logo image

Health Care Industry is Recognizing: Cyber Threats Jeopardize Hundreds of Millions of Patient Records (And That’s Just the Start)

The health care industry is where you go to heal if you get physically injured or attacked. But what happens when the health care industry is injured or attacked – not physically but digitally?

The answer is that hundreds of millions of people’s medical records can be exposed. In fact, there’s no “can be” about it. It’s already happening.

Minnesota-based Change Healthcare was hacked in 2024, with an astonishing 192 million patients having their health records compromised by a hacking incident.

You read that right: One hundred ninety-two million patient records.

That was the largest breach of patient records in history, by far, although it was certainly not the only significant one in recent years. The Kaiser Foundation Health Plan saw 13.4 million patient records exposed in 2024, while Colorado-based Welltok Inc. experienced a breach in 2023 that put 14.7 million patient records in the hands of hackers.

There have been more than 100 breaches in the past several years affecting 1 million or more patients each. And these were attacks against well-established companies who had full-time IT departments and strict HIPAA-compliance policies and procedures.

Cyber attackers know where they can inflict the most pain, and recent reports say they are focusing more than ever on the health care sector. The organization Health-ISAC recently reported that in the third quarter of 2025 the industry saw an uptick in threats associated with broader events and growing risks.

One of those includes the notorious Shai-Halud worm, which is distributed through malicious NPM packages and embeds itself in other packages owned by the target. From there it exfiltrates data to public GitHub repositories.

Another common attack on the health care industry has involved phishing attacks using QR codes that hide malicious links within images – thus bypassing much of the security that would otherwise stop them.

When patient records are compromised, it’s a nightmare both for the patients and for the providers.

UBX Cloud clients are protected by a cybersecurity platform that is based on UTM Stack, which combines network layer, infrastructure, end-user, and AI-based protection. It combines alerting and mitigation into a single interface that makes everything completely visible.

There is much any organization can do to protect itself – from regular patching to network segmentation to employee education on phishing attacks. But you also need a system that can sniff out threats, and can recognize the most serious kinds and take action immediately.

The health care industry has invested heavily in information technology and in solid professionals to manage it. But not every IT professional is a cybersecurity expert. Many are top-notch at designing networks that can operate efficiently and store data effectively, but that doesn’t necessarily mean they are up to speed on the cyberthreats that evolve and emerge on a daily basis.

It’s critical for top executives within health care organizations to understand the difference, and to make sure they have the people, the tools, the strategies and the discipline to stay ahead of cyberthreats. Hundreds of millions of patients’ data should provide more than enough incentive.

But the threats are only becoming more lethal and deceptive. As the health care industry relies increasingly on its digital systems to operate, attackers have the ability to shut down entire enterprises. Both the financial and human cost of that are too horrible to contemplate.

Get on top of this now. We’re here to help.

Steven Panovski

Related Posts

All posts

How Our People, Combined With Our Security Bundle, Guard Against Cyber Threats

The nature of cybersecurity threats is that there is no standard nature to them. They constantly evolve because they are the work of determined criminals who don’t give up.

So any cybersecurity bundle has to be dynamic and not static. It has to not only defend effectively against known threats, it also has to be on the lookout for emerging threats and have the ability to adapt.

At UBX Cloud, we protect our clients’ data and systems with our security bundle. It not only springs into action when an attack looms, it also keeps an eye out for vulnerabilities it can address ahead of time – and lets us know when we need to take immediate direct action in regard to a given situation.

Here are some of the elements of our security bundle, and how we utilize it to protect our clients:

• Advanced Threat Protection guards both endpoints and servers so they’re ready before a threat even shows up, and can shut down any attempt to access your system. • When a threat is present, the security bundle automatically deploys a combination of predefined and custom response actions across your entire system infrastructure to stop the threat cold. We are familiar with a wide variety of attack methods, so we’ve programmed in the most effective responses for those – while still leaving the system capable of conceiving a custom response when necessary. • The bundle constantly scans for vulnerabilities and sends alerts so we know what requires patching or any other sort of action well in advance of a threat. • Managing access permission is critical, so when an account’s access permission changes, the system detects it and alerts us so we can react quickly if the change has a suspicious origin. • Whenever critical data is accessed or changed, the system will know, so we move rapidly in the event of a potential problem. • If any malware or other type of attack hits your system, the XDR function detects it quickly and initiates a strong response. • We keep an eye on the Dark Web as well, so we know if your organization is producing compromised users or PII data.

Of course, all of this comes under the guise of our own team’s close watch on your system and your data. The security bundle is excellent, but we don’t expect it to do our job for us. It helps us to do the job of protecting you better.

The members of our team tightly monitor your system and your data on a continual basis to make sure it is safe and secure.

Cyberattackers don’t stop looking for new ways to hit you. But with our knowledge, experience and tools, we know how to stay several steps ahead of them – so that when they do show up looking for trouble, they find that they’ve got trouble.

And you don’t.

