Targeting the Human Factor: OSINT in Healthcare
DOI:
https://doi.org/10.34190/eccws.25.1.4561Keywords:
healthcare, cybersecurity, OSINT, general practitioners, supply chainAbstract
Patients increasingly report that physicians spend more time on the computer than on their examination. While digitalisation is a necessary development in healthcare, it unfolds in a sector constrained by shortages of medical and administrative staff, outdated software and technical infrastructure within the facilities, and uneven levels of digital literacy of medical staff, with the vision of fully paperless healthcare still largely unrealised. At the same time, healthcare has become a target of frequent and sophisticated cyberattacks. In the attempts of a data-driven society, healthcare faces growing demands for efficiency of care provided, interoperability, and timely access to patient data through eHealth solutions. The adoption of emerging technologies, including diagnostic LLMs, is often initiated by medical professionals, sometimes without supervision of IT departments or security teams. As a result, digital transformation increasingly relies on healthcare staff who embrace expanded operational, managerial, and digital responsibilities. This evolution significantly increases the human digital footprint of healthcare professionals and broadens the potential attack surface. As an essential sector under current cybersecurity frameworks, healthcare operates across both professional and private cyberspace. While cybersecurity measures may be implemented by employers during working hours, responsibility for security in private contexts largely depends on individual healthcare workers. Open-Source Intelligence (OSINT) techniques can exploit publicly available data related to professional tasks, online behaviour, and leisure activities, often revealing sensitive insights into clinical practices and personal routines of healthcare staff. From a cybersecurity perspective, healthcare can be perceived as a supply chain in which general practitioners frequently serve as the first point of contact. Due to their limited technical and financial resources, they may represent a structurally vulnerable link within this chain. Although cyber incidents affecting large hospitals attract greater media attention, smaller healthcare providers experience similar threats, which—given the interoperability vision—can have severe implications for the broader healthcare chain. This paper therefore examines OSINT-based human targeting of general practitioners and discusses how information obtained can be leveraged in cyber operations against the healthcare sector.
Downloads
Published
Issue
Section
License
Copyright (c) 2026 European Conference on Cyber Warfare and Security

This work is licensed under a Creative Commons Attribution-NonCommercial-NoDerivatives 4.0 International License.