Healthcare Was 2025’s Most-Targeted Sector. Here’s the Funding Window to Fix the Gap Behind It

  • Healthcare was the most-targeted U.S. critical infrastructure sector for cyber events in 2025, with 460 ransomware attacks and 182 data breaches reported to the FBI.
  • The underlying driver in most clinical environments is not a lack of security spending; it is that shared ICU, ED, pharmacy, and OR workstations do not fit standard password-and-phone MFA.
  • The Rural Health Transformation Program is putting $50 billion toward rural healthcare through FY2030, with cybersecurity named as an explicitly funded priority, so the budget conversation does not have to wait for next fiscal year.
  • Continuous, presence-aware authentication removes the credential from shared clinical workstations without slowing clinicians down or requiring a personal phone in restricted clinical areas.

Healthcare recorded 642 targeted cyber events in 2025 alone, 460 ransomware attacks and 182 data breaches, more than any other U.S. critical infrastructure sector, according to the FBI's Internet Crime Complaint Center. Behind that number sits a specific, structural gap: clinicians share workstations across 12-hour shifts in ICUs, EDs, pharmacies, and ORs, and most authentication tools were built for someone who sits at one desk all day.

This piece covers why that gap persists, what recent breaches show about the stakes, and the funding window that makes closing it easier to budget for right now.

Why Healthcare Keeps Topping the Target List

The FBI's own 2025 numbers make healthcare the most-targeted critical infrastructure sector in the country, and nearly two-thirds of breaches trace back to a human element rather than a novel exploit.

The human element, error, manipulation, or misuse, was involved in 62% of breaches in the most recent Verizon Data Breach Investigations Report. In just the first months of 2026, health systems including NYC Health + Hospitals (roughly 1.8 million individuals affected) and Erie Family Health Centers (roughly 570,000 individuals) reported major breaches, underscoring that this is an active, ongoing pattern, not a 2025 anomaly.

These figures describe scale and frequency across the sector; the specific initial access method behind each named 2026 breach above has not been independently confirmed here, so they are cited as context rather than as evidence of any single attack mechanism.

The Shared-Workstation Problem Standard MFA Does Not Solve

Clinicians moving between ICU, ED, pharmacy, and OR terminals under time pressure predictably route around any authentication step that slows them down, and many clinical areas restrict personal phones entirely.

This is rational behavior under a system not built for the clinical environment, not negligence: staff stay logged in when they step away, share credentials informally across shifts, and use passwords that satisfy complexity rules on paper while ending up written on a sticky note. Remote and telehealth access over RDP and VDI carries the same unattended-session risk as in-building workstations, with less physical oversight to catch it.

Pharmacy, lab, and OR environments add a further layer: controlled-substance dispensing systems require strict, individually attributable access, not just general workstation security. To be precise about scope, Proximia does not integrate with dispensing-cabinet hardware itself; it secures the workstation or terminal staff use to access records and request dispensing, which is where the shared-login problem actually lives.

Why Conventional MFA Falls Short in a Clinical Setting

Traditional MFA protects the login moment, not the shift, so a clinician who steps away from an unlocked terminal is still exposed no matter how strong the sign-in was.

The 2026 Verizon DBIR documents attackers increasingly bypassing MFA entirely by stealing session tokens rather than credentials, because MFA protects the login event and does nothing to protect the session that follows it. That finding is about the local workstation and remote-session layer specifically; it does not extend to how a separate cloud application manages its own session once a user signs in.

"We already have HIPAA-compliant MFA" is a common objection, and the honest answer is that traditional MFA does address login, it just does not address session persistence after a clinician steps away, which is exactly where shared-workstation exposure lives.

How Continuous, Presence-Aware Authentication Fits the Clinical Environment

Biometric plus XiFi Card, or phone where permitted, authentication replaces the password at shared clinical workstations, and Continuous Session Protection locks the session the instant a clinician steps away.

Sign-in takes roughly two seconds, faster than typing a password, with no behavior change required from clinical staff. A fresh biometric check on every access, combined with per-user, per-session immutable audit logs generated automatically, produces the individually attributable trail that HIPAA access-control requirements and DEA audit expectations both look for, on the workstations staff use to access records and request controlled-substance dispensing.

Proximia's access controls, audit logging, and encryption support HIPAA Security Rule requirements, specifically the access control provisions at 45 CFR 164.312(a)(1), the audit control provisions at 164.312(b), and the encryption provisions at 164.312(a)(2)(iv) and 164.312(e)(2)(ii). The precise phrasing matters here: this supports HIPAA compliance requirements and is HIPAA-aligned; HIPAA compliance itself is a covered-entity designation, not a vendor certification. The same authentication extends to RDP and VDI for remote and telehealth access, and integrates alongside existing Active Directory or Entra ID, without a rip-and-replace project.

The RHTP Funding Window Is Open Now

The Rural Health Transformation Program is directing $50 billion to rural health organizations through FY2030, and cybersecurity is a named funded priority, not something rural hospitals need to stretch a grant application to justify.

RHTP totals $50 billion over five years, FY2026 through FY2030, roughly $10 billion per year. FY2026 state awards ranged from $147 million (New Jersey) to $281 million (Texas), averaging about $200 million per state (CMS Rural Health Transformation Program overview; KFF; Hall Render, January 2026). Eligible organizations include rural hospitals, Critical Access Hospitals, Federally Qualified Health Centers, and Rural Health Clinics.

For an RHTP-eligible organization specifically, the funding window is open now, not tied to the next fiscal year's planning cycle, which changes the timing of a budget conversation that might otherwise wait a year.

Ready to Close the Gap?

See how Proximia supports HIPAA access-control requirements on shared clinical workstations without a personal phone. Schedule a demo at proximia.com/contact.

Frequently Asked Questions

Scroll to Top