Risk Management Strategies

18,855 Healthcare Cyber Incidents in Six Months: The Controls File Before a Hospital Renewal

CERT-In's sector data, placed before the Rajya Sabha in August 2026, counted 34,480 healthcare incidents in 2025 and 18,855 in the first half of 2026. This is how to read the breakdown the way an underwriter does, and the controls evidence a hospital group needs before its next cyber renewal.

Tarun Kumar Singh
Tarun Kumar SinghStrategic Risk & Compliance SpecialistAIII · CRICP · CIAFP
10 min read

Listen to this article

Audio version • 10 min read

cyber insurancehealthcareCERT-Insecurity controlsrenewal preparation

Last reviewed: September 2026

What the Rajya Sabha Numbers Actually Put on the Record

Until August 2026, an Indian hospital group arguing about its cyber renewal had no recent official sector-level incident count to point to. That changed when Union Minister of State for Electronics and Information Technology Jitin Prasad placed CERT-In's figures before the Rajya Sabha, reported by Outlook Money on 9 August 2026 and by The Times of India on 8 August 2026.

The headline numbers are these. Banking and healthcare together recorded 6,04,588 incidents in 2025 and 3,67,462 between January and June 2026. Within healthcare alone, CERT-In detected 34,480 incidents in 2025 and 18,855 between January and June 2026. On the banking side, CERT-In detected 39 targeted intrusion campaigns during 2025 and another 17 between January and June 2026, while incidents involving vulnerable services stood at 99,663 in 2025 and 39,319 in the first six months of 2026.

Two things follow. Doubled out, the half-year healthcare figure runs slightly ahead of the full-year 2025 count, so the exposure is not receding. And the same reply breaks the healthcare number down by incident type, which is where the underwriting conversation actually lives.

Reading the Breakdown the Way an Underwriter Will

Of the 34,480 healthcare incidents in 2025, malicious scanning and probing accounted for 32,297. Of the 18,855 in the first half of 2026, scanning and probing accounted for 18,259. That leaves 2,183 and 596 incidents respectively in every other category combined.

Scanning and probing is reconnaissance. It tells an underwriter that a hospital's internet-facing estate is being enumerated continuously, which was already assumed, and no cyber insurer prices a hospital on scan volume. The residual figure counts the incidents that progressed past reconnaissance, and those are the ones that sit upstream of a claim.

Why the split matters at renewal

A broker who walks into a renewal quoting 18,855 incidents as evidence of a hardening market is quoting the wrong number, and the underwriter will say so. The defensible use of this data is narrower, and more useful:

  • Scanning and probing volume justifies attack-surface controls: external asset inventory, exposure management, and closure of services that should never have been reachable.
  • The residual non-scanning incidents justify detection, segmentation and recovery controls, because those are the categories that turn into encryption events and data exfiltration.
  • The banking comparison earns its place here. CERT-In counted 39 targeted intrusion campaigns in banking in 2025 against 99,663 vulnerable-service incidents. Targeted campaigns are rare; unpatched and exposed services are not. Hospitals carry the same asymmetry, usually worse, because clinical equipment cannot be patched on an IT schedule.

HMIS and PACS Segmentation: The First Evidence Item

The single question that most reliably separates hospital submissions is whether the clinical network is segmented from the administrative one, and whether the operator can prove it as well as assert it.

A typical Indian hospital group runs a hospital management information system carrying registration, orders, billing and discharge data, a picture archiving and communication system holding imaging studies, a laboratory information system, and an administrative estate of email, finance and HR. When these share a flat network, a phishing compromise on a billing workstation reaches the imaging archive without crossing a control.

