The healthcare industry closes high-risk findings faster than almost any sector, by one measure, but security teams in the industry are also more anxious about threats than other industries, and the industry has a lower rate of programmatic testing than any other sector. This overview of the state of pentesting in healthcare pairs five years of Cobalt pentest findings with our 2026 survey of security leaders and practitioners to profile how the sector finds, fixes, and thinks about security risk..
The healthcare industry runs less proactive penetration testing than most sectors, leaning on compliance-driven rather than continuous programs. However, there is a contradiction in the findings: the healthcare industry posts one of the fastest mean remediation times of any sector, but by a more rigorous measure (half-life, the time to clear half of all high-risk findings including those still open), it sits mid-pack. It's fast on what it fixes; slower to work through the whole backlog.
Sources: Cobalt State of Pentesting Report 2026 (~5,000 penetration tests/yr) · 2026 survey of 455 security leaders and practitioners (Emerald Research).
Every high-risk pentest finding runs this gauntlet, from discovery to closure. The industry moves quickly on what it fixes, but the half-life shows a longer tail of findings still open.
are high-risk
get resolved
to remediate
half-life
Where the healthcare industry stands: remediation half-life by sector
Chart: the time to remediate half of all high-risk findings. Lower is better.
The healthcare industry sits mid-pack on half-life (55 days), tied with the finance industry and well behind the leaders. That is worth pausing on, because on mean time to remediate (MTTR) the sector is actually second-fastest at 37 days. The two metrics diverge because they measure different things: MTTR counts only findings already fixed, while half-life captures the time to close half of all high-risk findings, including those still open. A fast MTTR with a middling half-life is the signature of a team that resolves the visible, tractable findings quickly but lets a harder tail sit open.
Here is the same half-life ranking on a single scale. Each sector is a colored dot matching the bar above. Note where healthcare's teal dot sits relative to the fast leaders on the left.
Confidence gap: anxiety the data partly explains
The healthcare industry rates its own posture lower than any sector, and the remediation tail gives that worry some grounding.
Where some industries are over-confident, the healthcare industry is the opposite: it is the most anxious sector in the survey, and the half-life data suggests the worry is not baseless. The table below pairs each survey concern with the pentest reality that speaks to it.
AI in the healthcare industry
What healthcare security teams worry about in their AI apps, and how they are testing (or not). Survey of healthcare respondents (n=95).
The healthcare industry's AI anxiety is sharpest around data, fitting for a field built on protected patient records. Its teams name data leakage as a top concern more than any other sector, but they are also the least likely to have moved from planning to programmatic AI testing.
Distinct to the healthcare industry: accountability sits squarely with the CISO (79%, the highest of any sector), not the builders. This is the inverse of software, where engineering owns AI risk. It concentrates responsibility on the security office rather than the teams shipping AI.
AI is the hardest asset class to secure across every industry. The healthcare industry, already stretched on coverage, is planning more AI testing than it is doing. Read the AI and Pentesting Pulse Report 2026 for the full cross-industry picture and where autonomous pentesting is headed. →
Recommendations for improving your approach to pentesting
Measure against half-life, not MTTR. A fast mean fix time hides a longer tail. Track how long it takes to clear half of all high-risk findings, and drive that number down.
Move from compliance-driven to programmatic testing. At 39% programmatic (the lowest of the major sectors), the sector tests to pass audits more than to find risk. A continuous cadence closes the tail.
Turn AI plans into AI tests. 43% are planning to pentest AI, but aren't currently doing so. With data leakage the top-named concern, planning is not protection. Schedule the first AI pentest now.
Treat vendor AI as your risk. With only 11% self-hosting, most AI exposure enters through third-party models. Extend assurance and testing to the supply chain.
Give the CISO the mandate to match the accountability. If the CISO owns the blame (79%), they need the authority and budget over AI security to match, not just the liability.
© Cobalt. Prepared from the State of Pentesting Report 2026 dataset.