Report by Cobalt

State of Pentesting in Healthcare 2025

13 FINDINGSPublished Sep 3, 2025
View Original Report →

Key Findings

Healthcare resolved only 57.4% of serious pen test findings. This ranks healthcare 11th of 13 industries. By comparison, transportation led with 80.2%.

CobaltState of Pentesting in Healthcare 2025·Sep 3, 2025
HealthcarePen testVulnerabilitiesTransportation

71% of healthcare leaders cited GenAI as the top risk.

CobaltState of Pentesting in Healthcare 2025·Sep 3, 2025
HealthcareGenAI

14% of healthcare organizations resolve critical findings in business-critical within eight to 14 days.

CobaltState of Pentesting in Healthcare 2025·Sep 3, 2025
HealthcarePen testVulnerabilities

68% of healthcare leaders cited third-party software as the top risk.

CobaltState of Pentesting in Healthcare 2025·Sep 3, 2025
HealthcareThird-party risk

The 2025 breach at DaVita compromised over 900,000 patients' personal and clinical data.

CobaltState of Pentesting in Healthcare 2025·Sep 3, 2025
HealthcareBreach

Just 13.3% of healthcare pentest findings qualify as “serious”. This ranks healthcare 6th-best out of 13 industries.

CobaltState of Pentesting in Healthcare 2025·Sep 3, 2025
HealthcarePen testVulnerabilities

71% of healthcare leaders cited GenAI as the top risk.

CobaltState of Pentesting in Healthcare 2025·Sep 3, 2025
HealthcareGenAI

43% of healthcare organizations resolve critical findings in business-critical assets in one to three days.

CobaltState of Pentesting in Healthcare 2025·Sep 3, 2025
HealthcarePen testVulnerabilities

Healthcare’s half-life for serious pen test findings was 244 days. This ranks healthcare 11th of 13 industries. Transportation had a half-life of 43 days.

CobaltState of Pentesting in Healthcare 2025·Sep 3, 2025
HealthcarePen testVulnerabilitiesTransportation

Healthcare’s median time to resolve serious pen test findings was 58 days. This ranks healthcare 10th of 13 industries. Hospitality led with 20 days.

CobaltState of Pentesting in Healthcare 2025·Sep 3, 2025
HealthcarePen testVulnerabilitiesHospitality

Nearly 40% of healthcare SLAs require serious findings in business-critical assets to be fixed within three days. Another 40% require resolution within four to 14 days.

CobaltState of Pentesting in Healthcare 2025·Sep 3, 2025
HealthcarePen testSLAVulnerabilities

37% of healthcare organizations resolve critical findings in business-critical assets within four to seven days.

CobaltState of Pentesting in Healthcare 2025·Sep 3, 2025
HealthcarePen testVulnerabilities

68% of healthcare leaders cited third-party software as the top risk.

CobaltState of Pentesting in Healthcare 2025·Sep 3, 2025
HealthcareThird-party risk