What an underwriter will accept as evidence:

  1. A current network diagram showing VLAN or zone boundaries between the clinical segment (HMIS, PACS, LIS, modalities) and the corporate segment, with the firewall or ACL rule set that enforces them.
  2. The east-west rule base itself, not a summary. Specifically, which protocols are permitted from corporate to clinical, and whether SMB, RDP and management protocols are among them.
  3. Evidence of DICOM and HL7 interfaces being restricted to named source and destination pairs rather than open to the segment.
  4. Administrative access paths: whether domain administrators from the corporate forest can authenticate into clinical systems, and whether privileged access is brokered through a jump host with session recording.
  5. Dated proof that the segmentation was tested, from an internal exercise or an external assessment, showing what a compromised corporate endpoint could and could not reach.

Point five carries the most weight. Segmentation that exists on a diagram and not in the rule base is a common finding, and an insurer that has paid a hospital ransomware claim knows it well.

Biomedical Device Inventory and Unpatched Modality Exposure

CERT-In's vulnerable-services category is the closest public proxy for the exposure that hospitals struggle most to control. In banking that category ran to 99,663 incidents in 2025. In a hospital, the equivalent estate includes CT and MRI consoles, ultrasound carts, infusion pumps, ventilators, anaesthesia workstations, dialysis machines and patient monitors, much of it running operating system versions the vendor will not permit the operator to patch without revalidating the device.

This is not a solvable problem in a renewal cycle, and no underwriter expects it to be. What they expect is that the operator knows the size and shape of it.

The inventory an insurer will actually read contains, per device class: quantity, operating system and firmware version, vendor support status, network connectivity (isolated, clinical VLAN, internet-reachable), authentication method, and whether the device is covered by a vendor service contract that includes security updates.

Compensating controls where patching is blocked

Where the device cannot be patched, the evidence shifts to what surrounds it:

  • Micro-segmentation or a dedicated medical-device VLAN with default-deny egress, so an unpatched modality console cannot reach the internet or the corporate segment.
  • Passive device-discovery monitoring, because active scanning of clinical equipment carries its own patient-safety risk and several hospitals have learned that the hard way.
  • Documented downtime procedures for each critical modality, showing how imaging, pathology reporting and medication administration continue on paper if the system is unavailable. This is a business-interruption control as much as a security one, and it directly affects how an insurer models the business interruption element of a hospital cyber loss.
  • A change-control record showing when a device was last assessed and by whom.

A biomedical inventory that has never been reconciled against the network is worth very little. The gap between the asset register held by the biomedical engineering department and the devices actually appearing on the clinical VLAN is, in most hospitals, the exposure. Reconcile the two before submission, because the questionnaire will ask for the network-derived figure.

Backup Immutability, and the Restore Test Nobody Ran

Ransomware underwriting in India now turns on recovery capability more than on prevention. Prevention failures are priced into the market, while a hospital that can restore in 48 hours and one that cannot carry very different severity distributions on the same frequency assumption.

The evidence pack should establish four things, each with a date attached.

  1. Immutability. Whether backups are held in a write-once form (object-lock storage, an air-gapped copy, or tape rotated offsite) and for what retention period. State the mechanism, not the vendor name.
  2. Credential separation. Whether the backup infrastructure authenticates against the same directory as production. If a domain compromise reaches the backup console, immutability is the only thing left, and if there is no immutability there is no recovery.
  3. Restore testing. The date of the last full restore of the HMIS database and of a PACS study set, the elapsed time, and whether the restored system was validated clinically. Partial file-level restores do not answer this question.
  4. Recovery objectives per system. RTO and RPO stated separately for HMIS, PACS, LIS and billing, because they are not the same. A four-hour RPO on billing and a 24-hour RPO on imaging is a defensible position; a single blanket figure across the estate signals that nobody has done the analysis.

A restore test dated within the last six months, covering the systems the hospital says it cannot operate without, changes the tenor of a renewal meeting more than any other single document.

Third Party Access: Diagnostics, Billing and the Vendor Perimeter

Indian hospital groups run a wide vendor bench: outsourced radiology reporting, reference laboratories, revenue-cycle and TPA billing intermediaries, HMIS partners with standing support access, biomedical vendors with remote diagnostics, and health-tech platforms handling appointments and teleconsultation.

