Hospitals and clinics now run on a web of connected devices. Heart monitors, infusion pumps, imaging scanners and staff laptops all send information back and forth across the same networks that carry patient records. Every one of those connections is a route into the healthcare data sitting behind it.

The Internet of Medical Things (IoMT) refers to the web of connected devices, from wearable glucose sensors to hospital-grade MRI scanners. Artificial intelligence sits alongside it, reading scans, flagging unusual vital signs and helping staff spot problems earlier. Both technologies bring real benefits to patient care, but they also widen the number of places where healthcare data can be stolen, altered or held to ransom.

This article looks at why healthcare data has become such a popular target, what UK and Irish rules say about protecting it, and the practical steps that hospitals, clinics and smaller providers can take to keep patient information safe without slowing down the people who use it every day.

Why Healthcare Data Has Become a Prime Target

Criminals go where the money is, and patient records are worth far more on the black market than a stolen credit card number. A single record can include insurance details, medical history and identifying information all in one place, which makes healthcare data useful for fraud long after a breach is discovered.

The scale of the problem is reflected in the cost of dealing with it. Healthcare has had the highest average data breach cost of any industry for over a decade, reaching $7.42 million per incident in IBM’s 2025 Cost of a Data Breach Report, and organisations in the sector typically take around 279 days to identify and contain a breach involving healthcare data. Our cybersecurity facts page covers how this compares with other sectors.

Beyond Ransomware: Data Poisoning and Adversarial AI

Ransomware still causes the most damage, locking staff out of patient files until a payment is made. But as AI tools take on a bigger role in reading scans and flagging risk, a newer threat has appeared alongside it: deliberately feeding an AI system corrupted or misleading data so it makes the wrong call.

This is known as data poisoning, and it matters because a diagnostic AI tool that has been quietly fed bad training examples can misread a scan without anyone noticing straight away. Adversarial attacks work similarly, making tiny changes to an image or a data point that a person would never spot but that can trick an algorithm into reaching the wrong conclusion. Both attacks depend on access to the same healthcare data that trains and feeds these systems, so protecting the data itself is the first line of defence against them.

The Shadow IoT Problem in Hospitals

Most security teams can list the medical devices they manage. Far fewer can list the ones they do not. Shadow IoT refers to unauthorised devices, personal fitness trackers, staff smartwatches, a nurse’s own tablet, that connect to hospital Wi-Fi without IT ever approving them.

The scale of connected equipment in a modern hospital makes this hard to control. Research shows that the average hospital now runs 10 to 15 connected medical devices per bed, and a 2026 study of more than 2 million IoMT devices found that 99% of hospitals have at least one device with a known, exploited security flaw. Many of those devices are running outdated software that can no longer be patched, leaving the healthcare data passing through them permanently exposed. Our guide to ransomware attacks explains how attackers commonly get from an unmanaged device into the wider network.

UK and Ireland Rules Shaping Healthcare Data Protection

Most guidance on this topic is written for the US and its HIPAA rules, which leaves a gap for organisations working under UK and Irish law. The requirements differ in several important ways, and getting them right protects both patients and the organisations that handle their healthcare data.

The NHS Data Security and Protection Toolkit

Any organisation that accesses NHS patient data or systems in England must complete the Data Security and Protection Toolkit (DSPT) every year. The toolkit checks performance against the National Data Guardian’s data security standards and, for larger organisations, against the National Cyber Security Centre’s Cyber Assessment Framework.

The 2025 to 2026 version added a dedicated objective covering the lawful use and sharing of patient information, alongside existing checks on staff training, access controls, incident response and unsupported systems. Suppliers, GP practices and NHS trusts all submit separately, and the evidence required has become more detailed with each cycle. Getting this right does more than satisfy an auditor; it forces an organisation to document exactly who can see its healthcare data and why.

Lessons from Ireland’s HSE Ransomware Recovery

In May 2021, Ireland’s Health Service Executive was hit by a Conti ransomware attack that forced it to shut down all its IT systems nationwide. Maternity and oncology appointments were delayed, laboratory results had to be reported on paper, and it took the HSE more than four months to restore all of its servers and applications.