It’s True: We Provide Carrier-Grade Private Cloud on a 48U Cabinet (And It’s Way Better Than What Big Cloud Will Ever Do For You)

If you’re in telecom or any industry that demands carrier-grade cloud, it’s easy to assume that the only real options are AWS and Azure. After all, the Big Cloud giants have built their reputations on capacity and scale.

But here’s the truth: What you gain in “scale,” you lose in control, transparency, and value.

Too often, businesses assume they must accept whatever terms Big Cloud puts in front of them – limited bandwidth, shared platforms, premium-priced “top-tier” hardware, storage performance capped around 60,000 IOPS, and extra fees for every essential service like managed support, firewalls, backups, OS licensing, and network speed.

The more you think about it, the more you wonder why you associate Big Cloud with high capacity. They may have it, but they don’t provide much of it to you unless you pay a veritable extortion. And when you add up those costs, it’s not capacity you’re getting, it’s extortion disguised as infrastructure.

The UBX Cloud Difference

UBX Cloud delivers true carrier-grade private cloud – all within a single 48U cabinet – and we do it without the fine print or hidden fees.

Here’s what comes standard:

• Top-quality hardware • Unlimited bandwidth • Four ways to access support • Dedicated Juniper vSRX firewall • Veeam enterprise backup • 100 percent uptime guarantee • OS licensing • 24/7 monitoring and managed security support • 100GE private network • 500,000 IOPS of storage performance • Tier 4 data facility • Private, non-shared resources for data storage

All of it in one comprehensive package and a fair price.

How Do We Do It?

By now you’re wondering how we provide all that when Big Cloud can’t (or won’t) even come close to offering it to you. There are several reasons.

First, we have excellent strategic partners who give us access to expansive storage capacity, including storage partners Pure Storage and Zadara Storage.

Second, we don’t oversell our capacity on the theory that all our subscribers won’t use it at the same time. We assume you need everything you’re paying for and we make sure there’s room for you to take full advantage.

Third, we recognize that providing top-quality data management makes the rest of our jobs easier, and it makes your operation more secure and more likely to continue operating without glitches.

Transparent Pricing. No Surprises. Real People.

At UBX Cloud, everything’s included upfront. No tiered pricing traps. No “add-ons.”’ No nickel-and-diming.

And because we operate efficiently, our clients typically pay about 50 percent less than what Big Cloud would charge for equivalent (or often inferior) performance.

When you need support, you won’t get lost in a ticket queue – you’ll get a real person who knows your name, understands your setup, and actually cares about solving your issue.

Big Cloud’s Biggest Myth

Big Cloud has done a good job of one thing, though: They’ve convinced a lot of businesses that only the biggest players can deliver carrier-grade cloud. But it’s just not true.

Not only can independent providers like UBX Cloud provide carrier-grade cloud, we can do it more economically, more reliably, and with better performance all-around.

We care about the value you receive because we care about the relationship we have with every customer.

Experience the Difference

If you’re ready for carrier-grade performance without the Big Cloud baggage, give us a call.

We’ll show you just how much better it feels to have the power, transparency, and support you’ve always deserved.

Microsoft and Amazon Don’t Care About Outages, So Here’s What You Can Do About It

For those who are affected by the Microsoft and Amazon outages today – and who isn’t in some way? – you might expect both corporate giants would be trying to move heaven and earth to get the outages solved.

If you know anything about how these companies operate, you’ll know better than to have such luck.

The truth is, both of these companies are complete garbage when it comes to outages, and that’s because there is no economic incentive for them to care.

Microsoft and Amazon save money through multitenancy and oversubscribing. Multitenancy is when a single application serves multiple customers, or “tenants,” so each tenant’s data is supposedly kept private, but all the tenants have to share the available bandwidth.

Everyone accesses the same resources. It’s cost-efficient in theory, but it puts everyone at risk of an outage in the event of a single point of failure.

To top it off, they make it worse by oversubscribing, which is to say they allocate resources to more clients than they could actually accommodate if everyone tried to use the resources all at once.

It works out great for Microsoft and Amazon because they sell way more capacity than they could actually provide – and way more than they actually have to pay to maintain.

Have you ever bought tickets for a flight and were later told they were “oversold”? You sit there and wonder why they would sell more seats than they have, and they end up having to ask people to give up their seats. It sounds insane because it is, but it’s the same theory. They don’t think everyone will actually show up and they can just keep the money for the unused tickets.

If this theory holds and they never really get more users than they can handle, they’re fine. But when you have an outage, lots more people are affected.

You could probably get a 10 percent credit from Amazon or Microsoft if you work yourself to the bone, but it wouldn’t be worth the time and effort. No one expects you can get ahold of anyone at either company about the outage, so people just shrug it off and figure it’s a fact of life.

As a private company, if we did this poor a job providing service to our clients – and took this cavalier an attitude toward outages – our clients would leave us.

And we would deserve it.

We know that, of course, and we actually care about our clients, so we do everything to make sure their service is reliable. But Microsoft and Amazon don’t. Because they don’t have to. And because it’s not in their nature to.

Solution? Let UBX handle your cloud storage and data management needs. We actually care. Email me today at steven.panovski@ubxcloud.com. I’ll respond and everything.