Daspren LogoDaspren
Solution
PartenairesContact
Planifiez une démo
Daspren LogoDaspren
  1. Accueil
  2. Blog
  3. Healthcare Cybersecurity Balancing Care And Security
Daspren LogoDaspren

Révolutionner la cybersécurité grâce à une technologie centrée sur les données.

1179 Av. des Champs Blancs, 35510 Cesson-Sévigné
LinkedIn

Produit

  • Solution

Cas d'utilisation

  • Cartographie
  • Classification
  • Contrôle
  • Prévention des ransomwares
  • Prévention de l'exfiltration de données
  • DSPM
  • DLP
  • Protection Zero-day

Secteurs

  • Santé
  • Finance
  • Logistique
  • Gouvernement
  • PME

Ressources

  • Blog
  • Événements
  • Glossaire

Entreprise

  • L'entreprise
  • Carrières
  • Partenaires
  • Contact
© 2026 Daspren. Tous droits réservés.
Politique de confidentialitéConditions d'utilisationPolitique de cookies
Healthcare Cybersecurity: Balancing Patient Care and Security Requirements

Healthcare Cybersecurity: Balancing Patient Care and Security Requirements

7/3/2026 • 7 min read

CybersecuritySecurity StrategyRisk ManagementArchitecture

Healthcare has been among the sectors most exposed to data breaches in France for several years. Despite the many initiatives already implemented, the constant evolution of cyber threats highlights the need to continuously maintain and adapt cybersecurity measures. Healthcare organizations continue to face attacks that can have major consequences for their operations and, in some cases, for patient care.

This situation does not reflect a lack of awareness among healthcare stakeholders. Hospital information security managers are fully aware of the risks they face. Rather, it highlights a deeper challenge: reconciling the need for continuity of care, the modernization of often outdated infrastructures, limited human resources and an ever-growing number of regulatory requirements.

Against this backdrop, collaborative projects involving public authorities, healthcare organizations and industry are being developed to explore innovative approaches to cybersecurity.


Healthcare: a prime target

In 2025, the healthcare sector accounted for nearly 10% of the incidents handled by ANSSI, making it the third most affected sector after local authorities and education. However, it remains the sector with the highest average cost of a data breach (IBM, 2025). Ransomware campaigns remain particularly prevalent in the sector, with the trend still on the rise.

Chart comparing the average cost of a data breach across industry sectors in 2025.

Unfortunately, this is not a new situation. Since 2020, the share of incidents affecting healthcare organizations has increased significantly, despite the multiplication of action plans and public initiatives.

One of the reasons lies in the value of medical data. Unlike a bank card, which can quickly be disabled after fraud, a patient record retains long-term value. It may contain administrative, medical and personal information that can be exploited for several years, making it a particularly attractive target for cybercriminals.

Healthcare organizations are no longer exposed only to their own vulnerabilities, but also to those of their entire supply chain. The two successive compromises affecting Cerballiance, involving two different service providers, illustrate this reality and show that securing the vendor ecosystem remains a major challenge.

This unfortunate attractiveness is reinforced by the operational consequences a cyberattack can have on a healthcare organization. The unavailability of an information system can quickly disrupt patient care: postponed procedures, limited access to medical records, service reorganization or transfers to other facilities. According to the French Digital Health Agency, more than one third of cyber incidents reported in the sector have a direct impact on care. This operational pressure mechanically increases attackers' leverage.

Key takeaway: Healthcare organizations are prime targets because of the high value of their data. Protection must therefore cover both internal systems and the entire digital ecosystem.


Internal risk: an issue still underestimated

Cyberattacks naturally receive significant attention in the news. Yet internal errors continue to account for a substantial share of data breaches.

Nearly 20% of the breaches reported in 2024 originated from human error (CNIL). Since the GDPR came into force, the healthcare sector has also accounted for 12% of all notifications submitted to the authority.

