Your Medical Records Are for Sale. And Nobody Is Stopping It.
190 million Americans in one attack. 1.8 million fingerprints stolen in New York. A ransomware gang that locked up hospitals across three…
Your Medical Records Are for Sale. And Nobody Is Stopping It.
190 million Americans in one attack. 1.8 million fingerprints stolen in New York. A ransomware gang that locked up hospitals across three states. This is the healthcare data breach crisis — and it’s getting worse every year.

Your Medical Records Are for Sale. And Nobody Is Stopping It.
Somewhere on the dark web right now, your medical records may be for sale.
Not your credit card number — that’s worth about $10 to a cybercriminal. Your medical records: your diagnoses, your medications, your Social Security number, your insurance details, your billing history, the names of your doctors, your test results. A complete medical profile sells for $260 to $310 on dark web marketplaces — roughly 10 to 30 times the value of a stolen credit card.
And unlike a credit card, you can’t cancel your medical history.
The healthcare industry has become the single most targeted sector in the world for ransomware and data theft. In 2024 alone, 276 million Americans — four out of every five people in the country — had their health data exposed in breaches. The year before that set a record. The year before that set a record. The industry has held the top spot for the most expensive data breaches for 14 consecutive years, and the gap between healthcare and every other industry is widening.
This is not a technology story. It is a crisis with real consequences: delayed surgeries, cancelled prescriptions, diverted ambulances, patients unable to receive care — and hundreds of millions of people whose most intimate personal information is now in the hands of criminal organizations they will never be able to stop.
Here is what is actually happening.
The Largest Healthcare Breach in Human History: Change Healthcare
190 million Americans. One missing password. Nine days of undetected theft.
On February 21, 2024, an employee at Change Healthcare — a company most Americans had never heard of, but whose systems quietly processed roughly 40% of all U.S. medical claims — received what appeared to be a routine login request.
It was not routine.
Attackers affiliated with the ALPHV/BlackCat ransomware group had obtained valid credentials from a dark web marketplace — likely stolen months earlier by a separate piece of malware. They used those credentials to log into Change Healthcare’s remote access Citrix portal.
The portal had no multi-factor authentication.
For the next nine days, the attackers moved silently through the network. They mapped the systems. They identified the data. And then they exfiltrated it — approximately 6 terabytes of protected health information: medical records, insurance details, billing data, Social Security numbers, and payment information for an estimated 192.7 million Americans.
On day nine, they deployed ransomware. Change Healthcare’s systems went dark.
The impact was immediate and catastrophic. Pharmacy chains across the country couldn’t process prescriptions. Hospitals couldn’t submit insurance claims. Doctors couldn’t verify patient coverage. Roughly 70% of U.S. pharmacies and 40% of U.S. hospitals lost access to critical payment and administrative systems — some for weeks.
UnitedHealth Group, Change Healthcare’s parent company, ultimately paid the ransom. Then a second extortion group surfaced, claiming they also had copies of the stolen data. UnitedHealth paid again.
The final cost to UnitedHealth: $2.457 billion in direct breach-related costs by Q3 2024 alone — in addition to the ransom payments, the operational losses, and the class action litigation that followed.
The root cause? A single Citrix portal that lacked the most basic authentication requirement in modern cybersecurity.
What it means for you: Your healthcare data doesn’t just live with your doctor. It flows through dozens of intermediaries — claims processors, billing companies, insurance clearinghouses — many of which you’ve never heard of, none of which you consented to, and most of which you have no way to monitor. One breach of one intermediary can expose data from millions of providers and hundreds of millions of patients simultaneously.
NYC Health + Hospitals: 1.8 Million Fingerprints Stolen While Nobody Was Looking
The breach that broke in May 2026 — and the data stolen includes biometrics you cannot change.
Just days ago, New York City’s public hospital network — NYC Health + Hospitals, the largest public health system in the United States — disclosed the details of a data breach that affects at least 1.8 million people.
The attackers didn’t break into NYC Health + Hospitals directly. They breached a third-party vendor that had access to the hospital network’s systems. Once inside through that back door, they had access from approximately late November 2025 through February 2, 2026 — roughly ten weeks of undetected access — during which they systematically copied files.
