-

15 Percent of Healthcare PCs Fail Security Test, Increasing Risk of Ransomware, Breaches, and Compliance Violations

  • New Research from Absolute Security Reveals Failures Include Endpoints with Non-Compliant and Missing Critical Security & Risk Controls
  • Visit Absolute Security in the Cybersecurity Command Center at HIMSS 2025 (Booth C1031) to Learn How to Strengthen Healthcare Endpoints Against Ransomware, IT Failures, and Compliance Risks

SEATTLE & LAS VEGAS--(BUSINESS WIRE)--Absolute Security, the leader in enterprise resilience, today published Resilience Obstacles in the Healthcare Industry, Q1 2025. This new research analyzed telemetry from more than a million PCs in healthcare environments to uncover the top factors stopping them from achieving resilient security postures. Now a key strategic imperative,1 resilience helps organizations ensure their mission-critical endpoint security controls and business applications remain always on, fully operational, and able to quickly recover from ransomware, operational outages, and disruptive IT incidents.

Key Findings

This new research highlights three critical resilience challenges that healthcare Security and Risk Management (SRM) leaders face:

  • Missing, Non-Compliant Security and Risk Controls – Of the PCs analyzed, 15 percent of the time, critical security controls were found to be either non-compliant with internal security and risk policies or missing from devices. Foundational security controls assessed included Data Protection, Endpoint Protection Platforms (EPP/XDR), Security Service Edge (SSE), VPN, and Vulnerability Management solutions. These findings show that in healthcare, PCs and networks are frequently without a vital first line of defense against attackers and exploits.
  • Delayed Patching – The average Windows endpoint in healthcare is 48 days behind on critical security patches. With unpatched vulnerabilities being a leading cause of breaches and ransomware infections,2 this basic security hygiene failure is leaving organizations open to data breaches and prolonged, disruptive outages.
  • Shadow AI Risks – AI use is growing, with healthcare employees frequently accessing generative AI platforms including ChatGPT, which is not HIPAA-compliant. This not only raises concerns about potential patient data exposure and regulatory violations, but also demonstrates organizations struggle to govern Shadow AI use.

“Ransomware groups continue to target the healthcare sector, exploiting vulnerable endpoints to disrupt operations and steal sensitive patient data. At the same time, compliance risks are rising as healthcare organizations struggle to maintain healthy security controls and monitor AI-related threats," said John Herrema, Chief Product Officer, Absolute Security. “With a proactive and resilient approach, hospitals, clinics, and healthcare providers can close risk gaps, avoid regulatory failures, and quickly recover after being hit with a cyberattack or IT incident.”

Embedded in the hardware of more than 600 million endpoints, the Absolute Security Resilience Platform helps thousands of global customers remain resilient in the face of ransomware, other threats, BSOD and IT incidents. Learn more about how Absolute helps healthcare organizations like yours:

About Absolute Security

Absolute Security is partnered with more than 28 of the world’s leading endpoint device manufacturers, embedded in the firmware of 600 million devices, trusted by thousands of global enterprise customers, and licensed across 16 million PC users. With the Absolute Security Cyber Resilience Platform integrated into their digital enterprises, customers ensure their mobile and hybrid workforces connect securely and seamlessly from anywhere in the world and that business operations recover quickly following cyber disruptions and attacks.

To learn more, visit www.absolute.com and follow us on LinkedIn, X, Facebook, and YouTube.

ABSOLUTE SECURITY, ABSOLUTE, the ABSOLUTE LOGO, AND NETMOTION are registered trademarks of Absolute Software Corporation ©2025, or its subsidiaries. All Rights Reserved. Other names or logos mentioned herein may be the trademarks of Absolute or their respective owners. The absence of the symbols ™ and ® in proximity to each trademark, or at all, herein is not a disclaimer of ownership of the related trademark. Absolute Security is a Crosspoint Capital portfolio company.

1 Gartner, Leadership Vision for 2025: Security and Risk Management, Jan. 13, 2025.

2 Mandiant: M-Trends 2024 Special Report; Sophos: Unpatched Vulnerabilities: The Most Brutal Ransomware Attack Vector

Contacts

Media Relations
Joe Franscella
press@absolute.com

ABSOLUTE SECURITY


Release Versions

Contacts

Media Relations
Joe Franscella
press@absolute.com

Social Media Profiles
More News From ABSOLUTE SECURITY

Enterprises Lose $19 Million Per Hour When Endpoint Devices are Disrupted, Reveals Survey of 1,000 Enterprise CISOs

SEATTLE & LAS VEGAS--(BUSINESS WIRE)--BLACK HAT 2026 – Absolute Security, an Autonomous Cyber Resilience leader, today published the third volume in its State of Enterprise Cyber Resilience research series: Autonomous Cyber Resilience in the Era of AI. The report features results from a survey conducted by Censuswide that includes 1,000 Chief Information Security Officers (CISOs) based in the United States (500) and the United Kingdom (500). Among the top findings was that when endpoint devices...

Absolute Security Launches on Pax8 Marketplace to Deliver Endpoint Cyber Resilience Solutions for Managed Service Providers (MSPs)

SEATTLE--(BUSINESS WIRE)--Absolute Security, an enterprise cyber resilience leader, today announced it has launched on the Pax8 Marketplace, the global AI and cloud marketplace for small and medium-sized businesses (SMBs). This collaboration with Pax8 enables managed service providers (MSPs) to seamlessly access, deploy, and manage Absolute Security cyber resilience solutions directly within the Pax8 ecosystem. This enables MSPs to provide customers with AI-powered endpoint device security, com...

Absolute Security Unveils Lenovo ThinkShield TraceLock, Giving Customers the Ability to Maintain Control, Security, and Resilience Across Offline PCs

SEATTLE & NATIONAL HARBOR, Md.--(BUSINESS WIRE)--Gartner SRMS 2026 — Absolute Security, an enterprise cyber resilience leader, today unveiled Lenovo ThinkShield TraceLock. Powered by the Absolute Security Cyber Resilience Platform, customers can leverage this innovation to locate, wake, connect, control, and restore supported devices through a firmware-embedded, persistent connection, even when they are powered off or disconnected from WiFi or local area networks. With the ability to locate and...
Back to Newsroom