State of Pentesting in the Healthcare Industry

The healthcare industry closes high-risk findings faster than almost any sector, by one measure, but security teams in the industry are also more anxious about threats than other industries, and the industry has a lower rate of programmatic testing than any other sector. This overview of the state of pentesting in healthcare pairs five years of Cobalt pentest findings with our 2026 survey of security leaders and practitioners to profile how the sector finds, fixes, and thinks about security risk..

The healthcare industry runs less proactive penetration testing than most sectors, leaning on compliance-driven rather than  continuous programs. However, there is a contradiction in the findings: the healthcare industry posts one of the fastest mean remediation times of any sector, but by a more rigorous measure (half-life, the time to clear half of all high-risk findings including those still open), it sits mid-pack. It's fast on what it fixes; slower to work through the whole backlog.

Sources: Cobalt State of Pentesting Report 2026 (~5,000 penetration tests/yr) · 2026 survey of 455 security leaders and practitioners (Emerald Research). 

The high-risk remediation funnel

Every high-risk pentest finding runs this gauntlet, from discovery to closure. The industry moves quickly on what it fixes, but the half-life shows a longer tail of findings still open.

9%
of findings
are high-risk
86%
of those
get resolved
37d
mean time
to remediate
55d
high-risk
half-life
39%
run a programmatic pentesting cadence (lowest of the major sectors)
81%
say AI needs a strategic pause to recalibrate (highest of any sector)
56%
are compliance-driven rather than programmatic (highest of any sector)

Where the healthcare industry stands: remediation half-life by sector

Chart: the time to remediate half of all high-risk findings. Lower is better.

The healthcare industry sits mid-pack on half-life (55 days), tied with the finance industry and well behind the leaders. That is worth pausing on, because on mean time to remediate (MTTR) the sector is actually second-fastest at 37 days. The two metrics diverge because they measure different things: MTTR counts only findings already fixed, while half-life captures the time to close half of all high-risk findings, including those still open. A fast MTTR with a middling half-life is the signature of a team that resolves the visible, tractable findings quickly but lets a harder tail sit open.

Software38dProfessional Services45dHospitality50dHealthcare55dFinance55dEducation69dManufacturing73dRetail84dUtilities96dEntertainment98d

Here is the same half-life ranking on a single scale. Each sector is a colored dot matching the bar above. Note where healthcare's teal dot sits relative to the fast leaders on the left.

40d55d70d85d100dHealthcare · 55dfastest sectorslowest sector

Confidence gap: anxiety the data partly explains

The healthcare industry rates its own posture lower than any sector, and the remediation tail gives that worry some grounding.

Where some industries are over-confident, the healthcare industry is the opposite: it is the most anxious sector in the survey, and the half-life data suggests the worry is not baseless. The table below pairs each survey concern with the pentest reality that speaks to it.

The concern (survey)
 
The reality (pentest data)
66%feel they are constantly “playing catch-up” (the highest)
55dhalf-life, mid-pack and behind the fastest sectors
67%say AI demand has outpaced their ability to secure it
43%are only planning to pentest AI, not yet doing it
33%feel well-equipped to address AI security (the lowest)
39%run a programmatic pentesting cadence (the lowest)

AI in the healthcare industry

What healthcare security teams worry about in their AI apps, and how they are testing (or not). Survey of healthcare respondents (n=95).

The healthcare industry's AI anxiety is sharpest around data, fitting for a field built on protected patient records. Its teams name data leakage as a top concern more than any other sector, but they are also the least likely to have moved from planning to programmatic AI testing.

Top AI security concerns named by healthcare industry security teams
Data leakage / sensitive exposure
80%
Prompt injection attacks
67%
Adversarial manipulation of output
51%
Unauthorized access to LLM APIs
46%
Model bias (legal / reputational)
17%
43%
are planning AI pentests, but not yet running them (highest of any sector)
11%
self-host their AI models (most rely on vendors)
36%
see AI as a threat, not a tool (highest threat perception)
Who gets blamed if AI causes an incident

Distinct to the healthcare industry: accountability sits squarely with the CISO (79%, the highest of any sector), not the builders. This is the inverse of software, where engineering owns AI risk. It concentrates responsibility on the security office rather than the teams shipping AI.

CISO
79%
Data / AI team
45%
Engineering / product
39%
Nobody
8%
Zoom out: AI FINDINGS ACROSS INDUSTRIES
32%
of AI findings are high-risk (vs 12% across all assets)
38%
of high-risk AI findings get resolved (lowest of any pentest type)

AI is the hardest asset class to secure across every industry. The healthcare industry, already stretched on coverage, is planning more AI testing than it is doing. Read the AI and Pentesting Pulse Report 2026 for the full cross-industry picture and where autonomous pentesting is headed. →

Recommendations for improving your approach to pentesting

Measure against half-life, not MTTR. A fast mean fix time hides a longer tail. Track how long it takes to clear half of all high-risk findings, and drive that number down.

Move from compliance-driven to programmatic testing. At 39% programmatic (the lowest of the major sectors), the sector tests to pass audits more than to find risk. A continuous cadence closes the tail.

Turn AI plans into AI tests. 43% are planning to pentest AI, but aren't currently doing so. With data leakage the top-named concern, planning is not protection. Schedule the first AI pentest now.

Treat vendor AI as your risk. With only 11% self-hosting, most AI exposure enters through third-party models. Extend assurance and testing to the supply chain.

Give the CISO the mandate to match the accountability. If the CISO owns the blame (79%), they need the authority and budget over AI security to match, not just the liability.

See where your AI and application security actually stands
Cobalt runs ~5,000 pentests a year across a broad set of industries. Get a demo to see how your remediation half-life and fix rate compare.
Get a demo →

© Cobalt. Prepared from the State of Pentesting Report 2026 dataset.

Back to Blog
About Cobalt
Cobalt combines talent and technology to provide end-to-end offensive security solutions that enable organizations to remediate risk across a dynamically changing attack surface. As the innovators of Pentest as a Service (PtaaS), Cobalt empowers businesses to optimize their existing resources, access an on-demand community of trusted security experts, expedite remediation cycles, and share real-time updates and progress with internal teams to mitigate future risk. More By Cobalt
Cobalt’s Code-Assisted Pentests
Learn more about Cobalt's code-assisted pentests.
Blog
Apr 1, 2022
PlexTrac Announces Partnership with Cobalt, the Leading Pentest as a Service Provider
Customers using the solutions together benefit from smarter, faster testing and remediation workflows.
Blog
Oct 31, 2022