Hospitals had a manageable first half of 2026. Attacks against clinics and hospitals themselves ticked up only modestly. Meanwhile, the businesses that keep those hospitals running, billing vendors, medical device suppliers, managed service providers, got hit more than twice as often. That gap is the story, and it’s a preview of where cybersecurity spending needs to go next: not just harder shells around the obvious targets, but real scrutiny of everyone with a badge and a login to your network.

Hospitals Hardened. Their Vendors Became The Target.
This isn’t complicated economics. A hospital with a security operations center, an incident response retainer, and a compliance team that answers to regulators is expensive to breach and expensive to get caught breaching. A third-party billing company with twelve employees and a shared drive full of patient records is neither.
Attackers go where the data-to-effort ratio is best. Healthcare service providers, the vendors, the outsourced IT shops, the clearinghouses that process claims, often hold the same protected health information as the hospitals they serve, without the same defense in depth. No segmented networks, no dedicated threat detection team, sometimes no MFA on the remote access tools that connect them to a dozen client environments at once.
Attacks on healthcare service providers and other healthcare businesses more than doubled in the first half of 2026, even as direct attacks on hospitals and clinics rose only modestly.
That single data point should reframe how healthcare security teams think about risk. The weakest point in your environment might not be inside your environment at all.
A Compromised GitHub Repo Became A Wallet-Draining Supply Chain
You don’t have to work in crypto to learn something from what just happened to Injective Labs. Attackers compromised the GitHub repository behind the project’s SDK and pushed a poisoned version, @injectivelabs/[email protected], to the npm registry. The package shipped with fake telemetry code that quietly exfiltrated private keys and mnemonic seed phrases from anyone who installed it.

Swap “crypto wallet” for “patient record system” and the mechanism is identical to what’s happening in healthcare. Nobody breaches the hospital directly. They breach the dependency, the vendor, the SDK, the third-party plugin that a hundred organizations trusted without a second look. The npm registry, like the healthcare vendor ecosystem, runs on assumed trust. Attackers have figured out that assumed trust is cheaper to exploit than a hardened firewall.
The lesson isn’t “audit your npm dependencies,” although you should. It’s that supply chain and vendor risk are the same risk wearing different clothes. Every contract you sign with an outside company is a trust relationship you didn’t fully vet, sitting inside your threat model whether you acknowledge it or not.
What Actually Reduces Vendor Risk
None of this requires exotic tooling. It requires treating vendor connections with the same seriousness you’d apply to your own perimeter.
- Inventory every vendor with network access, API credentials, or data access, and rank them by what they can actually touch, not by contract size.
- Put vendor security requirements in the contract: patch SLAs, breach notification windows, MFA enforcement, and the right to audit.
- Segment vendor and third-party access onto its own network zone. A billing vendor’s VPN account should never have a path to your EHR database.
- Apply security hardening to every remote access point vendors use, RDP, SSH, VPN gateways, and lock down brute-force attempts with rate limiting or an automated blocking tool. Something like IPBan Pro handles this cheaply on exposed Windows and Linux endpoints without needing a full SOC behind it.
- Monitor vendor connections continuously. Threat detection on inbound vendor traffic catches lateral movement long before it reaches patient data.
- Update your incident response plan to explicitly cover a vendor-caused breach: who notifies whom, who owns forensics, who owns the regulatory clock.
Do this and you’re not just protecting against the next healthcare service provider getting popped. You’re protecting against the next Injective-style supply chain hit, wherever it shows up in your stack. Cyber security programs that only watch their own front door are going to keep missing the breach that walks in through someone else’s.
Sources
- Cybercriminals Flock to Healthcare Businesses as Attacks Surge
- Injective Labs GitHub Compromise Pushes Wallet-Key-Stealing npm Packages
Take Control of Your Server Security
Don't let brute-force attacks slow you down. Try IPBan Pro risk-free for 30 days.
Secure. Automated. Lightweight.
Take Control of Your Server Security
Don't let brute-force attacks slow you down. Try IPBan Pro risk-free for 30 days.
Secure. Automated. Lightweight.
