A Quiet Shift In Security Every Healthcare Compliance Team Should Read

Updated: October 6th, 2026
4 mins read
shift in healthcare security

Change Healthcare took down a third of US claims processing. Ascension spent weeks on the papers. OCR settlements keep citing “risk analysis failure,” and HITRUST r2 assessors are asking harder questions about what actually got tested versus what got scanned.

The math on pentesting shifted in the middle of all that.

In 2024, 1 in 40 findings was Critical. In 2025, it’s 1 in 10. The same scans, testers, and reporting formats, yet a 300% jump in the share of findings that need immediate intervention rather than waiting until the end of the quarter.

That ratio comes out of Astra’s latest State of Pentesting report, built on 6.8 million findings across 8,000+ engagements in 70 countries. For a healthcare compliance team walking into a 2026 HITRUST cycle or a HIPAA risk analysis refresh, it’s the stat that should reshape the year. As you already know, PHI environments don’t get graded on total findings closed. They get graded on whether the Critical ones were identified, patched, and evidenced before an assessor or an attacker gets there first.

Here’s why it matters, in the language of numbers your auditor already speaks.

Critical findings are outpacing everything else.

Critical vulnerabilities grew 14.6x faster than the other severity buckets last year. If your program still tracks “total vulnerabilities closed” as its health metric, you’re watching the wrong dial. The total might look flat or even improve. The Critical share underneath it is what the OCR letter will eventually ask about. A compliance dashboard that averages severity away is doing a very good job of hiding the thing you needed to see.

The metric change is a one-line rule away. The practical change is simple: make severity-weighted risk visible in the same place you already track controls, evidence, and remediation.

Cloud went from a side scope to the main quest.

Cloud findings in 2024 were 60,000 and in 2025 jumped up to  2.6 million. Cloud testing coverage in the same period grew 1.23x. The findings grew 43x.

Cloud pentests surface 2.4x more findings per engagement than web pentests. Most healthcare workloads that used to live in a hospital data center now sit in AWS, Azure, or a specialty EHR host. If the scope you signed off on last audit still treats cloud as the paragraph after the web app section, the gap between what’s tested and what’s exposed has widened without anyone updating a control.

This is the part most compliance calendars quietly get wrong. Patient-facing web portals get the deep pentest slot because that’s where the checklist points. The cloud environment holding the actual PHI gets a scanner and a screenshot.

Business logic is still where humans beat tools.

IDOR (insecure direct object references) showed up across all six attack surfaces analyzed: web, API, cloud, iOS, Android, and network. In healthcare, IDOR is the bug that lets patient A pull patient B’s chart by changing a number in the URL. A scanner can technically flag it and rarely catches it in context, because “user 42 can see user 43’s record” only makes sense to someone who understands what a record means in your product.

Frameworks can’t prescribe this. That’s the entire reason the pentest requirement exists inside HIPAA’s Security Rule risk analysis, HITRUST, and SOC 2. The framework knows there’s a category of risk that only a person poking at your product will find. The stats just confirmed the framework was right.

What this means for a 2026 healthcare compliance calendar

Compliance and pentesting get easier to run together when the numbers agree on what “important” means. A few concrete moves the data supports:

  • Re-scope cloud before the next pentest cycle. Start with wherever PHI actually sits now, not where it sat at the last audit.
  • Change the metric from “open findings” to “Critical open findings, aged.” Most compliance and security platforms can support this view. The bigger question is whether teams are using it.
  • Book retest windows into the HITRUST or SOC 2 calendar the same way you book assessor fieldwork. A pentest without a retest is a photograph, not a program, and OCR has stopped accepting photographs.
  • Reserve manual pentest hours for the surfaces where humans still beat tools: business logic, access control on patient records, chained API abuse between EHR and third-party apps. Let scanners handle the surface layer.

Back to that one stat

1 in 40 became 1 in 10.

If nothing else from the report lands, that ratio should. It’s the reason a healthcare compliance program that felt tight in 2024, right through the Change Healthcare fallout, can quietly drift out of shape in 2026 without a single control failing. The controls are fine. The threat mix underneath them moved.

The full State of Pentesting report has the rest of the numbers, including remediation timelines by severity, framework patterns, and how AI features are changing what testers find.