness-associate breach notices, client audits and lost contracts. The largest US health breach reported in 2025 — 62.2 million people — was at a business associate, Conduent.

What we test: Phishing resilience, MFA configuration, remote-access paths and the specific controls your clients audit.

06

The health-tech API

  1. Way inA consent or health-record API that trusts the patient ID in the request instead of checking what the caller is entitled to.
  2. ThenOther patients’ records become readable by changing a number.
  3. CostDPDP penalty exposure, and hard questions from every hospital and platform you integrate with.

What we test: Object-level authorisation, endpoint by endpoint — see API security testing.

Obligations

One incident, three rulebooks

What each regime asks of a healthcare organisation, side by side. HIPAA reaches Indian companies through business associate agreements, not through Indian law — but the audit your US client runs is real either way.

DutyCERT-In Directions and audit guidelinesDPDP Act and Rules, 2025HIPAA (US patient data)
Who it binds Every body corporate and government organisation in India Anyone processing digital personal data of people in India — core duties from about 13 May 2027 Covered entities, and business associates through their agreements, Indian BPOs included
Incident reporting 6 hours from noticing Board and each affected person without delay; detailed report within 72 hours Individuals no later than 60 days after discovery; business associates notify the covered entity
Logs 180 days, kept in India Logs and personal data kept for one year (Rule 6) Audit controls required; the proposed rule adds an asset inventory and network map
Security testing A comprehensive audit of all ICT at least once a year, and after every major change Reasonable security safeguards; testing is not prescribed by name Periodic evaluation today; the proposed rule would require vulnerability scans every 6 months and a penetration test every 12
Risk analysis Findings reported in business terms to top management An annual DPIA and audit for Significant Data Fiduciaries Enterprise-wide risk analysis — a factor in 76% of OCR’s 2025 enforcement actions
Penalty Up to a year’s imprisonment, a ₹1 lakh fine, or both (s.70B(7)) Up to ₹250 crore for failed safeguards; up to ₹200 crore for failed breach notice Civil penalties and corrective action plans; OCR collected $8.33 million in 2025
Who certifies Nobody — audits by a CERT-In-empanelled auditor where required Nobody — the Board adjudicates; there is no DPDP certificate Nobody — HHS does not certify; your clients audit you directly

SemperWise is not CERT-In empanelled. Where an audit must come from an empanelled auditor, we prepare you for it — testing, fixes and evidence — and you appoint the empanelled firm directly. We say so before any work starts.

Next step

Know what will be tested before anything is.

A 30-minute call with a practitioner who scopes around clinical systems. No charge, and no obligation.

  • A one-page map of the clocks and duties that apply to you — hospital, laboratory, health-tech or BPO
  • What will be tested live, what only in staging, and what only passively
  • A written scope and a fixed price, with a retest of every fix included
  • Findings mapped to DPDP, HIPAA and ISO 27001, so remediation doubles as evidence
Book a clinical-safe call We reply within 24 business hours.

Before anyone tests a hospital

Eight questions to ask any testing provider — including us

A clinical environment changes what careful testing looks like. These questions separate a provider who has thought about it from a scanner with a logo.

  1. What will you never touch without our written instruction?

    The answer should include live medical devices and anything connected to patient care. Ours: those are passive-only — observation, configuration review and boundary testing — unless you instruct otherwise in writing.

  2. When does testing run, and who can stop it?

    Agreed windows away from clinical peaks, a named person on your side who can halt testing immediately, and a named tester on ours.

  3. What runs in staging instead of production?

    Most HMS and patient-portal testing can run against a vendor staging environment. Production should be kept for what genuinely cannot be reproduced there.

  4. What happens to patient data you come across?

    It should be viewed only as far as needed to prove a finding, never copied off-site, and redacted in the report.

  5. Who confirms a finding before it reaches us?

    A person, every time. A report that is a scanner export buries the three findings that matter under three hundred that do not.

  6. Is a retest included, and will the report show closure?

    CERT-In’s 2025 audit guidelines describe a closure report confirming that findings were remediated. A retest should be in the price, not a second purchase.

  7. Are you empanelled, if our regulator or partner requires it?

    Ask directly. We are not CERT-In empanelled; where an empanelled report is required, we say so and prepare you for that audit.

  8. Will findings arrive mapped to our obligations?

    A finding about weak encryption is evidence under DPDP Rule 6, the HIPAA Security Rule and ISO 27001 at once. It should arrive mapped, not be re-typed by your team.

Where SemperWise fits

What we do for hospitals, labs, health-tech and BPOs

Services are people doing the work; SemperWise One is the platform that keeps the evidence current between engagements. Each row says which.

