A Decade of Healthcare Cyber Threats: Empirical Analysis, Evidence-Based Prioritisation, and AI Threat Model
This paper presents an empirical analysis of 1,214 healthcare cyber threat records from 2017 to 2024, revealing a measurable shift toward stealth-oriented tactics, a critical misalignment between current detection guidance and attacker focus, and the identification of high-priority techniques that address both traditional vulnerabilities and emerging AI-integrated clinical system threats.
Original paper licensed under CC BY 4.0 (http://creativecommons.org/licenses/by/4.0/). This is an AI-generated explanation of the paper below. It is not written or endorsed by the authors. For technical accuracy, refer to the original paper. Read full disclaimer
Imagine the digital world as a giant, bustling city where every building is a different kind of business. Some buildings sell toys, others sell clothes, but one specific neighborhood is the most valuable real estate in town: the hospital district. Why? Because inside these buildings, people are keeping life-saving secrets (like medical records) and running machines that literally keep people alive. If a burglar breaks into a toy store, they might steal some action figures. If they break into a hospital, they can hold the whole neighborhood hostage, demanding a ransom to turn the lights back on, or they can steal secrets to sell on the black market. Because of this, the "burglars" (cybercriminals) have been trying to break in for years, but they aren't just using crowbars anymore. They've learned to wear invisible cloaks.
To understand how we track these burglars, security experts use a giant, living map called MITRE ATT&CK. Think of this map not as a list of locks, but as a catalog of moves. It doesn't just say "they broke the window"; it says "they used a crowbar," "they picked the lock," or "they walked in the front door because the owner left it open." This map helps defenders know what tricks to watch out for. Another tool is the CISA Known Exploited Vulnerabilities (KEV) list. If the ATT&CK map is the catalog of moves, the KEV list is the "Most Wanted" bulletin board. It only lists the specific broken locks and open windows that burglars have actually used to get inside recently, ignoring all the theoretical holes that no one has touched yet. The big question researchers have been asking is: "Are the security guards watching the right doors?"
This paper takes a deep dive into the last decade of digital break-ins at hospitals to answer that question. The researchers acted like digital detectives, gathering a massive collection of 1,214 "crime reports" from 2017 to 2024. They looked at 44 different groups of attackers, ranging from organized crime gangs to nation-state spies, and tracked exactly which moves they used. What they found is a bit of a plot twist. For a long time, security guards were trained to watch for the "loud" moves: the ones where a burglar smashes a window (Initial Access) or hides a secret note under a rug (Persistence). But the paper shows that the burglars have changed their style. They are now masters of the "silent" move. Instead of breaking in and hiding, they are using the owner's own keys and walking right through the front door, blending in with the normal crowd.
The study reveals that the most common move these attackers use today is Defense Evasion, which accounts for about 15% to 20% of all their actions every single year. This is the art of staying invisible. In contrast, the old-school moves like "hiding in the attic" (Persistence) and "breaking the front door" (Initial Access) have declined significantly in how often they appear in the data distribution over the 2017–2024 period, dropping from double-digit percentages down to zero in the observed technique use. This doesn't mean these tactics are extinct or never used, but rather that they are no longer the primary tactics seen in the data compared to the rise of stealthier methods. The attackers have realized that if they use legitimate tools that the hospital already has—like the computer's own command center or the staff's valid login badges—they don't leave any footprints. It's like a thief who doesn't pick the lock but instead waits for the owner to open the door, then just walks in and acts like they belong.
Here is the scary part: the security guards are still looking for footprints. The paper found a "structural inversion," meaning the security advice is strongest exactly where the burglars are least active, and weakest where the burglars are most active. The guards have built amazing sensors to catch the loud, messy break-ins at the end of a crime, but they have almost no sensors for the quiet, invisible moves happening at the very beginning. The researchers identified 42 specific "moves" that are happening right now but are barely being watched. These are the top priorities for hospitals to fix immediately.
Even more interesting, the paper shows that this isn't just about old computers anymore. Hospitals are starting to use Artificial Intelligence (AI) to help doctors diagnose patients. The researchers found that the same "silent" tricks the burglars use on regular computers work perfectly on these new AI systems, too. A burglar doesn't need to learn a new way to break into an AI; they just use the same old tricks they've been using for years. The paper concludes that we need to stop building security based on what burglars used to do and start building it for what they are doing now: walking in the front door, wearing a uniform, and hoping no one notices they aren't supposed to be there. The good news is that the paper provides a clear "to-do" list of 42 moves to block, and for 12 of those 42 techniques, the security tools already exist and can be turned on right now for free.
Drowning in papers in your field?
Get daily digests of the most novel papers matching your research keywords — with technical summaries, in your language.