Although these incidents do not receive the same visibility as ransomware attacks that paralyze an organization, they are no less concerning. Poorly assigned access rights, an account that is never deactivated after an employee leaves, or inappropriate access permissions can expose sensitive data over the long term without triggering an immediate alert.

This exposure is also amplified by the day-to-day realities of healthcare organizations. The pace of work, shaped by urgency and the constant need to ensure continuity of care, can lead professionals to prioritize immediate efficiency over cybersecurity best practices.


Particularly complex information systems

Healthcare organizations face significant technical constraints. Applications must remain available at all times, biomedical equipment is often used for many years, and information systems must continuously communicate with a broad partner ecosystem.

These constraints partly explain the prolonged presence of legacy systems. In 2022, nearly 60% of hospitals were still using workstations running Windows 7.

However, these figures should not lead us to consider all difficulties as inevitable. Some are indeed linked to the specific nature of the healthcare sector and require trade-offs. Others reflect decisions made more difficult by years of underinvestment, delayed modernization projects or persistent budget constraints.


Regulatory compliance and data sovereignty: complementary challenges

The healthcare sector operates in an increasingly demanding regulatory environment. Between the GDPR, the NIS 2 Directive, the frameworks issued by the French Digital Health Agency, the CaRE program and the recommendations of ANSSI, organizations must comply with an ever-growing number of obligations.

While these frameworks have gradually helped raise cybersecurity maturity, their implementation remains complex. In many organizations, security teams with limited resources must simultaneously ensure regulatory compliance, support business projects, manage incidents, raise user awareness and oversee audits.

Beyond compliance, the protection of health data also raises an issue of digital sovereignty. The growing use of cloud services leads organizations to question their actual control over their data. Extraterritorial legislation, such as the U.S. Cloud Act, raises questions about the ability of European organizations to maintain effective control over their sensitive information.

Key takeaway: Protecting health data is not only about complying with regulatory obligations. It also requires having the necessary resources and making technology choices that preserve long-term control over data and critical infrastructures.


More innovative approaches to strengthen data protection

The core principles of cybersecurity are now well established: securing and tracing access, managing identities, controlling service providers and modernizing infrastructures. However, as threats evolve, protection can no longer rely solely on strengthening the perimeter of the information system. It must also focus on protecting the data itself, including when a compromise has already occurred.

This is the logic behind the BALISE project, led by GCS e-Santé Bretagne, winner of the national call for expressions of interest "Sécuriser les territoires" under France 2030.

Its ambition is to develop a cybersecurity demonstrator based on the marking of health data in order to better protect it, improve its traceability, detect potential leaks, block them before they leave the information system where possible, and make them easier to identify in the event of disclosure.

The project is based on a paradigm shift, placing data at the heart of the cybersecurity strategy rather than limiting protection to infrastructures.

Overview of the BALISE project developed with GCS e-Santé Bretagne to improve health data protection.

In this context, DASPREN contributes to the BALISE project by providing its expertise in sensitive data identification and mechanisms for data leak protection. Alongside the other partners, the company is helping develop a sovereign solution adapted to the constraints of healthcare organizations, combining innovation, traceability and resilience.


Conclusion

The cybersecurity difficulties faced by the healthcare sector cannot be explained by a lack of awareness or an absence of regulation.

They are primarily the result of several converging factors: complex infrastructures, limited human resources, a demanding regulatory environment and constant trade-offs between security and continuity of care.

Faced with attackers whose methods are evolving rapidly, the response can no longer be limited to adding new obligations or new tools. It requires cybersecurity to be treated as a strategic issue across the entire organization.

Today, protecting health data is inseparable from protecting patients. As such, it can no longer be considered a purely IT matter, but is now an essential component of the resilience of the healthcare system.

← Previous article
Reputation: A Fragile Asset in the Face of Cyberattacks
Next article →
Supply Chain Attacks: When Trust Becomes an Entry Point