Patient portals, HMS web applications and mobile apps

Service

Authenticated, multi-role testing against the OWASP Top 10 and ASVS, including the access-control flaws that expose other patients’ records — in staging first.

Web application testing

APIs that connect to labs, insurers and national health platforms

Service

Object-level authorisation, token handling and consent logic tested endpoint by endpoint.

API security testing

Clinical and office networks that should be separate

Service

External perimeter, Active Directory and segmentation testing — passive-only on medical devices unless you instruct otherwise in writing.

Network testing

US clients auditing you as a business associate

Service

Security Rule risk analysis, safeguard review, BAA review and the evidence pack your clients ask for.

HIPAA readiness

The DPDP Act’s duties from May 2027

Service

Data-processing inventory, role determination, notices, rights handling and a rehearsed 72-hour breach playbook. In SemperWise One, patients’ requests arrive through a public form with the statutory clocks attached, and breach reports are drafted against the 72-hour deadline.

DPDP compliance

Evidence for DPDP, HIPAA and ISO 27001 at once

SemperWise One™

One control set mapped to every framework you hold, with evidence that carries a collection date and an expiry.

Unified control model

Exposed PACS viewers, VPNs and forgotten portals

SemperWise One™

Continuous discovery of what faces the internet, so a newly exposed service is noticed the day it appears.

Attack surface management

Proving to partners that testing happened

SemperWise One™

An assessment certificate at a live link that shows scope and remediation status as it changes — without publishing a finding or a patient detail.

Assessment certificates

No full-time CISO

Service

A named senior practitioner a few days a month, with an incident response retainer for the night the HIS stops.

Virtual CISO

Terms

Healthcare security terms, defined

ePHI
Electronic protected health information — the patient data the HIPAA Security Rule protects.
Business associate and BAA
A vendor that handles protected health information for a US covered entity, and the agreement that binds it to HIPAA. Indian BPOs are usually business associates.
HIS / HMS
The hospital information or management system that runs admissions, billing, wards and pharmacy.
EMR / EHR
The patient’s electronic medical or health record — the clinical history clinicians work from.
PACS and DICOM
The imaging archive that stores scans, and the standard format and network protocol it uses.
LIS
The laboratory information system that manages test orders, samples and results.
IoMT
The internet of medical things: infusion pumps, monitors and imaging modalities on the network, often on legacy operating systems.
Data Fiduciary and Data Processor
Under the DPDP Act, the organisation that decides why personal data is processed, and the one that processes it on its behalf. A hospital is the fiduciary; its HMS vendor is usually a processor.
Significant Data Fiduciary
A fiduciary the government designates for higher risk, with an annual DPIA and audit on top of the ordinary duties.
Risk analysis (HIPAA)
The enterprise-wide assessment of risks to ePHI that the Security Rule requires — and the failure OCR penalises most often.
CERT-In-empanelled auditor
An auditing firm on CERT-In’s approved list, needed where a regulator or partner requires an empanelled audit.
Segmentation
Dividing a network so that a compromise in one zone — the office — cannot reach another, such as clinical devices.

Questions

Healthcare security — answered.

What buyers in this sector ask us before they commit to anything.

Does the DPDP Act apply to hospitals and diagnostic labs?

Yes. A hospital or laboratory that holds patient data digitally is a Data Fiduciary under the Digital Personal Data Protection Act, and its core duties apply from about 13 May 2027: reasonable security safeguards under Rule 6 (including keeping logs for a year), breach intimation to the Board and patients without delay with a detailed report in 72 hours, and working notice, consent and rights processes. Clinical establishments get a narrow exemption from some children’s-data restrictions when providing health services — not from the security or breach duties. Penalties reach ₹250 crore. See DPDP Act compliance for how the work is sequenced.

How quickly must a hospital report a cyber incident in India?

Within six hours of noticing it, to CERT-In, under the April 2022 CERT-In Directions — malicious code such as ransomware, data breaches, data leaks and unauthorised access are all on the list of reportable incidents. From about 13 May 2027 the DPDP Rules add a second track for personal-data breaches: tell the Data Protection Board and each affected patient without delay, then send the Board a detailed report within 72 hours. The two are separate duties with separate content, so the report templates should be drafted before they are needed, not during the incident.

Does HIPAA apply to Indian companies?

Not directly through Indian law, but in practice yes: an Indian company that handles US patients’ protected health information for a covered entity is a business associate, and signs a business associate agreement that binds it to the HIPAA Security Rule and breach-notification duties. Your US clients audit you against that, and they carry their own OCR exposure — risk-analysis failures featured in 76% of OCR’s 2025 enforcement actions. Business associates accounted for 35.8% of US healthcare breaches in 2025. Our HIPAA readiness work is built for exactly this position.

How often should a hospital do VAPT?

