CinchOps managed IT services and cybersecurity Houston Texas
  • Services
    • Managed IT
    • Cybersecurity
    • Business Continuity & Disaster Recovery (BCDR)
    • Virtual CTO & CIO Services
    • Cloud Services
    • Software Defined Wide Area Networks (SD-WAN)
    • Voice Over IP (VoIP)
    • Business Process Automation
  • Industries
    • By Company Size
      • Small & Midsize Businesses
      • Enterprise Scale
    • Construction
    • CPA Firms
    • Energy Services & Utilities
    • Engineering
    • Law Firms
    • Manufacturing
    • Oil & Gas Services
    • Wealth Management
  • Local to You
    • Brookshire
    • Cypress
    • Fulshear
    • Houston
    • Katy
    • Missouri City
    • Richmond
    • Rosenberg
    • Sealy
    • Sugar Land
    • The Woodlands
    • Tomball
  • Reviews
  • Resources
    • IT Scorecards
    • IT Outage Calculator
    • Blog
    • News & Updates
    • Videos
    • FAQs
    • CinchOps CyberJeopardy
  • Research
    • Houston Area Security Index
    • Houston Area Patch Index
    • Houston MSP Review Index
    • Houston Growth Index
    • Houston Vulnerability Index
    • Cybersecurity by the Numbers
  • About Us
    • Our Story
    • Your Story
    • My Story
  • Contact
I Need IT Support Now
Managed IT Houston Healthcare
Shane March 28th, 2025

The Growing Cybersecurity Crisis in Healthcare: 2025 Report Analysis

When Ransomware Targets Hospitals: Insights from Claroty’s Latest Report

Healthcare Security
89% of Hospitals Run Medical Systems Attackers Can Already Exploit.

Claroty scanned millions of connected medical devices and found the exposure is nearly universal. Here is what is most at risk - and the five-step plan to fix it.

TL;DR
Claroty's Team82 analyzed more than 2.25 million connected medical (IoMT) devices and 647,000 operational-technology devices across 351 hospitals for its State of CPS Security: Healthcare Exposures 2025 report. The results are stark: 99% of organizations have devices with known exploited vulnerabilities (KEVs), and 89% run medical systems that carry ransomware-linked flaws and are insecurely connected to the internet. Imaging systems - X-rays, CT, MRI - are the riskiest category, with 28% carrying KEVs. Russian ransomware crews like Black Basta and BlackCat have already hit major systems (the Change Healthcare and Ascension attacks). The fix is not more scanning but a focused, five-step plan: scope, discover, validate, prioritize, and mobilize - so the handful of genuinely exploitable, internet-exposed devices get fixed first.
📊 The Exposure 🎯 Who Is Attacking 🪜 The 5-Step Plan 🚀 How CinchOps Helps

Nearly every hospital is running connected devices attackers can already exploit - and in healthcare, that is not just a data problem, it is a patient-safety problem.

Hospitals depend on thousands of connected devices, from MRI machines to patient monitors to building controls. Claroty's healthcare report shows how many of those devices carry flaws attackers actively use - and how many are needlessly exposed to the internet. Here is the scale of the problem, who is exploiting it, and the practical plan the report recommends for getting ahead of it.

The real point: you cannot patch everything, so the goal is to find the small set of devices that are both exploitable and reachable - and fix those first.

The Scale of the Exposure

Known-exploited vulnerabilities are almost everywhere - but concentrated in a few systems.

Hospital information systems and imaging devices carry the most known-exploited vulnerabilities - and they hold the most sensitive data.

% CARRYING KNOWN-EXPLOITED VULNERABILITIES Hospital Information Systems 45% Imaging systems (X-ray, CT, MRI) 28% Patient devices (monitors, ECG) 8% Connected surgical devices 3% Operational technology (building systems) 2%
Share of each system type carrying known-exploited vulnerabilities (Claroty Healthcare Exposures 2025).

Across the dataset, 99% of organizations had at least one device with a known-exploited vulnerability, and 89% had medical systems with ransomware-linked flaws that were also insecurely connected to the internet. The most exposed are the systems that matter most: hospital information systems, which hold patient records and financial data, and imaging systems, which are essential to diagnosis.

Who Is Attacking Healthcare

Ransomware crews target hospitals because they cannot afford downtime.

When a hospital goes down, patient care is on the line - which is exactly why ransomware groups see healthcare as a payer.

  • Black Basta. A Russian ransomware-as-a-service operation whose affiliates have hit more than 500 organizations. It was tied to the 2024 Ascension attack, which forced patient diversions and drove roughly $1.8 billion in losses.
  • BlackCat / ALPHV. A Russia-affiliated crew behind the 2024 Change Healthcare attack, using triple extortion. The FBI believes it compromised over 1,000 organizations and took more than $300 million in ransoms.
  • Why hospitals get targeted. Attackers know care cannot stop, so hospitals are among the critical-infrastructure targets most likely to pay - which keeps the attacks coming.
  • How they get in. Exploits against exposed devices and phishing provide the foothold, then double- and triple-extortion pressure follows.

The 5-Step Plan to Fix It

Claroty's framework goes beyond "patch everything" to "fix what actually matters."

The goal is to find the small set of devices that are both genuinely exploitable and reachable - then remediate those first.

  • Scope. Account for the critical clinical processes by device type and department, so you know what a compromise would actually disrupt.
  • Discover. Identify every connected device, its detailed attributes, and how it communicates - you cannot protect what you cannot see.
  • Validate. Confirm which exposures are real and externally reachable, filtering out the theoretical from the truly dangerous.
  • Prioritize. Rank by business impact and exploitability using a security framework, not just raw vulnerability counts.
  • Mobilize. Apply practical mitigations - patching, closing open ports, segmentation, and endpoint protection - starting with the highest-risk devices.
100% Free

Free Cybersecurity Assessment

Do you know which of your connected devices are exposed and exploitable? Get a FREE review of your device and network security.

