Award-winning MFT Software - Diplomat MFT
Award-winning MFT Software - Diplomat MFT

Why Cybercriminals Target Healthcare: Coviant Software’s CEO Breaks Down the $4M Data Breach Crisis

by | Sep 22, 2025

Coviant Software CEO Greg Hoffer recently sat down with Cyber Defense TV for a discussion on why it is important for organizations of all sizes and across all industries to use a secure, managed file transfer solution for moving data securely and reliably. The conversation touched on the hidden risks and costs associated with DIY workflows, challenges specific to protecting healthcare data, and more.

Here’s what you’ll learn from watching this episode:

  • Healthcare Under Attack: Why healthcare is a favorite target for cybercriminals, with 127 confirmed HIPAA breaches and 4 million records compromised in Q1 alone
  • The Value of Your Medical Data: Why protected health information (PHI) and electronic health records (EHR) are worth 10x more than credit card data on the dark web and the reason why cybercriminals target healthcare organizations
  • The Supply Chain Problem: How sensitive data moves through complex networks of third parties, billing companies, and cloud services—creating massive security risks for organizations without secure file transfer workflows
  • Why Scripts Fail: The hidden costs and risks associated with using homegrown file transfer solutions and why they become maintenance nightmares
  • Managed File Transfer Solutions: How Diplomat MFT replaces risky scripts with enterprise-grade security, automated encryption and security management, auditing tools, and state-of-the-art security and compliance features
  • HIPAA Gets Teeth: Upcoming regulatory changes that will significantly increase standards for health data security and management, and increased fines and enforcement for healthcare data breaches
  • Beyond Healthcare: How MFT solutions apply to banking, legal, and any industry handling sensitive data under regulations like GLBA, GDPR, and SOX
  • Scalability & Deployment: That it’s not the size of the organization, but the size of the problem, and how organizations from five employees to large enterprises can easily implement secure file transfer without breaking the bank

Table 1: Dark Web Data Value Comparison (2024-2025 Market Research)

Table 1: Dark Web Data Value Comparison

Credit card data typically sells for $17-$120 per record. Because credit cards can be blocked or cancelled quickly, stolen data is often limited to one-time fraud use.

Healthcare data has a much longer shelf-life that can be used for more lucrative identity theft, insurance fraud, and medical fraud schemes, increasing the per-record value to between $250-$1,000.

KEY INSIGHT: Healthcare records far surpass the value of stolen credit cards, explaining why healthcare organizations have become the #1 target for cybercriminals.

What Makes Healthcare Data So Valuable?

Complete patient profiles with personal, financial, and health data (including personally identifiable information like social security numbers, dates of birth, address, and phone number) are often stored together and have long-term, reusable value. Health data can be used for identity theft, loan and credit applications, tax fraud, and medical equipment fraud.

Sources: HIPAA Vault (2025), Trustwave (2024), ID Agent (2024), Imprivata (2024)

Table 2: HIPAA Penalties – Evolution of Enforcement

Table 2: HIPAA Penalties

In the 1990s when HIPAA was first enacted, typical maximum fine was $1 million and regarded as a significant deterrent. Today, multibillion-dollar healthcare organizations consider $20 million little more than a rounding error. Expected penalty increases for HIPAA will be significantly higher, increasing risks and costs associated with non-compliance.

Table 3: Healthcare Data Supply Chain: Where Does Your Information Go?

Healthcare Data Supply Chain

Healthcare organizations are required to send and receive protected health information (PHI), electronic health records (EHR), and other sensitive data with many internal and external entities. These include, but are not limited to:

  • Other hospitals, clinics, pharmacies, and healthcare providers
  • Medicare/Medicaid payment processing
  • Insurance companies and claims processors
  • Laboratories and medical imaging companies
  • Federal and state regulatory agencies
  • Billing and financial services organizations

Table 4: File Transfer Solutions Comparison

File Transfer Solutions Comparison

When comparing a secure-by-design managed file transfer solution with custom scripts developed and maintained in-house by IT staff, the full range of features and risks must be considered. Even if the up-front costs are lower, long-term risks associated with lack of reliability, poor security, staff inefficiency, and the financial penalties that come with a data breach must be calculated.

This chart shows some of the features and capabilities required for secure, enterprise-grade file transfers that are consistent with security best practices and HIPAA / HITECH compliance.

