Challenges surrounding Identity Access Management (IAM), Authentication, and Access Control are being uncovered at four times the rate of the previous year. Nearly two-thirds of these issues fall into the Critical or High category.
Despite Multi-Factor Authentication (MFA) becoming standard practice for healthcare IT teams, healthcare’s complex network of Electronic Health Records (EHRs), third-party applications, and medical devices can create blind spots that lead to unintended or permanent access, especially when projects conclude or workflows change.
The Hidden Identity Risk
The hidden risk lies in identities that are not tied to any specific individual. Service accounts keep applications running, medical devices transmit data, and cloud workloads integrate different systems. Working behind the scenes, they don’t change roles, get disabled when someone leaves, or carry a badge. These identities may have broader access, sometimes exceeding that of actual users.
When a service account is compromised, it can give attackers the freedom to cross systems without triggering the usual cybersecurity alarms associated with a stolen employee account.
IT teams must also factor in the risk that deactivating the wrong account could halt a clinical interface, disrupt data transmission from a device, or interfere with a vendor-supported workflow.
Impact on Healthcare
Non-human identities are invaluable to threat actors because they often operate continuously in the background of healthcare environments. The increased use of cloud solutions, automation, connected devices, and AI has led to the prevalence of non-human identities, and this trend will only continue.
Key Questions for Healthcare Leaders to Consider
How are you maintaining visibility of your non-human identities? Including:
- How many non-human identities are active in our systems?
- What data and systems can each identity access?
- When was that access last evaluated?
- Which identities are critical to patient care or other essential operations?
Threats to Monitor
Active Exploitation of On-Premises SharePoint RCE Vulnerability
Overview: Threat actors are actively exploiting a vulnerability affecting on-premises Microsoft SharePoint Server. The issue is especially urgent for organizations still running SharePoint Server 2016 or 2019, which reached end of support on July 14, 2026.
Healthcare Impact: On-premises SharePoint remains prevalent in healthcare for policies, internal collaboration, documentation, and file exchange. A compromised server could reveal sensitive material and provide an attacker another avenue into systems connected through Microsoft identity and trust relationships.
Recommended Actions: Apply the required cumulative updates and confirm patch coverage across every SharePoint server. Check for signs of earlier compromise and review any internet-facing exposure. Audit Site Member permissions and rotate ASP.NET machine keys. For SharePoint 2016 and 2019, isolate the system or move migration plans forward.
Questions to Ask Your Team:
- Do we have a complete inventory of on-premises SharePoint servers and versions?
- Is any SharePoint server still exposed to the public internet?
- Have we checked for prior compromise and rotated machine keys after patching?
Peer Pulse: Jim Kirk, Sr. Director Consulting Services, Fortified
Healthcare Is Finding More Risk. Now What?
Russell: The Mid-Year Horizon Report 2026 found that the average healthcare organization is carrying 16 Critical and High risks, up from 10 last year. At the same time, remediation rates dropped from 23% to 6%. What do those numbers tell you?
Jim: We’re seeing more, which is good. The uncomfortable part is that we are not fixing more. Visibility has improved, but capacity has not kept pace. Most teams already know where many of their problems are. The real question is whether they have the time, authority, and operational support to get those problems resolved.
Russell: Why is identity still such a stubborn problem?
Jim: Because identity is no longer just about employees. Every application, service account, cloud platform, vendor integration, and connected device creates another identity to manage. The process around those identities has not grown at the same speed as the environment. That is why this becomes an operations issue, not just a security issue. These accounts support workflows people depend on every day.
Russell: Cybersecurity Supply Chain Risk Management findings are tracking toward a sixfold increase. What is driving that?
Jim: Part of it is simple: healthcare uses more vendors. The other part is that assessment programs are getting better at finding risk that may have been there for years. Finding it is only step one. Someone still must work with the vendor, decide what is acceptable, track the fix, and follow up. That handoff is where a lot of programs get stuck.
Russell: Incident response and recovery planning also continue to show up as threat areas. Why do organizations struggle there?
Jim: Because a plan can look great until people have to use it. The first exercise usually exposes something important: a department that did not know its role, a decision no one owns, or a dependency that never made it into documentation. You cannot find those gaps by reading the plan. You need to get people in a room and make them work through the problem.
Russell: You have seen cyber incidents affect much more than technology. What should healthcare leaders take from that?
Jim: The moment another department is disrupted, that department is part of the response. We have seen incidents affecting physical security, badge access, and routine operational workflows. Those teams may never think of themselves as part of cybersecurity, but during an incident they are. The Incident Recovery (IR) plan needs to match the way the team will operate during a live incident.
Russell: What is one thing healthcare security leaders should focus on for the rest of 2026?
Jim: Turn visibility into decisions. Do not let the risk register become a waiting room. Decide what matters most, assign an owner, and keep pressure on the item until it is fixed or formally accepted. Strong programs are not the ones with the cleanest reports. They are the ones that keep the highest-risk work moving.
Closing Perspective
Healthcare is getting better at finding risk, but a long list of findings does not protect the organization if no one owns the next decision. Neither does a complete inventory of service accounts, vendors, and connected systems.
Whether a non-human identity or a risk finding, give each one an owner and make sure the highest-risk items lead to action.
Action is what makes better visibility truly matter.