They are done by medical professionals who have no obligation or incentive to serve the best interests of the patient. If your doctor fucks up, he can be found liable. If the insurance doctor fucks up, there is no liability whatsoever. Cases have been brought to court and then immediately thrown out because there is no legal basis for holding them accountable.
It’s also not as easy to hack electronic systems anymore. It’s not that they are invulnerable, but the vulnerabilities are generally more complicated and difficult to exploit. Setting aside people still running Windows XP or something, vulnerabilities get patched pretty quickly today. State actors have the time and resources to still do straight up electronic hacking, but opportunities for individuals are sparse.
Of course there is still the human element. Most data breaches done by individuals nowadays rely, at least in part, on social engineering.