Cyber Defense TV – Interview with Greg Hoffer, CEO of Coviant Software Interview Transcript

Gary Miliefsky: Welcome back to another exciting episode of Cyber Defense TV. I’m your host Gary Miliefsky, publisher of Cyber Defense Magazine. Sitting in my hot seat today is Greg Hoffer, CEO of Coviant Software. Coviant Software is an award-winning company, and one of the three awards they won recently from Cyber Defense Magazine was for HIPAA compliant managed file transfer software.

Speaking of HIPAA, Greg, we have 127 confirmed incidents in HIPAA breaches with four million records just in Q1 alone. What is going on? And welcome back to the hot seat.

Greg Hoffer: Hi Gary. Thank you for having me. Yes, healthcare certainly is in the news a lot recently, and I think what we’re all coming to realize over the past number of years is that the information that we share with healthcare providers is incredibly sensitive and has become a very ripe target for malicious actors out there.

And unfortunately, the sad truth is that the protection of that data is lagging behind in healthcare organizations. So, we really need to step up our game at securing these things.

Miliefsky: Now banks take cybersecurity very seriously. What’s going on in healthcare? Do they have the budgets? What’s slowing them down and why are they the soft underbelly for the cyber criminals?

Hoffer: I think that’s a great question. We all know the value of our money in banks, and there have been longstanding regulations to protect that because nobody wants to lose all of their money, so, there’s regulations with penalties involved that provide that economic incentive for banks to do everything in their power to protect it. I think for way too long, the healthcare industry, even though there’s HIPAA regulations that were a great start to protect that information. I think it’s a little bit aged right now and there maybe aren’t enough teeth in that regulation to provide the economic incentive for healthcare companies to actually protect the data. I mean, a $20 million fine is nothing to a healthcare company making a billion dollars in profits.

I think also you’re absolutely right that these IT staffs at healthcare organizations might not have the proper budget allocated to them, and they’re certainly very, very busy. There’s a lot to do in a healthcare organization, across the operations of patient records, intake, payment processing, insurance claims, Medicare, Medicaid reporting. There’s just an awful lot to do, and I think that’s where we see the disparity in the protection of that data.

Miliefsky: I’ve heard on the dark web, you know, PCI records your credit card info and all that is worth maybe 10 cents a record, but your healthcare could be 10 times the amount. The PHI record is 10 times more valuable. So healthcare is kind of the new bank and what’s in the bank is not your money. It’s all your medical information.

Hoffer: Yeah, that’s right. And these malicious actors see a ton of value out of the healthcare information because it contains personally identifiable stuff that can be used to forge your identity. And from that, it’s almost a multiplier effect, right? If your personally identifiable information is stolen by the bad guys, they can then apply for loans. They can mess with liens on your house. They can get credit cards under your name and use money that potentially you’re held accountable for. That’s why personally identifiable information has become the biggest target for malicious actors.

Miliefsky: And Greg, I’ve heard in country they’ll even change your address and ship very expensive medical equipment. Have a fake doctor in a fake office sign off on papers to get you thousands of dollars of medical gear that they then sell it on the black market. There’s just so many ways the bad guys are stealing this PHI and making money with it.

And then it’s really a supply chain issue. All these files are stored by a hospital or healthcare provider, but they move around and they move around to third parties, and there’s billing companies. There’s so much involved, the complexity of it. Where does secure managed file transfer come in and Diplomat MFT, to help solve this problem?

Hoffer: That’s an excellent point, and I’m not sure everyone is aware of how much data, not only do healthcare organizations intake, but quite often that intake of information, even if they do their best to protect it, and they follow all of the security guidelines, and they invest the money to protect the data within their corporate walls. The fact of the matter is that data is then used across a very vast information supply chain. The information for payment processing goes to Medicare, Medicaid. Some billing provider has to go to the insurance company for claims.

A lot of the data goes into some analytics service in the cloud to provide operational efficiencies for the company or data insights. Patient information might go to some data lake for analysis or to HR management systems. The data that a healthcare organization deals with spreads across lots and lots of services and systems. And as a result, there’s this potential leakage, not just within the healthcare industry itself, but somewhere in their information supply chain.