What was in those files is deeply alarming: patient names, health insurance details, medical information including diagnoses, medications, and test imagery, billing and payment records, government-issued IDs, geolocation data — and, most disturbingly, fingerprint and palm-print biometric data.
You can cancel a credit card. You can change a password. You cannot change your fingerprints.
NYC Health + Hospitals serves primarily uninsured patients and those on Medicaid — among the most financially vulnerable populations in the country. These are not people with resources to monitor their identities, contest fraudulent claims, or navigate the aftermath of medical identity theft. The system is now offering 24 months of credit monitoring through Kroll, which is the standard response to a breach — and which, for 1.8 million people whose fingerprints are now in criminal hands, is an almost insulting gesture.
The questions that remain unanswered as of this writing: Why did it take three months for the hospital system to detect the breach? Who was the unnamed third-party vendor? Has a ransom been demanded or paid?
What it means for you: The weakest link in healthcare cybersecurity is almost never the hospital itself. It is the vendor ecosystem — the billing companies, IT providers, scheduling platforms, and data analytics firms with access to hospital systems — that creates the attack surface. Every third-party vendor connection is a potential entry point, and most healthcare organizations have dozens of them.
Yale New Haven Health: 5.5 Million Records Gone in a Day
Connecticut’s largest health system — and an $18 million settlement that won’t bring the data back.
On March 8, 2025, Yale New Haven Health System — Connecticut’s largest, operating five acute care hospitals and over 360 outpatient locations — identified unusual activity on its network. An investigation confirmed what IT security teams most dread: an unauthorized party had gained access and copied patient data before anyone noticed.
The breach affected 5,556,702 patients — the largest healthcare breach reported to federal regulators in all of 2025. The stolen data includes names, dates of birth, addresses, phone numbers, email addresses, race and ethnicity, Social Security numbers, and medical record numbers.
Class action lawsuits arrived almost immediately. At least five federal cases were filed against Yale New Haven Health alleging negligence in protecting patient data. The health system settled for $18 million — which, divided among 5.5 million affected patients, amounts to roughly $3.27 per person whose private information was stolen.
The attackers have never been identified. No ransomware group claimed responsibility. The health system declined to say whether a ransom was demanded or paid.
What it means for you: Even the most prestigious academic medical centers with substantial resources are being successfully breached. Sophistication and reputation provide no protection. And $18 million sounds significant until you realize it represents a fraction of the harm inflicted — and that no settlement can un-steal Social Security numbers that are now in criminal hands.
The Scale of the Crisis: By the Numbers
These three breaches are not outliers. They are the visible peaks of a systemic crisis that gets worse every year.
2024 — The worst year in healthcare breach history:
- 276 million patient records compromised — a 64% increase from the previous record year
- That is four out of five Americans who had health data exposed in a single calendar year
- 592 regulatory filings of reported healthcare hacks to HHS
- Average cost per breach: $9.8 million — more than double the financial sector, 2.5 times the cross-industry average
- Healthcare held the top spot for breach costs for 14 consecutive years
2025 — The industrialization of healthcare cybercrime:
- 605 total breaches reported to HHS, affecting 44.3 million Americans
- Healthcare was the most targeted critical infrastructure sector for ransomware, with 460 ransomware incidents
- Average breach detection time: 241 days — meaning attackers spend eight months inside a system before anyone notices
- Average cost per breach rose to $10.93 million per incident
2026 — It continues:
- NYC Health + Hospitals: 1.8 million (May 2026)
- The Conduent breach: potentially one of the top three largest healthcare breaches ever, affecting 25 million in Oregon and Texas alone — with final numbers still climbing
Why Healthcare? The Four Reasons Criminals Won’t Stop
Healthcare is not just targeted opportunistically. It is specifically and deliberately hunted. Four structural factors make it uniquely profitable.
1. The data never expires. A stolen credit card is cancelled within hours. A stolen Social Security number attached to a complete medical record — including diagnoses, medications, insurance policy numbers, and billing details — is permanent. It can be used for medical identity fraud, insurance fraud, prescription drug fraud, and financial identity theft, potentially for decades. Criminals don’t need to rush. The data stays valuable.
