Join our Newsletter — 33% off our NHI Course
Home› FAQ› Cyber Security› Why do cyberattacks and privacy incidents become more…
Cyber Security

Why do cyberattacks and privacy incidents become more damaging during healthcare disruptions like a pandemic?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated September 26, 2026 Domain: Cyber Security

Disruptions create confusion, staffing strain, and rushed technology changes, which expand the attack surface for phishing, malware, and unauthorized access. In healthcare, that means attackers can exploit remote work, rapid telehealth adoption, and distracted staff to steal data or move laterally. Risk rises when governance, training, and verification lag behind operational urgency.

Why disruptions amplify the attack surface in healthcare

Pandemics and similar disruptions compress decision-making. Teams shift to remote access, telehealth, new vendors, and temporary workflows before governance catches up, so normal safeguards such as review, segmentation, and verification become harder to sustain. That combination creates more opportunities for phishing, malware, credential theft, and accidental disclosure, especially when staff are under load and patients still need uninterrupted care.

When the operating model changes faster than security controls, the environment becomes easier to exploit. Attackers do not need novel techniques to benefit, they often need only a wider set of exposed systems, hurried exceptions, and users who are working outside familiar routines.

Healthcare also carries a strong trust component. Clinicians, patients, and administrators must exchange data quickly, which makes rushed access decisions and exception handling more dangerous than in less time-sensitive sectors.

Why privacy incidents become harder to contain

Privacy harm grows when sensitive data flows expand faster than policy enforcement. Telehealth, patient portals, home devices, and emergency integrations can expose more records, more logins, and more third-party handling points at once. If consent, purpose limitation, retention, and access review are not updated at the same pace, a small mistake can affect many records and many teams.

In disruptions, privacy failures are often governance failures as much as technical ones. A rushed rollout may work operationally while still creating weak audit trails, broad access, or unclear ownership of who can see and share information.

That matters because healthcare data is unusually sensitive and often difficult to replace once disclosed. The practical issue is not only breach notification, but also downstream misuse, loss of patient trust, and regulatory exposure when control expectations lag behind the new operating model.

What changes when urgency outruns verification

Urgency changes the balance between speed and assurance. Remote work and rapid digital care can be necessary, but they reduce the time available for identity proofing, device trust checks, configuration review, and exception management. In that gap, attackers can exploit weak authentication, overbroad permissions, or staff attention diverted by crisis response.

Healthcare disruptions also increase the chance of lateral movement once an account or endpoint is compromised. Shared clinical systems, interconnected vendors, and fast-moving support arrangements can let a single foothold reach records, scheduling, billing, or other sensitive services if network and access boundaries are relaxed.

The main security problem is not disruption itself, it is ungoverned acceleration. The more the organisation relies on temporary access paths and hurried exceptions, the more damage a single compromise can cause.

Risk and Threat Considerations

Disrupted healthcare environments create a larger and less stable attack surface, so phishing, ransomware, credential theft, and privacy misuse can spread faster than normal control processes can react. The same operational pressure that keeps care moving can also make malicious access look routine.

Failure mechanism: Security and privacy controls are bypassed or weakened through rushed onboarding, broad temporary access, remote-work trust assumptions, and delayed verification of users, devices, and third-party connections.

Impact: Attackers or careless insiders can reach more systems and records, move laterally, and expose sensitive health data at scale, while the organisation struggles to distinguish emergency access from abnormal activity.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST SP 800-53 Rev 5 sets the technical controls, while GDPR defines the regulatory obligations.

FrameworkControl / ReferenceRelevance
NIST SP 800-53 Rev 5IA-2 — Identification and Authentication (Organizational Users)Crisis-driven remote access makes user authentication a central control concern.
AC-6 — Least PrivilegeRapidly granted access during disruptions can create excessive privilege and lateral movement risk.
AU-2 — Event LoggingDisrupted operations need logs to distinguish emergency access from misuse.
Recommendation — Enforce strong user authentication for remote and privileged healthcare access. Limit emergency access to the minimum privileges needed and time-box it. Log emergency access and review it quickly for abnormal use.
GDPRArt.32 — Security of processingHealthcare disruptions often expand processing paths and raise security-of-processing obligations.
Art.25 — Data protection by design and by defaultRapid telehealth and remote access changes need privacy controls built into the new workflow.
Recommendation — Apply appropriate technical and organisational measures to new patient-data flows. Build privacy defaults into new care channels before broad rollout.

Practitioner Guidance

What to prioritise: Treat the highest-risk change points first, remote access, telehealth workflows, privileged support paths, and any emergency exception that bypasses normal approval or review.

What to verify: Confirm that temporary access still has an owner, an expiry, a logging path, and a rollback plan. If those four elements are missing, the control is not temporary, it is simply expanded access.

Decision rule: If a change increases reach to patient data or core clinical systems, require stronger verification before rollout, even during a crisis. Speed can be justified, but undocumented trust should not be.

Practitioner takeaway: The safest disruption response is not to slow everything down, but to keep access bounded, observable, and reviewable while the organisation is moving fast.

Deepen Your Knowledge

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Reviewed and updated by the NHIMG editorial team on September 26, 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org