A review by PwC afterwards found the HSE had what it called a low level of cybersecurity maturity, including no dedicated security chief and weak controls against the kind of attack that struck. The recovery has since cost well over $100 million. For any healthcare provider handling patient records, the lesson is straightforward: basic controls such as patching, network segmentation and a named person responsible for security matter far more than any single piece of new technology.

GDPR and Automated Decisions Involving Healthcare Data

Healthcare data counts as special category data under UK and EU GDPR, which means it needs stronger protection than ordinary personal information. Article 22 of the regulation also gives patients the right not to be subject to a decision based solely on automated processing, including AI, where that decision has a legal or similarly significant effect on them.

In practice, this means an AI system can support a clinician’s judgement on a diagnosis or a treatment plan, but a person needs to remain part of that decision. Building this human check into a workflow from the start is far easier than trying to add it later, and it also gives patients a clear route to challenge a decision they disagree with. Our page on cybersecurity compliance sets out how GDPR fits alongside other rules that apply to UK organisations.

Building a Zero Trust Approach to Healthcare Data

Building a Zero Trust Approach to Healthcare Data

Firewalls alone are no longer enough to protect a hospital network. Once an attacker gets past the perimeter, a flat network lets them move freely between systems, which is exactly what happened during several of the largest healthcare breaches on record. Zero Trust starts from a different assumption: no device or user is trusted by default, wherever they sit on the network.

Micro-segmentation for Connected Medical Devices

Micro-segmentation splits a hospital network into smaller, isolated zones, so an infusion pump can only communicate with the systems it needs to reach, rather than the entire network. If an attacker compromises one device, the damage is contained to that zone instead of spreading to patient records held elsewhere.

This matters because so many medical devices cannot be patched or updated in the way a laptop can. Segmenting them away from administrative systems and staff devices means a vulnerable scanner or monitor is no longer a direct route to the healthcare data held in clinical and billing systems.

Identity and Access Controls for AI Systems

AI tools that read scans or flag patient risk need their own access controls, just as a person would. Each system should have a defined identity, clear limits on what data it can reach, and a log of what it has accessed and when.

Without this, an AI tool with broad access becomes an attractive target in its own right: compromise the tool and an attacker gains the same reach into healthcare data that the tool itself has. Treating algorithms as accounts to be managed, rather than as background infrastructure, closes that gap.

What Smaller Providers Can Afford to Do

Healthcare Data, what small providers can do

Most published advice on this topic is written for large hospital groups with dedicated security teams and six-figure budgets. A mid-sized private clinic or a small GP practice handling the same sensitive healthcare data rarely has either, yet the rules and the risks apply just as much.

The good news is that the highest-value steps are also some of the cheapest. A full device inventory costs staff time rather than software licences. Turning on multi-factor authentication for every account that touches patient records is usually included in tools an organisation already pays for. Reviewing who has access to which systems and removing access to systems nobody uses anymore requires a spreadsheet and an afternoon rather than a large budget.

Spending does need to rise for a smaller number of items: network segmentation hardware, a proper backup system that is tested rather than assumed to work, and cyber insurance that actually covers ransomware response. Weighing these costs against the average breach cost for the sector, well over seven million dollars according to IBM’s latest figures, makes the case for early investment straightforward. A smaller provider that puts a few thousand pounds into segmentation and backups is protecting itself against a bill that could otherwise run into the hundreds of thousands, without ever accounting for the damage to patient trust that follows a public breach.

How AI Helps Defend Healthcare Data

AI is not only a source of new risk. Used well, it also gives security teams a way to keep up with the sheer volume of activity across a modern hospital network, something that would be impossible to review manually.

Cutting Alert Fatigue with Machine Learning

Security teams in large hospitals can receive thousands of alerts a day from firewalls, antivirus tools and device monitors. Most are false alarms, and staff who are overwhelmed by noise start to miss the alerts that matter. Machine learning models can learn what normal activity looks like on a specific network and flag only the events that fall genuinely outside that pattern.