2. Hospitals cannot afford to go offline. A ransomware attack on a retail company creates inconvenience. A ransomware attack on a hospital can kill people. Surgeries are postponed. Ambulances are diverted. Medication records are inaccessible. ICU patients lose monitoring. The operational urgency is so extreme that hospitals face enormous pressure to pay ransoms immediately — making healthcare the most reliably profitable ransomware target on earth. Criminals know this.
3. The technology is ancient. Medical devices with 10 to 15-year operational lifespans run software that hasn’t been updated in a decade. Legacy systems from the 1990s and early 2000s operate alongside modern platforms, connected by integrations that were never designed with security in mind. Most healthcare organizations have hundreds of third-party vendor connections, each representing a potential entry point. The attack surface is enormous and poorly defended.
4. Security investment has been chronically underfunded. Healthcare organizations typically allocate 4 to 7% of their IT budgets to cybersecurity. Financial services firms, facing similar data sensitivity, allocate 10 to 15%. The gap between the value of the data being protected and the investment in protecting it is precisely what criminals are exploiting.
What Happens to the Stolen Data
When cybercriminals steal healthcare records, the data doesn’t disappear. It enters a sophisticated criminal economy.
Complete medical records sell for $260 to $310 each on dark web marketplaces — making a breach of 1.8 million records potentially worth over $550 million to criminal buyers. Medical data is valuable for several distinct criminal use cases:
Medical identity fraud: Criminals use stolen insurance details to submit fraudulent claims for procedures, equipment, and prescriptions that are then fenced or sold. Victims discover the fraud when their legitimate claims are denied because their coverage has been exhausted — sometimes years later.
Prescription drug fraud: Stolen medical records enable criminals to obtain prescriptions for controlled substances using a victim’s identity and insurance. Victims learn of this when they are unexpectedly denied medication they actually need.
Financial identity theft: A complete medical profile — containing Social Security number, date of birth, address, insurance numbers, and billing history — provides everything needed to open fraudulent credit accounts, file false tax returns, and commit financial fraud.
Blackmail: Highly sensitive diagnoses — HIV status, mental health conditions, substance abuse treatment, reproductive health history — represent potential blackmail material, particularly for high-profile individuals.
The victims in most of these cases don’t discover the fraud for months or years. By then, the damage is done. The $3.27 settlement check from a class action lawsuit doesn’t come close to covering it.
The Response Gap: Why Nothing Is Being Fixed
The crisis has been building for over a decade. The patterns of failure are consistent and well-documented. And yet the same failures repeat, year after year, breach after breach.
The regulatory framework is inadequate. HIPAA, the primary U.S. healthcare data protection law, does not require multi-factor authentication. The Change Healthcare attack — which exposed 192.7 million Americans — was enabled entirely by a portal with no MFA. This is not a niche technical finding. It is a basic security control that has been standard practice in every other sensitive data industry for years. HIPAA doesn’t mandate it.
The incentives are misaligned. When a hospital is breached, the immediate cost is paid by regulators, class action settlements, and notification expenses. The long-term cost is borne by patients — through identity fraud, compromised medical records, and privacy violations. The people who pay the price are not the people making the security investment decisions.
The vendor ecosystem is uncontrolled. The Change Healthcare breach didn’t start with a hospital. It started with a clearinghouse. The NYC Health + Hospitals breach didn’t start with the hospital. It started with a vendor. Healthcare cybersecurity is only as strong as the weakest link in an ecosystem of dozens of third parties — and most healthcare organizations have limited visibility into how those vendors protect data.
Breach detection is catastrophically slow. The average time from initial breach to detection in healthcare is 241 days. That is eight months during which attackers have complete access to systems containing the most sensitive data in existence. By the time an organization discovers it has been breached, the data has already been sold, the ransom has already been demanded, and the damage is already done.
The Human Cost Nobody Accounts For
Every data breach statistic represents a real person.
It is the cancer patient whose diagnosis is now permanently attached to a stolen identity circulating on criminal forums. It is the mental health patient whose psychiatric history was contained in a file that has now been sold. It is the Medicaid recipient — already among the most vulnerable people in the country — who will spend years untangling fraudulent medical claims filed in their name.