That’s why I’m happy to see proposed changes to HIPAA are coming up soon. That include things focused on assessing the risk and protecting the information supply chain by requiring these healthcare organizations to do more than just close their eyes once they hand the data off to some other link in that chain.

Miliefsky: And how do you replace the hodgepodge of scripts for moving files? Organizations don’t take file transfer as seriously as they should, and they’ve got their own code and their own scripts. How do we replace that and fix that? And where does Diplomat MFT come in in that equation?

Hoffer: That’s exactly the insertion point for a managed file transfer platform such as our Diplomat MFT. When a company, no matter how small or large, decides they really need to put emphasis on security, both within corporate boundaries and across the supply chain, they very quickly realize that the scripts they grew up on [aren’t sufficient]. They pay IT staff to build and maintain scripts, because initially it’s just, “Hey, we need data sent over to this state government to process claims or reporting to DHS about what we found through clinical research or whatever it is.”

Over time though, these scripts become big black hole of maintenance support. The IT staff has a high turnover, so it’s hard to maintain, build, et cetera, and it’s not audited. There’s no alerting. There’s questionable security, so managed file transfer is a solution that replaces those scripts with a purpose-built solution that adds easy to use file transfer, integrating across a wide variety of protocols, whether it’s file-based like SFTP or cloud-based, Google Cloud, Amazon, AWS S3, Azure, data lakes, or blobs, et cetera.

And layered across all of that are features like role-based access control, granular permissions so that you have least-privilege enforcement so that only the right people can perform these file transfers within your organization. It has data encryption, so you encrypt data not only in transit using secure protocols, but you encrypt the data at rest, with PGP, for example. And then full auditing of everything that goes on, full alerting so you know when things work or don’t work. Data archiving and retention… all the things that you really need to maintain security around that information you’re managing are consolidated into a one easy to use platform like Diplomat MFT.

Miliefsky: [That’s what is] probably missing from those on the wall of shame at hhs.gov and the 127 organizations breached so far, and probably their complete supply chain, too. They really need Diplomat MFT, and they need it today. And I think you said it’s no-code, it’s point and click setup. What’s holding these people up? And it’s not expensive, is it?

Hoffer: We’re certainly not expensive. We’re probably the best value in the MFT market providing almost all the features you would ever need at the lowest price with the best support in the industry. I think what’s holding people back is just that momentum behind this is the way we’ve always done it. That’s one big impediment. Maybe lack of knowledge that there are different or better ways to do this. So, if a company steps back and thinks, “What are my risks? How do we assess what we’re doing and how we can protect that data?” I think they’ll realize that they can do a little bit of research and find solutions like a managed file transfer platform that can achieve these goals, without necessarily breaking the bank.

Miliefsky: The breaches will go down and it’s a lot less than paying the fines. Healthcare has to get proactive. We really need to see more proactivity and regulatory compliance. It sounds great that HIPAA’s going to have some teeth in it. Do you know when those changes come about?

Hoffer: There are some proposed changes to HIPAA that also by the way, up those fines so that there are more teeth that brings it in line with the modern economy. When HIPAA was first released a $1 million fine might have been punitive, but nowadays it’s just a rounding error in the accounting. The proposed changes are in flight. They were hoping that they’ll come about sometime in the next 12-month timeframe. They used to say that it was going to happen in 2025, but as you know, regulation moves slowly. Fingers crossed it’ll happen.

Miliefsky: That sounds great. And I’m curious, with this whole supply chain issue, is Diplomat MFT licensed for a major organization and their supply chain? How does it get licensed and how does it get deployed?

Hoffer: A customer of ours acquires a license and installs our software on a machine that they own or manage. This can be in the cloud or on premises. Virtual machine, physical machine, we don’t really care. And then that allows that organization to automate and secure their file transfers both within their corporate boundaries and across to their supply chain. If they have regional or satellite offices, then we have a remote agent architecture that allows for easy transfer that way.

But when dealing with the supply chain, supply chain partners themselves usually have their own mechanism to perform the file transfer, whether they’re hosting an SFTP server or they require transfers through S3 buckets or Azure blobs, things like that. Our system has a wide variety of support for these file exchanges through those mechanisms. If you are in that supply chain and you want to increase your security, then it makes sense to also look at something like Diplomat MFT. By the way, one of the new features we’ve released recently is an audit tool, so customers of Diplomat MFT can run a utility that inspects the potential risks of their supply chain so that they can begin that conversation. For example, one of my vendors might be smaller with a small IT shop and they’re running some open source SFTP server, and maybe that’s an older version or has known vulnerabilities. Our audit tool raises that as a potential alert so our customer can talk with them about increasing their security.