Each of those relationships is a credentialed path into patient data, and most cyber policy wordings treat a loss originating at a vendor differently from one originating in the insured's own estate. Some respond only where the insured is legally liable for the data; some carry contingent business interruption cover with a waiting period; some carry an exclusion for outsourced service providers unless specifically endorsed.

The renewal file should carry, for the ten or so vendors with access to patient data or clinical systems:

  • The access method (site-to-site VPN, remote-access tool, named user accounts in the HMIS, API integration) and whether it is always-on or requested per session.
  • Whether access is multi-factor authenticated and time-bound.
  • The data categories the vendor can reach, and whether that reach is scoped to the vendor's own patients or the whole database. Reference labs and reporting vendors are frequently over-scoped.
  • The contractual position on security obligations, breach notification timelines and audit rights.
  • The date of the last access review, with evidence that dormant accounts from ended engagements were removed.

Cross-check this list against the cyber insurance programme itself. If the operator depends on a single outsourced reporting vendor for night-time radiology, the contingent business interruption sub-limit and waiting period should be tested against that dependency rather than accepted as boilerplate.

DPDP Duties and the Six-Hour CERT-In Clock Alongside the Policy Condition

A hospital handling patient records is a data fiduciary under the Digital Personal Data Protection Act, 2023, processing what is, by any clinical reading, the most sensitive personal data an Indian organisation holds. Breach obligations run to the Data Protection Board and to affected individuals, and patient volumes make individual notification at a hospital group an operational exercise rather than a letter.

Sitting alongside that is CERT-In's directions of April 2022, under which specified cyber incidents must be reported within six hours of noticing them. The corpus covers the mechanics of that obligation in detail in [CERT-In cyber incident reporting and cyber insurance programmes](/regulation-compliance/cert-in-incident-reporting-insurance-india-2026), and the point for a hospital is the collision of clocks.

Three deadlines start at different moments and run at different speeds:

  1. The CERT-In six-hour report, which starts when the incident is noticed.
  2. The DPDP notification duties to the Board and to affected data principals.
  3. The policy's own notice condition, which typically requires notification to the insurer as soon as practicable and, separately, requires the insurer's prior consent before the insured incurs response costs, engages counsel or forensics, or makes any payment.

The evidence item here is the incident-response plan itself, showing named roles, the six-hour reporting path, the DPDP assessment step, the insurer notification contact, and a record that the plan has been exercised. A tabletop exercise involving the medical superintendent, the CIO, the data protection officer and the broker, dated within the last year, is worth more to an underwriter than the plan document alone.

Assembling the Renewal File

Hospital cyber submissions in the Indian market are still frequently a proposal form and little else. Operators getting differentiated terms submit an evidence pack, and the difference shows in retention levels and ransomware sub-limits more than in headline rate.

A workable pack for a hospital group renewal runs to roughly twenty pages and contains:

  1. Network diagram with the clinical and corporate zone boundary, plus the enforcing rule set.
  2. Biomedical device inventory by class, with operating system, support status and network placement, reconciled against network discovery.
  3. Backup architecture note covering immutability mechanism, credential separation, and the dated restore test result for HMIS and PACS.
  4. Recovery objectives per critical system, with the clinical downtime procedures that apply while systems are unavailable.
  5. Third-party access register for vendors touching patient data, with the last access review date.
  6. Identity summary: multi-factor coverage on email, remote access and privileged accounts, stated as a percentage of accounts rather than as a policy statement.
  7. Incident-response plan with the CERT-In six-hour path, DPDP assessment step and insurer notification built in, plus the date of the last tabletop.
  8. A short remediation roadmap for the known gaps, with owners and dates. Underwriters do not expect a clean sheet from a hospital. They expect the operator to know what is open and to be working on it.