It is the patient whose surgery was postponed because the hospital’s systems were locked by ransomware. It is the person whose prescription couldn’t be filled because the pharmacy couldn’t process insurance verification. In 2025, PIH Health Hospitals in California was hit by ransomware that left over 3 million patients unable to access healthcare services. Medical records were inaccessible. Surgeries were postponed. Emergency rooms diverted patients to other facilities.
These are not abstract data losses. They are direct harms to real people — and the current regulatory and legal framework treats them as acceptable costs of doing business in digital healthcare.
What Needs to Change
Security experts, regulators, and researchers are aligned on what is required. The industry has not delivered it.
Mandatory multi-factor authentication for all remote access to healthcare systems is the single most impactful change that could be made today. It would have prevented Change Healthcare. It would have raised the barrier significantly against the NYC Health + Hospitals breach. HIPAA should require it. Currently, it does not.
Third-party vendor security standards with mandatory verification, continuous monitoring, and contractual liability for breaches originating from vendor access. Healthcare organizations cannot secure their patients’ data if they have no visibility or control over how their dozens of vendors protect it.
Breach detection investment to close the 241-day gap between breach and discovery. Eight months of undetected access is not a technology problem — it is a priority and investment problem. Continuous monitoring, behavioral detection, and network segmentation can dramatically reduce dwell time.
Real regulatory enforcement with penalties that reflect the actual harm caused to patients — not symbolic fines that represent a fraction of a breach’s economic impact. When the consequence of failing to secure 190 million people’s medical records is a regulatory process and a class action settlement that amounts to dollars per victim, the incentive to invest in prevention is insufficient.
The Bottom Line
In 2024, four out of five Americans had their health data exposed. In one attack — one company, one portal, one missing password — 192.7 million people had their most intimate information stolen by a criminal organization.
In May 2026, the largest public hospital system in the United States disclosed that hackers had been inside its network for three months, walking out with the fingerprints of 1.8 million people.
The healthcare data breach crisis is not a series of isolated incidents. It is a systemic failure: of regulation that hasn’t kept pace with the threat, of investment that has chronically underestimated the risk, of a vendor ecosystem with no accountability, and of an industry whose most fundamental asset — patient trust — is being sold on the dark web for $300 a record.
The data that should be most protected in society — the record of your illnesses, your treatments, your most private biological and psychological history — is the data that is most consistently, most profitably, and most irreversibly stolen.
And until the incentives, the regulations, and the investment change, it will keep happening.
Sources: HHS Office for Civil Rights Breach Portal · TechCrunch (NYC Health + Hospitals breach, May 2026) · Malwarebytes (NYC Health + Hospitals analysis, May 2026) · HIPAA Journal (Change Healthcare final breach count; Yale New Haven Health settlement; 2024 and 2025 breach reports) · The HIPAA Guide (Change Healthcare timeline) · BleepingComputer (Yale New Haven Health breach) · IBM Security Cost of a Data Breach Report 2024 · Patient Protect (Healthcare breach statistics 2025–2026) · FBI Internet Crime Complaint Center Annual Report 2024 and 2025 · IECC Annual Cybersecurity Healthcare Report · Security Boulevard (healthcare ransomware analysis) · Cloudskope (Change Healthcare breach timeline) · Security Magazine (Top 20 Healthcare Breaches 2025) · Nebraska Attorney General v. Change Healthcare et al.
If this resonated, follow for more on data privacy, healthcare policy, and the systems that are supposed to protect you.
메타데이터
- post_id
- 59b0abe074e3
- slug
- your-medical-records-are-for-sale-and-nobody-is-stopping-it-59b0abe074e3
- url
- https://medium.com/@tanvir.infosec/your-medical-records-are-for-sale-and-nobody-is-stopping-it-59b0abe074e3
- canonical_url
- https://medium.com/@tanvir.infosec/your-medical-records-are-for-sale-and-nobody-is-stopping-it-59b0abe074e3
- author_url
- https://medium.com/@tanvir.infosec
- status
- ok
- fetched_at
- 2026-06-09 15:37:30