At least once a year, and after every major change. That is what CERT-In’s Comprehensive Cyber Security Audit Policy Guidelines of July 2025 expect of the ICT estate, and it matches the annual penetration test New York now requires of its general hospitals and the 12-month cycle proposed for HIPAA. In practice, a hospital changes more often than once a year — a new HMS version, a new lab integration, a new patient app — and each is a reason to test. Continuous penetration testing keeps the scope current between annual audits.

Can you test medical devices without putting patients at risk?

Yes, by not testing them the way you would test a web server. Live medical devices and anything connected to patient care are passive-only for us unless you instruct otherwise in writing: we observe traffic, review configuration and architecture, and test the boundary between the office network and the clinical network, which is where most real exposure lives. Where active testing of a device is genuinely needed, it is done on a spare or out-of-service unit, with your biomedical engineering team and, where possible, the manufacturer.

Our HMS vendor handles security. Is that enough?

It is a start, not an answer. Under the DPDP Act the hospital is the Data Fiduciary and the vendor is its Data Processor, so the duty to keep safeguards and to report breaches stays with the hospital. Ask the vendor for evidence rather than assurance: when was the system last independently tested, what was found, what was fixed, and how are logs retained. Write security obligations and breach notice into the contract. With the vendor’s permission, test the portal and APIs your staff and patients actually use.

What will the new HIPAA Security Rule require, and when?

The proposed rule HHS published in January 2025 would remove the distinction between required and “addressable” safeguards, require a technology asset inventory and network map, vulnerability scans at least every six months, a penetration test at least every twelve, and written procedures to restore data within 72 hours. It is not in force. In July 2026 HHS moved the overhaul to its long-term regulatory agenda, pushing a final rule to 2027 at the earliest. Building to it now is still sensible — it describes what auditors already look for.

Is there a cybersecurity certification a hospital can get?

Not for the laws themselves. There is no DPDP certification, and HHS does not certify anyone under HIPAA — “HIPAA certified” describes a training course, not a legal status. ISO 27001 is certifiable, by an accredited certification body rather than by a consultancy, and it is the certificate hospital groups and health-tech companies are most often asked for. What partners increasingly want alongside it is recent, verifiable testing evidence — which is what an assessment certificate is for.

Why are hospitals targeted so often?

Because the pressure to restore service quickly is unusually high, the data is unusually valuable, and the estate is unusually hard to patch — legacy devices, vendor-run systems and dozens of integrations. Sophos found exploited vulnerabilities to be the leading technical cause of healthcare ransomware attacks in 2025, at 33%, and a median ransom payment of $150,000. The defensive answer is unglamorous: patch what faces the internet, separate clinical networks from the office, and keep backups you have actually restored.

Sources

Checked by our research desk on 23 September 2026. Regulations and figures move; where a number here matters to a decision, follow it to the source.

  1. Average cost of a healthcare data breach falls to $7.42 million (IBM Cost of a Data Breach 2025) — HIPAA Journal, 2025
  2. Healthcare ransomware roundup H1 2026 — Comparitech, 2026
  3. Telangana Cyber Security Bureau registers case over alleged leak of Star Hospitals’ patient data — Telangana Today, August 2026
  4. Indian healthcare sector most targeted by cyberattacks (Check Point data) — Digital Health News, July 2025
  5. India Cyber Threat Report 2025 — DSCI and Seqrite
  6. India records its highest average cost of a data breach — Cost of a Data Breach Report 2026 — IBM, 3 August 2026
  7. 2025 healthcare data breach report — HIPAA Journal, 2026
  8. Healthcare data breach statistics (largest breaches by year) — HIPAA Journal
  9. Directions under sub-section (6) of section 70B of the IT Act, 2000 — CERT-In, 28 April 2022
  10. Digital Personal Data Protection Rules, 2025 (Rules 6 and 7) — MeitY, 13 November 2025
  11. Digital Personal Data Protection Act, 2023 (the Schedule of penalties) — MeitY
  12. Directive (EU) 2022/2555 (NIS2), Article 23 reporting — EUR-Lex
  13. 10 NYCRR 405.46 — Hospital cybersecurity requirements — New York State Department of Health
  14. Comprehensive Cyber Security Audit Policy Guidelines, v1.0 — CERT-In, 25 July 2025
  15. New HIPAA regulations: the proposed Security Rule update — HIPAA Journal
  16. HHS moves HIPAA Security Rule overhaul to long-term agenda — Clark Hill, 13 July 2026
  17. The state of ransomware in healthcare 2025 (Sophos) — HIT Consultant, November 2025

All 17 industries we serve

Next step

Test what matters, without touching care.

A 30-minute call, no charge. We agree what can be tested live, what only in staging and what only passively — then send a written scope and a fixed price, with a retest of every fix included.