The alternative is massive investment in security, which would raise costs to insurers/patients, and introducing procedures that would slow down the speed of medical practice, which is already too slow. One example i've seen is the "medical system", a conglomerate of healthcare providers under one brand.
At a high level, the priority is simply to swallow up as many healthcare solutions as you can, to reduce cost and increase profit, and make healthcare process more seamless for the patients.
At a medium level, this means you have 50 different organizations connected to your network, and you may or may not have centralized control over any of them. You don't have the cash, time or resources to go in and overhaul all the networks. So you tell them all to connect through your central office and throw every single transparent filter or proxy at them to try to catch all the crap flying out the door (and there is a lot of it).
At a local level, doctors are already stymied by the complex process of providing care to patients. I've worked with them to try to find tailored solutions to speed up simple things like returning lab results. It's surprisingly difficult to improve on. Add new security procedures and their time shrinks even more, adding on top of all their existing procedure.
Healthcare is just always going to suck at security. The alternative is more costly and slower healthcare.