• Skip to main content
  • Skip to secondary menu
  • Skip to primary sidebar
  • Skip to secondary sidebar
  • Skip to footer

ecw Leaderboard Ad
  • Opinion
  • Health IT
    • Behavioral Health
    • Care Coordination
    • EMR/EHR
    • Interoperability
    • Patient Engagement
    • Population Health Management
    • Revenue Cycle Management
    • Social Determinants of Health
  • Digital Health
    • AI
    • Blockchain
    • Precision Medicine
    • Telehealth
    • Wearables
  • Life Sciences
  • Investments
  • M&A
  • Value-based Care
    • Accountable Care (ACOs)
    • Medicare Advantage

Hospital Cybersecurity Trends 2026: Top IoMT Challenges, Statistics, and Risk Management Strategies

by Fred Pennic 12/18/2025 Leave a Comment

  • LinkedIn
  • Twitter
  • Facebook
  • Email
  • Print

What You Should Know: 

A new report from Asimily reveals that despite the explosion of connected care, hospitals are flying blind.

–  A survey of North American CISOs found that 43% list “complete device visibility” as their most urgent unsolved challenge, while one-third blame internal process breakdowns for their inability to secure medical devices. With the average hospital now managing 350,000 connected devices, the industry is struggling to move from reactive patching to proactive risk management.


Modern healthcare is a miracle of connectivity. From infusion pumps to MRI machines, the “Internet of Medical Things” (IoMT) has revolutionized patient care. But according to a new report released today by risk mitigation platform Asimily, this connectivity has outpaced the security infrastructure meant to protect it.

The report, “The State of Hospitals’ Cyber Asset Exposure Management in 2025,” paints a concerning picture of the healthcare security landscape. Despite 93% of healthcare organizations experiencing cyberattacks in the last year, hospital CISOs remain hamstrung by a fundamental problem: they cannot protect what they cannot see.

The Visibility Crisis

The sheer scale of the problem is daunting. The average hospital now houses between 10 and 15 connected medical devices per bed, totaling upwards of 350,000 IoMT devices for a single facility. Yet, the survey indicates that 43% of CISOs identify “complete device visibility” as the challenge they want to solve first—far outranking ransomware detection (24%) and compliance (22%).

“Visibility should be table stakes for security professionals,” the report notes, but the reality is that clinical engineering teams often deploy new devices without notifying IT. This creates “shadow IT” on a massive scale, where lethal medical equipment sits on the network completely unmonitored.

It’s Not Just Tech—It’s Process

Perhaps the most revealing finding is that the biggest barrier to security isn’t hackers, but bureaucracy. When asked about the biggest hurdle to effective risk management, 33% of respondents cited “internal process issues,” making it the top complaint.

The report highlights a dangerous lack of ownership. In many hospitals, responsibility for medical devices is fractured between Clinical Engineering, Health Technology Management (HTM), and IT Security.

  • The Disconnect: Technicians may patch a device or change its configuration without informing security, leading to “configuration drift” that opens new vulnerabilities.
  • The Result: Security teams often find out about a new device only after it has been compromised.

The “Prioritization” Trap

Even when security teams do see a vulnerability, they are often paralyzed by the volume of alerts. With hundreds of thousands of devices, patching everything is impossible.

The data shows that hospitals are failing to prioritize effectively. Only 22% of CISOs prioritize remediation based on device criticality and usage—the gold standard for hospital security.

  • 18% still rely on manual review, a virtually impossible task given the scale.
  • 15% admit to having “no clear process” for addressing IoMT vulnerabilities.
  • 22% rely solely on vendor alerts, which often lag behind active threats.

“A critical CVSS score may actually have no impact in a particular network if vulnerable systems are segmented,” the report argues, suggesting that teams relying on generic scores are wasting resources on low-risk issues while high-risk devices remain exposed.

