Digital Exposure In Healthcare Environments: The Blind Spot Between Legacy Records, Medical Devices, And The Laboratory Chain

Digital Exposure In Healthcare Environments: The Blind Spot Between Legacy Records, Medical Devices, And The Laboratory Chain

From a digital infrastructure standpoint, a hospital is not a single, cohesive environment. It is a technological patchwork: electronic health record systems deployed over a decade ago, medical equipment connected to the network for remote monitoring, integrations with outsourced laboratories, telemedicine platforms, and connections to health insurance providers for billing and procedure authorization.

Each of these pieces was added at a different time, by a different vendor, following a different security standard. And at most healthcare institutions, no single area today has a centralized, up to date inventory of all of it. The result is an exposure surface that grows continuously, in a sector where a security failure does not just mean a data leak, it can mean a real time disruption of patient care.

A Sector That Deals With Lives, But Operates With Fragmented Infrastructure

The digitization of healthcare brought real gains in speed and precision: electronic health records, telemedicine, interconnected hospital systems. But this modernization opened a door that many institutions never properly closed. As systems become increasingly connected to the internet, exposure to cyberattacks grows along with it, and medical data has stopped being just confidential documents and become valuable digital assets, coveted by criminals who see these records as a source of profit and leverage for extortion.

The volume of incidents reflects this exposure. In the first half of 2025, the Brazilian healthcare sector recorded 11,426 security breaches across its systems, and although not all turned into direct attacks, 97% were considered real, with about 20% classified as high severity. The analysis points to a growing risk scenario driven by the combination of increasingly connected hospital infrastructure and insufficient digital protections.

Legacy Systems: Yesterday's Technology Protecting Today's Data

One of the most persistent blind spots in healthcare environments is the continued operation of legacy systems, often running on software versions that no longer receive any security updates. It is not uncommon for critical diagnostic equipment to depend on obsolete operating systems to function, simply because replacing the software would mean replacing the entire equipment, a cost few institutions can absorb quickly.

This problem is not hypothetical. The best known case in Brazil involved the Barretos Cancer Hospital, hit by a variant of the Petya ransomware that spread globally by exploiting exactly this type of vulnerability in outdated Windows systems. The attack hijacked access to data on infected machines, demanding a bitcoin ransom to release the information.

The exposure is not limited to old software running without support. Medical imaging systems that use the DICOM protocol (used to store and transmit exams such as CT scans and MRIs) frequently end up directly accessible over the internet, without the institution itself even noticing. A Kaspersky analysis identified Brazil as the fourth country in the world with the most publicly exposed and accessible DICOM devices, including cases where real patients' imaging exam results appeared available online, with no authentication barrier at all.

Connected Medical Devices: When The Network Becomes Part Of The Treatment

Infusion pumps, vital sign monitors, ventilators, and medical imaging servers (PACS) have stopped being isolated equipment and now operate as interconnected devices on the hospital network. This connectivity is what enables remote monitoring and data integration across departments, but it also turns each of these devices into a potential entry point.

Equipment such as infusion pumps, vital sign monitors, ventilators, and PACS servers, essential to hospital operations, ends up becoming an accessible target for criminals even without advanced technical skills, since simply using public search tools like Shodan is enough to locate devices directly exposed to the internet.

The impact of an attack affecting these devices goes far beyond a conventional IT incident. In a panel held during the Healthcare Innovation Show 2025, security executives from major Brazilian healthcare institutions openly discussed this dimension of the problem. Hospitals hit by ransomware see a 30% increase in mortality, according to data cited at the event, with cases where connected medical devices became unavailable during the attack, directly compromising monitoring and medication administration for hospitalized patients. The risk of an infusion pump or a vital sign monitoring panel being exposed to the internet does not come down to an attacker simply switching the device off remotely. The bigger danger lies in the fact that these devices share the same internal network as other critical hospital systems. Once a cybercriminal gains initial access by exploiting that vulnerable device, they use it as a "pivot" to move laterally, quietly navigating the internal network until reaching the central patient records server or the hospital's financial system.

When The Weakest Link Is The Outsourced Laboratory

Hospitals and clinics do not operate in isolation: they depend on an extensive network of partner laboratories, management software vendors, and telemedicine platforms to run day to day. Each of these connections also represents an extension of the main institution's exposure surface, even when the attack does not happen directly on its own systems.

In September 2025, the ransomware group KillSec claimed responsibility for an attack against MedicSolution, a provider of management software used by dozens of medical institutions for scheduling, exam storage, and cloud based medical records. Criminals obtained more than 34 GB of data, totaling nearly 95,000 files, including lab tests, medical assessments, x-rays, and unedited patient images, some belonging to minors. The investigation identified leaked files belonging to distinct laboratories and clinics that used the same third party platform.

This pattern of attacking the technology vendor chain is particularly dangerous precisely because it allows multiple organizations to be hit simultaneously, exploiting the trust each institution places in its vendors, without those institutions having any direct visibility into the real security posture of those partners.

