Healthcare Fixes Findings Fast. Programmatic Testing Hasn't Kept Pace.

Healthcare security teams move quickly on what they fix, but the sector runs more compliance-driven testing than any other, and it shows. This report combines five years of Cobalt pentest findings with a 2026 survey of healthcare security leaders and practitioners to profile how the sector finds, fixes, and thinks about security risk.

39%
Run a programmatic pentesting cadence (lowest of major sectors)

66%
Feel they are constantly playing catch-up (highest of any sector)

43%
Planning AI pentests but not yet running them (highest of any sector)

What’s Inside:

  • Why a fast mean remediation time masks a longer tail of open findings
  • How compliance-driven programs differ from continuous ones and what each misses
  • The gap between AI security plans and AI security action in healthcare
sopr-healthcare-2026-cvr