How Cyberattacks on Mainline Health and Select Medical Exposed Over 200,000 Patients episode artwork

EPISODE · Jun 25, 2025 · 45 MIN

How Cyberattacks on Mainline Health and Select Medical Exposed Over 200,000 Patients

from Daily Security Review · host Daily Security Review

The healthcare industry is facing a relentless wave of cyber threats, as demonstrated by two recent breaches impacting Mainline Health Systems and Select Medical Holdings. In April 2024, Mainline Health experienced a direct ransomware attack by the Inc Ransom group, compromising sensitive data for over 101,000 individuals. Select Medical’s breach, in contrast, occurred through a third-party vendor—Nationwide Recovery Services—exposing records of nearly 120,000 patients. These incidents illustrate the growing vulnerability of healthcare organizations, whether from direct attacks or through weaknesses in their extended vendor networks.As healthcare organizations digitize records, adopt connected medical devices, and rely on cloud services and third-party vendors, the risk landscape grows more complex. Ransomware, hacking, and third-party vendor compromises are now the leading causes of healthcare data breaches—often with serious implications for patient care, financial stability, and organizational reputation.In this episode, we examine:How the Inc Ransom group operates, and why healthcare is a prime targetThe increasing financial and operational impact of ransomware and third-party breachesCommon attack vectors including hacking, phishing, and supply chain vulnerabilitiesWhy third-party risk management is becoming a critical element of healthcare cybersecurityThe direct impacts of breaches on patient safety, care delivery, and mortality ratesRecommended mitigation strategies, from multi-factor authentication and privileged access management to continuous monitoring of vendor ecosystemsThe role of national cybersecurity frameworks, HHS initiatives, and information sharing platforms in building sector resilienceThese recent breaches serve as a wake-up call: healthcare cybersecurity can no longer be reactive or siloed. A comprehensive approach—addressing both internal defenses and third-party risks—is essential to protect sensitive patient data and maintain uninterrupted care.

Episode metadata supplied by the publisher feed · Published Jun 25, 2025

Embed this episode

NOW PLAYING

How Cyberattacks on Mainline Health and Select Medical Exposed Over 200,000 Patients

0:00 45:10

No transcript for this episode yet

We transcribe on demand. Request one and we'll notify you when it's ready — usually under 10 minutes.

No similar episodes found.

No similar podcasts found.

Frequently Asked Questions

How long is this episode of Daily Security Review?

This episode is 45 minutes long.

When was this Daily Security Review episode published?

This episode was published on June 25, 2025.

Can I download this Daily Security Review episode?

Yes. Use the download control on the episode player to save the publisher-provided media file.
URL copied to clipboard!