An argument about limit rather than terms needs its own modelling rather than a benchmark, and the approach is set out in cyber risk quantification and limit sizing. The broader clinical and property exposures that sit around the cyber programme are covered in the hospital sector risk profile.

CERT-In's figures gave the sector a number it did not previously have. The operators who benefit are the ones who use it to fund the control programme, then walk into the renewal with evidence that the programme exists.

About the Author

Tarun Kumar Singh

Tarun Kumar Singh

Strategic Risk & Compliance Specialist

  • AIII
  • CRICP
  • CIAFP
  • Board Advisor, Finexure Consulting
  • Developer of the Behavioural Underinsurance Risk Index (BURI)

Tarun Kumar Singh is a seasoned risk management and insurance professional based in Bengaluru. He serves as Board Advisor at Finexure Consulting, where he advises insurance, fintech, and regulated firms on governance, growth, and trust. His work spans insurance broker regulatory frameworks across India, UAE, and ASEAN, IRDAI compliance and Corporate Agency model reform, VC governance in insurtech, and MSME insurance gap analysis. He is the developer of the Behavioural Underinsurance Risk Index (BURI), a framework applying behavioural economics to underinsurance and insurance fraud risk.

Frequently Asked Questions

Do the CERT-In healthcare numbers mean hospital cyber premiums will rise?
Not on their own. Most of the count is malicious scanning and probing (32,297 of 34,480 incidents in 2025 and 18,259 of 18,855 in the first half of 2026), which indicates reconnaissance rather than compromise. Indian cyber underwriters price a hospital on its own controls, claims history and data volumes. The data is useful for funding a control programme internally and for framing the sector context, but a submission that quotes the national count without evidence of segmentation, patch posture and tested recovery tends to attract harder terms, not softer ones.
What is the single most useful document to add to a hospital cyber submission?
A dated full restore test covering the HMIS database and a PACS study set, stating elapsed time and whether the restored system was clinically validated. Ransomware severity, which is what drives the ransomware sub-limit and the retention, depends more on recovery capability than on prevention. A restore test within the last six months answers the question insurers care most about, and very few Indian hospital submissions currently carry one.
How should a hospital handle biomedical devices that cannot be patched?
Document them. Hiding them is what costs terms. Build a device inventory by class showing operating system, firmware, vendor support status and network placement, and reconcile it against what actually appears on the clinical VLAN. Then evidence the compensating controls: a dedicated medical-device segment with default-deny egress, passive discovery rather than active scanning (active scans of clinical equipment carry patient-safety risk), and written downtime procedures for each critical modality. Underwriters expect unpatchable estate in a hospital; they penalise operators who cannot quantify it.
Does notifying CERT-In within six hours satisfy the policy's notification condition?
No. They are separate obligations to separate parties. CERT-In's April 2022 directions require reporting specified incidents within six hours of noticing them. The policy requires notice to the insurer under its own condition and, separately, usually requires the insurer's prior consent before response costs, counsel or forensics are engaged. Engaging an incident-response firm in the first hours to meet the regulatory deadline without insurer consent is a recurring source of coverage disputes. Put both steps in the same runbook line and pre-agree panel vendors at renewal.
How does third-party vendor access affect a hospital cyber policy?
Materially, because outsourced radiology reporting, reference laboratories, billing intermediaries and HMIS support partners all hold credentialed paths into patient data. Wordings differ on whether a loss originating at a vendor is covered, whether contingent business interruption applies and what waiting period attaches. Maintain an access register for every vendor touching patient data covering access method, multi-factor status, data scope and last access review date, then test the contingent business interruption sub-limit and waiting period against the vendors the hospital genuinely cannot operate without.

Related Glossary Terms

Related Insurance Types

Related Industries

Related Articles

Sarvada Intelligence

Ready to see Sarvada in action?

Explore the platform workflow or start a product conversation with our underwriting automation team.

Explore the platform