Get Your Free Assessment

In healthcare, a hacked MRI or patient monitor is not just stolen data - it can delay care. That raises the stakes and is exactly why exposed, exploitable devices have to be found and fixed first.
Shane Stevens, CEO, CinchOps - LinkedIn

Device and Network Security for Healthcare

CinchOps helps Houston-area healthcare and clinical practices find exposed devices, segment their networks, and remediate the exploitable ones first - through our cybersecurity and managed IT services.

Explore CinchOps cybersecurity →

How CinchOps Helps Secure Your Business

CinchOps is a Katy, Texas managed IT services provider serving businesses across the Houston metro, including healthcare practices with connected devices to protect.

  • Device and exposure assessment. We find every connected device and flag the ones that are exploitable and internet-reachable.
  • Secure network design. Segmentation that keeps a compromised device from reaching critical systems.
  • 24/7 monitoring and response. Continuous detection so an intrusion is caught before it spreads.
  • Zero Trust for critical systems. Verify every access request to the systems that hold sensitive data.
  • Audits and staff training. Regular reviews and awareness training to keep exposure low.

Do not wait to become the next headline. Contact CinchOps to protect your patients, staff, and reputation.

Frequently Asked Questions

What did the Claroty healthcare report find?

Its State of CPS Security: Healthcare Exposures 2025 report analyzed 2.25 million IoMT and 647,000 OT devices across 351 hospitals. It found 99% of organizations have devices with known-exploited vulnerabilities, and 89% run medical systems with ransomware-linked flaws that are insecurely internet-connected.

Which medical systems are most at risk?

Hospital information systems and imaging devices. Around 45% of hospital information systems and 28% of imaging devices carry known-exploited vulnerabilities - and both hold or support highly sensitive clinical data.

Why do ransomware groups target hospitals?

Because care cannot stop. Hospitals are among the critical-infrastructure targets most likely to pay to restore operations, which makes them attractive to crews like Black Basta and BlackCat that were behind the Ascension and Change Healthcare attacks.

Is patching every device the answer?

No - it is not realistic, and many medical devices cannot be patched easily. The report recommends finding the devices that are both genuinely exploitable and externally reachable, and fixing those first through a scope-discover-validate-prioritize-mobilize approach.

What is a KEV?

A Known Exploited Vulnerability - a flaw that attackers are actively using in the real world, tracked in the U.S. CISA KEV catalog. A device carrying a KEV and exposed to the internet is a top-priority risk.

Discover More

CinchOps Cybersecurity Services
Dragos 2025 OT/ICS Report: Industrial Ransomware Surges
Industrial Ransomware Surges in Q3 2025

Sources

  • Claroty, State of CPS Security: Healthcare Exposures 2025
  • Claroty, Team82 Research on Riskiest Medical Device Exposures
Shane Stevens, founder and CEO of CinchOps
About the Author

Shane Stevens

Shane Stevens is the founder and CEO of CinchOps, a managed IT and cybersecurity provider for small and mid-sized businesses across the Greater Houston area, including Katy. He brings more than 35 years of IT experience, including director, VP, and CTO roles at Tidal Software, Cisco, ABB, Delinea, Digital.ai, and NinjaOne, to keeping local businesses secure, efficient, and productive.

Read Shane’s story·Connect on LinkedIn

BLOG

Latest News & Articles

January 26th, 2026
MSP Near Me
Proactive vs. Reactive IT Support: How to Tell the Difference Before You Hire an MSP

Is Your MSP Really Proactive? What Houston Small Businesses Should Ask Before Hiring Managed IT Support – If You’re Always Calling IT, Your IT Isn’t Working

June 5th, 2025
Managed IT Houston Cyberscurity
The Alarming Reality: Check Point Software Cyber Attack Report Q1 2025 Shows Nearly 50% Surge

Ransomware Growth Analysis: Q1 2025 Cyber Attack Surge – Nearly 50% Increase Demands Immediate Business Response

January 6th, 2026
MSP Near Me Houston
Role of Patch Management: Minimizing Houston Business Risks

Making Patch Management Work For Small Businesses – Your Business Is Only As Secure As Your Last Update

November 12th, 2025
Managed Service Provider Houston Cybersecurity
Microsoft’s Secure Future Initiative Update: What Houston Businesses Need to Know

The Secure Future Initiative Decoded For Local Business Owners – How Enterprise Security Principles Apply To Small Businesses

May 26th, 2026
Managed IT Houston
Managed IT Houston: The Hidden Cost of Downtime in 2026

What the Hidden Costs of Downtime Report Means for Houston Businesses – Why Prevention Beats Recovery Every Time, According to 2026 Data

Take Your IT to the Next Level!

Book A Consultation for a Free Managed IT Quote

BOOK A FREE CONSULTATION
281-269-6506
CinchOps managed IT services and cybersecurity Houston Texas
  • Home
  • Our Story
  • Reviews
  • FAQs
  • Contact
  • Sitemap
Contact info
  • 281-269-6506
  • info@cinchops.com
  • 2717 Commercial Center Blvd.
    Suite E200
    Katy, Texas, 77494

Services
  • Managed IT
  • Cybersecurity
  • Virtual CTO & CIO
  • Business Continuity & Disaster Recovery (BCDR)
  • Cloud Services
  • Business Process Automation
Service Areas
  • Brookshire
  • Cypress
  • Fulshear
  • Houston
  • Katy
  • Missouri City
  • Richmond
  • Rosenberg
  • Sealy
  • Sugar Land
  • The Woodlands
  • Tomball
©2026 CinchOps, LLC. All Rights Reserved.  | Privacy Policy