This does not remove the need for trained staff, but it does mean their attention goes to the alerts most likely to involve real harm to healthcare data, rather than being spread thinly across thousands of low-priority notifications.

Predictive Vulnerability Management

Rather than waiting for a scanner to find a known flaw, some AI-based tools now look at a device’s age, its software version and how it is used to estimate which systems are most likely to be exploited next. This lets IT teams patch or isolate the highest-risk devices first, rather than working through a list in any particular order.

For a hospital with tens of thousands of connected devices, this kind of prioritisation is the difference between fixing the right ten devices this month and fixing the wrong ten.

A Practical Roadmap for Securing Healthcare Data

None of this needs to happen at once, and trying to do everything simultaneously usually means nothing gets finished properly. A staged approach lets a mid-sized clinic or a large NHS trust make steady progress without disrupting patient care.

  1. List every connected device. Build and keep updating a complete inventory of every device that touches your network, including those staff have brought in themselves.
  2. Segment the network. Separate medical devices, administrative systems and guest Wi-Fi so a breach in one area cannot spread freely to another.
  3. Set access rules for people and AI systems alike. Give each user and each algorithm only the access it needs, and review that access regularly.
  4. Patch what can be patched, isolate what cannot. Where a device cannot be updated, restrict what it can connect to instead.
  5. Test your incident response plan. Run a practice exercise so staff know what to do in the first hour of an attack, not just on paper.
  6. Complete your DSPT or equivalent audit honestly. Treat the annual submission as a genuine check on your defences rather than a box-ticking exercise. Our best cybersecurity measures guide covers many of these steps in more detail for smaller teams without a dedicated security department.

Security teams and clinical staff often pull in different directions, since doctors need instant access to healthcare data in an emergency while IT wants tighter controls. The roadmap above is designed to reduce that friction: segmentation and access rules protect the network without adding extra steps for a clinician trying to reach a patient’s file during a crisis.

Next Steps for Protecting Healthcare Data

Securing healthcare data is not a one-off project with a fixed end date. New devices join hospital networks every month, AI tools take on more clinical tasks each year, and the rules governing it all continue to change. What holds up over time is a small set of habits: knowing every device on the network, limiting what each one can reach, and treating annual audits like the DSPT as a genuine test rather than a formality.

If your organisation has been through a data security incident, or you have questions about how these rules apply to your service, share them in the comments below. We read every one and use them to shape future updates to this guide.

Frequently Asked Questions on Healthcare Data Security

These are some of the questions we hear most often from readers working in UK and Irish healthcare organisations.

What is the difference between IoT and IoMT?

IoT (Internet of Things) covers any connected device, from a smart thermostat to a factory sensor. IoMT (Internet of Medical Things) is the subset used specifically in healthcare, such as infusion pumps, patient monitors and diagnostic imaging equipment.

Does the NHS DSPT apply to private clinics?

Yes, if the organisation accesses NHS patient data or systems, including private providers delivering NHS-commissioned care, GP practices and IT suppliers working with the NHS.

Can AI tools help with GDPR compliance?

AI can help identify what personal data an organisation holds and speed up the reporting of a breach, but it cannot make the final call on a decision that has a legal or similarly significant effect on a patient. That still needs a person.

How do I secure a medical device that cannot be patched?

Network segmentation is the usual answer. Keep the device on its own restricted network zone so it can only communicate with the systems it truly needs, limiting what an attacker can reach if that device is compromised.

What does a healthcare data breach typically cost?

According to IBM’s 2025 Cost of a Data Breach Report, the average healthcare breach cost $7.42 million globally in 2025, the highest of any industry, though this was down from $9.77 million the year before.

What is Shadow IoT, and why does it matter in hospitals?

Shadow IoT means devices connected to a network without IT’s knowledge or approval, such as a personal smartwatch or an unregistered tablet. These devices sit outside normal monitoring and patching, so they often become the easiest way into a hospital network.