When The Attack Hits Public Health Infrastructure

Exposure is not limited to private hospitals. In December 2021, systems belonging to Brazil's Ministry of Health, including ConecteSUS, responsible for issuing the National Covid-19 Vaccination Certificate, and e-SUS Notifica, used for reporting flu-like syndrome, were compromised in an attack claimed by the Lapsus$ group. The attackers left messages stating that 50 TB of data had been copied and deleted, classifying the attack as ransomware. ConecteSUS was down for days, temporarily leaving millions of Brazilians without access to their own vaccination records, in the middle of managing an ongoing pandemic.

The episode illustrates how digital exposure in healthcare does not affect only the attacked institution: it can compromise the entire population's access to essential services, with effects that extend far beyond the technical environment where the incident began.

Why Health Data Is Such A Valuable Target

Unlike a credit card number, which can be canceled and replaced within minutes, a medical record contains permanent information: diagnoses, treatment history, genetic conditions, family information. Medical records can be worth up to 50 times more than banking data on the criminal market, precisely because they enable long term fraud, such as fake health insurance reimbursements, purchases of controlled medications, creation of fictitious identities, and even direct extortion based on confidential diagnoses.

This high value also fuels a more recent pattern identified in attacks on the sector: the public disclosure of leaks as a deliberate emotional and reputational extortion tactic, pressuring institutions to pay ransoms not just to keep operations running, but out of fear of the public exposure of their patients' sensitive clinical data.

The Problem Is Rarely A Lack Of Technology, It's A Lack Of Inventory

Practically none of the cases described above began with a sophisticated, unprecedented flaw. They began with outdated systems nobody migrated, connected medical equipment nobody knew was accessible over the internet, or third party vendors whose security posture the contracting institution never monitored continuously.

The common thread across these scenarios is the absence of a centralized, up to date inventory of the institution's own exposure surface. Unlike a conventional corporate network, a healthcare environment combines traditional IT, biomedical equipment, third party integrations, and legacy infrastructure into a single ecosystem, and most institutions do not have a unified view of which part of that ecosystem is, at this very moment, accessible over the internet, vulnerable to a known flaw, or connected to a vendor whose security has never been verified.

Best Practices To Reduce Exposure In Healthcare Environments

Continuously map every connected asset, not just traditional IT systems. Medical equipment, imaging servers, and building automation systems are also part of the attack surface and are rarely included in conventional IT inventories.

Treat legacy systems as a permanent risk, not a temporary exception. When fully replacing a piece of equipment is not feasible in the short term, network isolation, segmentation, and compensating monitoring are essential while migration has not yet happened.

Audit the security posture of laboratories, software vendors, and third party platforms with the same seriousness applied to internal systems. As the MedicSolution case shows, a single compromised vendor can expose data from multiple institutions simultaneously.

Proactively monitor exposure of internet connected devices. Equipment discovered through public tools like Shodan represents a real, detectable risk before exploitation, not just after it.

Have a specific care continuity plan for system unavailability scenarios. In healthcare, incident response cannot be limited to data recovery, it needs to ensure patient care continues even with compromised systems.

Treat cybersecurity as part of patient safety, not just an IT issue. The increase in mortality associated with ransomware attacks on hospitals, cited by sector experts, makes clear that digital exposure in healthcare has direct clinical consequences, not just operational or reputational ones.

How QuimeraX Operates In This Landscape

QuimeraX's EASM (External Attack Surface Management) module was designed to solve exactly the core problem described in this article: the absence of a centralized inventory in technologically fragmented environments. Through continuous asset discovery, Asset Hunter identifies exposed systems, subdomains, and services that were never formally documented, including legacy environments and forgotten integrations, while the Assets module maps exposed ports and internet accessible devices, the same type of exposure that tools like Shodan reveal to anyone with malicious intent.

For risk that originates outside the institution's direct perimeter, as shown by the MedicSolution case, the TPCRM (Third Party Cyber Risk Management) module continuously monitors the exposure of partner laboratories and software vendors, while CTI (Cyber Threat Intelligence) identifies leaked credentials and mentions of threats targeting the healthcare sector before they become public incidents.

The differentiator lies in turning the fragmented complexity of a hospital environment, normally its biggest risk, into a single, continuous inventory prioritized by real criticality.

Want to know how much of your institution's infrastructure is exposed today without your knowledge? Schedule a demo with the QuimeraX team and find out, in practice, what Asset Hunter finds on your healthcare environment's attack surface.

Conclusion

The digitization of healthcare is not reversible, nor should it be: it saves lives every day through faster diagnoses, more precise treatments, and more integrated care. But that same digitization created a fragmented technical ecosystem, where legacy records, connected medical devices, and integrations with laboratories and insurers coexist without any single area having unified visibility over all of it.

The real cases that have marked the sector in recent years, from the Barretos Cancer Hospital to ConecteSUS, from exposed DICOM systems to the laboratory chain affected by MedicSolution, share a common origin: exposure that existed, but that nobody knew existed. In a sector where the consequence of a failure can be measured in lives, not just financial loss, closing this visibility gap has stopped being a technical choice and become a clinical responsibility.