TL;DR: Healthcare now generates 30% of the world’s data, according to Probely, while hacking-related breaches in the sector rose 239% and ransomware attacks rose 278% between January 2018 and September 2023, according to Snyk’s analysis. The core lesson is that HealthTech security fails when development, monitoring, and staff readiness are treated as one-time tasks instead of continuous controls.
NHIMG editorial — based on content published by Probely: From Innovation to Protection: Ensuring Data Security in Healthcare
By the numbers:
- The healthcare industry generates 30% of the world’s data volume, making it one of the most data-intensive sectors.
- Between January 2018 and September 2023, hacking-related data breaches in healthcare increased by 239%.
- Ransomware attacks in healthcare increased by 278% over the same period.
Questions worth separating out
Q: How should healthcare organisations implement continuous security in HealthTech systems?
A: They should build controls into the development and operating model, not bolt them on later.
Q: Why do AI and IoT systems increase healthcare security risk?
A: They expand the number of places where sensitive data can be collected, processed, or exposed, and they often introduce weaker trust boundaries than core clinical systems.
Q: What do healthcare teams get wrong about security by design?
A: They often treat it as a design principle instead of an operational control.
Practitioner guidance
- Embed security checks into CI/CD pipelines Add automated testing, policy gates, and vulnerability scanning at each build and release stage so defects are found before production deployment.
- Map data paths for AI and IoT systems Inventory where AI models, connected devices, and analytics tools collect, store, and transmit patient data.
- Review privileged and non-human access Audit service accounts, API credentials, and integration accounts that can reach clinical systems or health records.
What's in the full article
Probely's full article covers the operational detail this post intentionally leaves for the source:
- Step-by-step guidance on applying security by design inside a HealthTech development lifecycle
- Practical examples of continuous testing and monitoring for healthcare applications
- Recommended staff training themes for healthcare teams handling sensitive data
- Implementation context for using API and web scanning in a healthcare delivery environment
👉 Read Probely's analysis of continuous security for healthcare data protection →
Healthcare data security is changing fast. Are your controls keeping up?
Explore further
Healthcare security is a continuous control problem, not a periodic assurance problem. The article is right to frame security as something that must evolve with the technology stack because healthcare systems change too quickly for annual review cycles to provide meaningful protection. Continuous validation, monitoring, and release-integrated controls are the only credible way to keep pace. Practitioners should design for persistent assurance, not event-driven remediation.
A question worth separating out:
Q: Who is accountable when healthcare data is exposed through weak access governance?
A: Accountability sits with the organisation that owns the data, the systems, and the access lifecycle, even when a vendor or contractor is involved. Healthcare compliance frameworks expect organisations to maintain safeguards, logs, and access oversight. If third-party access is in scope, ownership must include offboarding, review, and evidence of control operation.
👉 Read our full editorial: Healthcare data security needs continuous controls, not annual reviews