Continental Postal Services of Hebland

Six in 10 Cyberattacks in Colombia Target Hospitals


Six out of every ten cyberattacks in Colombia target hospitals and clinics, according to a recent report by Biofile. Credit: AI-generated illustration. ColombiaOne.

Six in 10 cyberattacks recorded in Colombia target health sector institutions, a figure that highlights the growing exposure of hospitals and clinics to digital threats.

The figure, included in a Biofile report based on a measurement analyzed from IBM’s X-Force Index, shows that medical information has become one of the main targets for cybercriminals.

The risk is not limited to the theft of personal data, as an attack on a hospital can compromise medical records, diagnoses, medications, test results, and systems used to care for patients.

It can also affect the operation of an entire institution and force health professionals to temporarily rely on manual procedures. In an emergency department, an interruption of this kind can have particularly serious consequences.

Six in 10 cyberattacks in Colombia target hospitals

Healthcare institutions hold large amounts of information that is particularly attractive to criminals. Medical records contain personal data, medical histories, diagnoses, treatments, and other information that can be used to commit fraud, extortion, or new forms of impersonation.

According to the report cited by Biofile, 60% of cyberattacks recorded in Colombia were directed against healthcare institutions. The figure does not mean that all of these attacks resulted in information leaks or that all medical records were compromised, but it does show the scale of the threat facing the sector.

The situation becomes more significant at a time when Colombia’s healthcare system is moving toward greater digital interoperability. Integrating systems allows essential patient information to circulate among different stakeholders and facilitate care, but it also increases the number of points that must have adequate protection mechanisms.

The problem of a cyberattack against a hospital goes far beyond an IT failure. When systems become unavailable, doctors may temporarily lose access to information needed to make clinical decisions, while processes such as referrals, medication distribution, procedure scheduling, or access to test results can be delayed.

A case in Colombia illustrates the consequences that these types of incidents can cause. In March 2024, a ransomware attack affected the technological infrastructure of a hospital in Caldas. The institution had to restrict access to its network, use backups, and rely on manual records while it worked to recover its platforms.

Ransomware attacks represent one of the main threats to healthcare organizations. In these cases, criminals can block systems and files and subsequently demand money to restore access. In other scenarios, in addition to encrypting information, they steal data and threaten to publish it if the institution does not comply with their demands.

What is clear is that in March alone this year, the National Health Superintendency — the public entity that oversees healthcare system actors to protect users’ rights — reported more than 23 million attempted attacks in a single month.

Colombian hospitals.Colombian hospitals.
Hospitals and clinics are particularly vulnerable to cyberattacks, with consequences that extend far beyond sensitive patient information. Credit: Josep Maria Freixes / ColombiaOne.

Digital transformation also increases risks

Digitalization has made it possible to modernize numerous healthcare processes, but it has also created an increasingly larger attack surface. Connected systems, medical devices, healthcare platforms, cloud services, and databases must be protected against threats that evolve rapidly.

The problem is not limited to the technology used by large clinics. A malicious email opened by an employee, a reused password, an outdated system, or an incorrect configuration can become an entry point for compromising an entire network.

International experience confirms that the healthcare sector is facing growing pressure. An analysis cited in the same report indicates that during the first half of 2026, hundreds of ransomware attacks and claims against healthcare organizations were recorded worldwide.

For Biofile, what matters is not only preventing criminals from accessing systems, but also ensuring that essential services can continue operating even during a digital emergency.

This means having reliable backups, response protocols, monitoring systems, and continuity plans that have been tested before an attack occurs. It also requires training staff, since a significant portion of risks begins with human error.

All of this makes clear from this report that the healthcare sector is one of the main fronts in cybersecurity in Colombia. Protecting medical information, therefore, is no longer an issue exclusively for IT departments. It is also about guaranteeing the privacy of millions of patients and, above all, preventing a digital threat from ultimately affecting a person’s care when they need it most.



Source link

Leave A Reply

Your email address will not be published.