Miliefsky: Wow, that’s wonderful. Diplomat MFT is really required in the healthcare space. Isn’t it also a need in other areas? I mean, I could think of law firms working on patents and intellectual property and sharing files with other people. There’s so many use cases in PCI records. Where else does Diplomat MFT go?

Hoffer: Yes, I think it’s easy to focus on healthcare because it is one of the top targets for the bad guys these days. But fundamentally what we’re saying is that whenever you share sensitive information you need to follow these good security practices. And so that sensitive information might be the credit card numbers or bank account statements like we mentioned for banks and credit unions. Those usually fall under PCI-DSS standard, isn’t really a regulatory compliance, it’s not enforced by the government, but it’s enforced by the payment card industry. If you don’t adhere to those standards, you can’t use those systems, which means you can’t take payments from customers, so it provides good teeth for those companies to keep things secure.

We also see other regulations across the globe and across industries such as GDPR in Europe to protect information privacy. We see other banking regulations like Basel II and Basel III. Here in the United States we have GLBA, the Gramm-Leach-Bliley Act. We have Sarbanes Oxley (SOX). Diplomat MFT really does cover whatever sensitive information that you are working with that needs to be secured. And there’s usually a regulation around that somewhere.

Miliefsky: That’s great. And is Diplomat MFT sold through channels or direct?

Hoffer: It’s both. We have a wide array of partners across the globe that are certified and trained in helping customers understand the value and deploy the solutions. But the vast majority of what we do is direct. But we sell directly to anyone who’s interested, whether you are here in North America or Europe or Asia-Pac or whatever. But there are plenty of avenues where you can acquire Diplomat MFT. If you need the comfort of someone in your own time zone, then we have a partner there for you.

Miliefsky: And Greg, sometimes an organization is five employees, but they’ve got hundreds of thousands of records, and then there’s organizations with, you know, thousands of employees with millions of records. What’s the sweet spot for Diplomat MFT? How scalable is it on the downside for small organizations and on the upside, larger organizations?

Hoffer: Here again, we provide tremendous value in this marketplace. We have offerings all the way from a basic edition that can handle those smaller shops at a very reasonable price point, all the way up to large enterprise organizations that have multiple instances of our server to handle these vast loads of tens of thousands of transactions flowing every single day, with literally thousands of exchange partners that they transfer files to and from on a daily basis. So really what we like to say, we position our software so that regardless of your size, we have the right budget solution for you.

But it’s really the size of the problem that matters, not the size of the shop. So even if you’re a small ten-person shop only dealing with 10,000 records, if all of those 10,000 records are sensitive healthcare information, then you fall under that same compliance mandate that those large healthcare organizations do. And you are at risk for those very large penalties as well. You really need to consider a managed file transfer solution and not worry so much about how big am I or can I afford it? I promise you, you can afford it, especially when you consider the risks of fines.

Miliefsky: Absolutely. Greg, is there anything we haven’t covered that you’d like to share with our viewers and listeners? I know we’re going to save, you guys are mature. This is version 9.4 I believe. So we’ll save more details about the latest version, but you guys have been doing this for a long time. Anything else you want to share with our viewers and listeners?

Hoffer: No, I appreciate the conversation. I just want to emphasize that we are the best value managed file transfer solution, and we keep a finger on the pulse of the industry. And that’s again, another value we provide to organizations. Your IT shop might not be up to date on all the regulations and the proposed regulations, but that’s our job. We focus on this and try to stay in front of these regulations changes and the threats emerging in the security landscape, and so we do our dead level best to keep your information secure in all modern times.

Miliefsky: Absolutely. You heard it first here from Greg Hoffer, the CEO of Coviant Software found online at coviantsoftware.com. Folks get one step ahead of the latest threat. Get secure managed file transfer from his company. It’s one of the most mature, best solutions in the market. Easy to deploy, point and click, and you’ll get one step ahead of the bad guys who do want your files, because files means money to the criminals. And then come back next time for another exciting episode of Cyber Defense TV.