For most hospital executives, cybersecurity lives in the IT budget. A new Fitch Ratings report argues it belongs on the balance sheet.
The August 2026 analysis draws a direct line between cyberattacks and credit quality. The hospitals at greatest risk of a breach crossing from an operational event into a ratings event are those already operating under financial stress: rural hospitals, critical access facilities and other providers with limited liquidity, thin margins and constrained capital.
The intersection of cybersecurity and credit quality had been drawing scrutiny from credit analysts for years before recent events gave the question a definitive answer.
A Ponemon Institute survey sponsored by Proofpoint found that 93% of U.S. healthcare organizations experienced at least one cyberattack in 2025, with the average number of attacks per organization climbing to 43 — a 3% year-over-year increase. Of those organizations, 72% reported a disruption in patient care as a result, up 300 basis points from the prior year.
Ray Lowe, senior vice president and CIO of AltaMed Health Services in Los Angeles, has arrived at the same conclusion from the operating side.
“Today, it’s not a matter of if you’re going to be breached,” Mr. Lowe said during a “Becker’s Healthcare Podcast” episode. “It’s going to matter of when you’re going to be breached. And when you are breached, how are you going to contain this the most localized area so it doesn’t go systemically across your organization to shut you down.”
Healthcare has held the distinction of being the most expensive sector for data breaches for 13 consecutive years, averaging $6.6 million per incident in 2026 according to IBM Ponemon data. Even where headline breach costs declined — that figure represents a 22% year-over-year drop — Fitch attributes the improvement to fewer large-scale incidents rather than any fundamental strengthening of security posture across the sector.
Healthcare organizations take an average of nine months to identify and contain a breach — roughly five-and-a-half weeks slower than the global average. That lag compounds the financial damage: the longer a system operates in disruption mode, the more billing delays, manual workaround costs and revenue cycle dysfunction accumulate. In many cases, Fitch notes, the most significant financial effects of a cyberattack emerge during recovery rather than during the attack itself.
Two recent rating actions illustrate how quickly an operational event becomes a credit event:
- Palomar Health, already contending with declining patient volumes and an unfavorable payer mix, was hit by a cyberattack that forced it to shut down parts of its network and severely disrupted billing.
- Frederick Health, facing its own operating pressure, experienced a ransomware attack that prompted an IT shutdown, closed its lab and emergency departments and required ambulance rerouting for three weeks.
Both attacks contributed to credit downgrades at institutions where financial headroom was already narrow. A cyber event did not create the underlying stress in either case, but did accelerated it.
Gerry Glombicki, senior director at Fitch Ratings, frames the sector’s structural vulnerability as being “not technology itself but the sector’s limited tolerance for disruption” — the standard of real-time availability for patient care means even brief outages carry immediate patient safety consequences, creating an environment with little tolerance for downtime. That intolerance creates a target-rich environment and limits an organization’s ability to absorb the shock of a breach the way a less time-sensitive business might.
The shift from prevention to containment is precisely what Fitch’s credit analysis rewards. Organizations with robust incident response capabilities, operational continuity plans and sufficient financial flexibility are best positioned to absorb a breach without triggering a ratings action. Even as cybersecurity spending rises across the sector, rural and critical access hospitals face competing capital priorities, workforce shortages and aging technology infrastructure that already constrain security investment — leaving them most exposed when a breach hits.
The threat environment is also accelerating faster than most organizations can match. Mr. Lowe described a patch management landscape that has changed fundamentally in both volume and pace.
“Patch management is a very simple thing. Everybody does it. We usually do it once a week. Have our change boards and maybe do three or four,” he said. “Now the orders are going to be 10, 20, 30 from the vendors, because the environment is so dynamic. With the acceleration tied to the AI enablement, everything is moving so fast.”
HHS has proposed significant updates to the HIPAA Security Rule in response, including mandatory encryption, multi-factor authentication, network segmentation, annual penetration testing and a 72-hour restoration requirement. The agency estimates the proposed changes would cost the sector $33 billion over five years. But Fitch’s analysis is careful to separate compliance from resilience. Regulatory requirements establish a floor. Whether an organization can absorb a breach without rating pressure depends on what it has built above that floor — and on whether the financial cushion exists to survive the recovery period.
“There’s always tech debt,” Mr. Lowe said. “We need to be aware of what’s in our app stack, where our problems can be, and we have to take an active role saying how do we solve that problem. We can’t ignore it.”
At the Becker's 11th Annual IT + Revenue Cycle Conference: The Future of AI & Digital Health, taking place September 14–17 in Chicago, healthcare executives and digital leaders from across the country will come together to explore how AI, interoperability, cybersecurity, and revenue cycle innovation are transforming care delivery, strengthening financial performance, and driving the next era of digital health. Apply for complimentary registration now.