Forgotten Dairies
Healthcare’s Weakest Link Is Now Its Vendors -By Fransiscus Nanga Roka
Because a year of free credit monitoring is not a strategic response that is tough enough. Healthcare organizations need zero-trust access, phishing-resistant MFA, network segmentation, immutable offline backups, continuous vulnerability management as well as encryption and strict least-privilege controls. We recommend third-party contracts have concrete cybersecurity standards and include swift notification of an incident, independent audits and responsibility for security failures. The threat of enforcement, through HHS, shows that poor risk analysis after a ransomware incident can lead to corrective-action plans and fines.
The ransomware crisis ravaging American healthcare is at a tipping point. Cybercriminals aren’t just attacking hospitals, they’re exploiting the entire set of staffing firms, physician groups, contractors and technology vendors who have access to medical data. The shoddy cyber-attacks of Health Carousel and Consolidated Medical Practices of Memphis (CMPM) are not an August 10 cyber-attack incident to be looked at in isolation, but a clash over corporate accountability.
Health Carousel provides healthcare staffing and workforce-management services throughout the country. According to cyber-threat reporting Genesis told the world it was behind a ransomware attack on CMPM, which is based in Tennessee, on August 10, and it said it would publish compromising material about the company. Obviously, that is still an attacker claim and not definitive evidence of the extent of compromise. Health Carousel and Dire Wolf also need independent verification before total victim amounts or the types of data exfiltration can be considered fact.
The accusations emerged in August 2026 in a US health care industry already awash in ransomware-related scandals. This standard model is mercilessly streamlined: compromise credentials or insufficient infrastructure, access networks, escalate privileges, extract royal cash value nugget and (depending on temperament) encrypt systems in exchange for payment. As HHS itself acknowledges, ransomware is not only about encryption; it’s also about exfiltration.
This model is particularly destructive in healthcare and more so because of the nature of healthcare. You can cancel a stolen credit card. Diagnosis, medical history, social security number or date of birth can’t be recreated. Medical identity data, once it is exposed, can open the floodgates of years’ worth of impersonation and fraudulent billing and privacy abuse.
Why does liability matter so much to the corporate defense? Because “the hackers did it” is no longer the most effective corporate defense in the world.
HIPAA requires that regulated entities conduct thorough and accurate assessments of the risks and vulnerabilities to electronic protected health information and take the appropriate precautions. Importantly, the Breach Notification Rule generally assumes that a breach is presumed if (as here) there is an impermissible disclosure of protected health information unless the organization can demonstrate a low probability that the information was compromised.
That converts future investigations and any possible class actions from a search for criminals into an investigation of corporate behavior: Did you know about the vulnerabilities? Was multifactor authentication adequately deployed? Were privileges segmented? Were patches delayed? Were vendors continuously assessed? Were backups isolated? And the most basic of tests: would a system of security have detected or significantly mitigated the breach?
Plaintiffs could seek damages for any clear-cut harm caused by identity protection, mitigation costs and other legally cognizable injuries while also seeking injunctive relief that requires better cybersecurity. But courts need to distinguish between actual injury and speculative future harm.
Because a year of free credit monitoring is not a strategic response that is tough enough. Healthcare organizations need zero-trust access, phishing-resistant MFA, network segmentation, immutable offline backups, continuous vulnerability management as well as encryption and strict least-privilege controls. We recommend third-party contracts have concrete cybersecurity standards and include swift notification of an incident, independent audits and responsibility for security failures. The threat of enforcement, through HHS, shows that poor risk analysis after a ransomware incident can lead to corrective-action plans and fines.
Washington should go further: cyber care must become a patient safety issue at the board level. Because when ransomware takes healthcare offline, the asset at stake is not just data. Trust, and occasionally the safe distance from which to deliver medicine.
Fransiscus Nanga Roka
Faculty of Law University 17 August 1945 Surabaya and Managing Partner Law Firm Victorious Indonesia