Five Years Later: What Our 2021 Healthcare Cybersecurity Constraints Look Like Today

Topics:
Healthcare Cybersecurity
This is some text inside of a div block.
Thought leadership
This is some text inside of a div block.
Seth Carmody
Seth Carmody

August 19, 2026

Five Years Later: What Our 2021 Healthcare Cybersecurity Constraints Look Like Today

In March 2021, Medcrypt published “Why Healthcare Cybersecurity Is Hard,” written by Seth Carmody, arguing that healthcare’s cybersecurity problem was never primarily a technology gap — it was structural and economic. The paper named six constraints that, left unaddressed, would keep producing the same outcomes no matter how much any single organization spent on security:

  • Healthcare optimizes for healthcare, not security.
  • Security debt accumulates and lands on consumers.
  • Adversaries exist.
  • Security requires deep specialization.
  • U.S. governance of healthcare technology is fragmented.
  • Uncertainty breaks the existing regulatory risk model.

Five years and an estimated $125 billion in cumulative healthcare cybersecurity spending later, we went back and checked each one against the record — new breaches, new regulation, and a materially different vendor landscape.

The headline finding: four of the six constraints haven’t just persisted. By most measures, they’ve intensified. Two have genuinely changed. None have gone away.

What stayed the same, and got worse

Healthcare has now ranked as the costliest industry for a data breach for 14 consecutive years running, at $7.42 million on average, and still takes longer than any other sector to detect and contain a breach. The February 2024 Change Healthcare/UnitedHealth attack is now the largest healthcare breach on record, affecting 192.7 million people and costing the company more than $2.46 billion in 2024 alone. Ransomware incidence among healthcare organizations nearly doubled between 2021 and 2024, from 34% to 67% of organizations hit — and a peer-reviewed 2026 study now ties ransomware attacks to an estimated 42–67 additional patient deaths.

What genuinely changed

Two constraints moved, and both moved because regulation forced them to. Section 524B of the FD&C Act, effective in 2023, gave FDA its first explicit statutory mandate to require postmarket cybersecurity from device manufacturers — mandatory software bills of materials, coordinated vulnerability disclosure, and a 60-day clock for remediating critical vulnerabilities. Alongside it, Section 515C created a pathway for predetermined change control plans, and FDA’s new Quality Management System Regulation retired the 1996-era Quality System Regulation in favor of ISO 13485. Separately, a consolidating vendor market — Claroty/Medigate, Forescout/CyberMDX, Axonius/Cynerio, and ServiceNow’s pending acquisition of Armis — means the “no market exists for this expertise” problem from 2021 is largely resolved. The workforce and culture gap behind it is not: 93% of device makers still say they prioritize time-to-market over security.

What it means

None of this reaches the legacy devices already in hospitals, and none of it changes the underlying economics: manufacturers still compete on clinical features, not security, and the cost of that gap still lands on the organizations least equipped to absorb it. As the paper puts it, “the extent to which healthcare achieves a sufficient state of security and resilience remains proportional to how well the supply chain reduces security debt at the source, not to how much any single organization spends managing the debt it inherits.”

→ Get the Full Paper  [WHITEPAPER LANDING PAGE URL]

And join Seth Carmody and Medcrypt CEO Mike Kijewski live on August 26 at 11am PT as they walk through the findings and take audience questions:

→ Register for the Webinar  https://us06web.zoom.us/webinar/register/WN_MsklohsZSTWsNhrWfGGgUg

Related whitepapers

No items found.

Related webinars

No items found.

Subscribe to Medcrypt news

Get the latest healthcare cybersecurity news right in your inbox.

We'll never spam you or sell your information