The Path Forward: From Panic to Strategy

Asimily’s findings suggest that the solution requires a cultural shift as much as a technical one. The report recommends that hospitals move away from “chasing patches” toward a holistic exposure management strategy.

This involves unifying visibility across IT, IoT, and OT devices to eliminate blind spots. But crucially, it requires establishing clear ownership channels between clinical engineering and security teams to ensure that when a device enters the building, it enters the security perimeter.

With cyberattacks costing healthcare organizations an average of $3.9 million per incident, the cost of remaining blind is no longer sustainable. As 2026 approaches, the hospitals that succeed will be those that finally bridge the gap between “medical equipment” and “cyber asset.”

  • LinkedIn
  • Twitter
  • Facebook
  • Email
  • Print

Tap Native

Get in-depth healthcare technology analysis and commentary delivered straight to your email weekly

Reader Interactions

Primary Sidebar

Subscribe to HIT Consultant

Latest insightful articles delivered straight to your inbox weekly.

Submit a Tip or Pitch

Featured Interview

CliniComp SVP Talks New Era EHR: How AI-Driven, Interoperable Platforms Are Replacing Legacy Health IT Systems

Most-Read

GE HealthCare Acquires Intelerad for $2.3B to Create Cloud-First, AI-Enabled Imaging Ecosystem

GE HealthCare Acquires Intelerad for $2.3B to Create Cloud-First, AI-Enabled Imaging Ecosystem

Humana Partners with Sunrise to Expand Digital Sleep Apnea Diagnostics

Humana and Epic Launch Coverage Finder to Deliver Digital-First Medicare Advantage Check-In

Cleveland Clinic and Khosla Ventures Form Strategic Alliance to Accelerate Healthcare Innovation

Cleveland Clinic and Khosla Ventures Form Strategic Alliance to Accelerate Healthcare Innovation

Northwell Health Selects to Deploy Abridge’s Ambient AI Across 28 Hospitals

Northwell Health to Deploy Abridge’s Ambient AI Across 28 Hospitals

Omada Health Launches "Nutritional Intelligence" with AI Agent OmadaSpark

Omada Health Launches AI-Powered Meal Map to Transform Nutrition for Cardiometabolic Patients

From Overwhelmed to Optimized: How AI Agents Address Staffing Challenges and Burnout in Healthcare

From Overwhelmed to Optimized: How AI Agents Address Staffing Challenges and Burnout in Healthcare

Qualtrics Acquires Press Ganey Forsta for $6.75B to Create the Most Comprehensive AI Experience Platform

Qualtrics Acquires Press Ganey Forsta for $6.75B to Create the Most Comprehensive AI Experience Platform

Pfizer and Trump Administration Announce Landmark Agreement to Lower Drug Costs

Pfizer and Trump Administration Announce Landmark Agreement to Lower Drug Costs

KLAS Report: Epic's Native Ambient Speech Tool Reshapes Customer AI Strategies

KLAS Report: Epic’s Native Ambient Speech Tool Reshapes Customer AI Strategies

Epic Unveils MyChart Central and New APIs to Advance Interoperability at Open@Epic

Epic Outlines Roadmap for Next-Generation Data Sharing at Open@Epic

Secondary Sidebar

Footer

Company

  • About Us
  • Advertise with Us
  • Reprints and Permissions
  • Op-Ed Submission Guidelines
  • Contact
  • Subscribe

Editorial Coverage

  • Opinion
  • Health IT
    • Care Coordination
    • EMR/EHR
    • Interoperability
    • Population Health Management
    • Revenue Cycle Management
  • Digital Health
    • Artificial Intelligence
    • Blockchain Tech
    • Precision Medicine
    • Telehealth
    • Wearables
  • Startups
  • Value-Based Care
    • Accountable Care
    • Medicare Advantage

Connect

Subscribe to HIT Consultant Media

Latest insightful articles delivered straight to your inbox weekly

Copyright © 2025. HIT Consultant Media. All Rights Reserved. Privacy Policy |