Healthcare has become the most targeted sector in the global ransomware epidemic — and the stakes couldn't be higher. When a hospital's systems go dark, it isn't just data at risk. It's patient lives.

From cancelled surgeries and diverted ambulances to stolen medical records sold on the dark web, ransomware attacks on healthcare organisations have evolved from IT crises into genuine public health emergencies. Understanding the true scale of this threat — and what hospitals can do about it right now — is no longer optional. It's a matter of life and death.


The Scale of the Problem: Ransomware by the Numbers

The numbers are staggering, and they're getting worse.

In 2024, 67% of healthcare organisations worldwide experienced ransomware attacks, compared to just 34% in 2021.

That's a near-doubling in just three years, and the trend is accelerating.

Throughout 2025 alone, researchers recorded 445 ransomware attacks on hospitals, clinics, and other direct care providers.

The financial damage is equally alarming.

Healthcare data breaches cost an average of $7.42 million per incident in 2025, the highest of any industry for the 14th consecutive year, according to the IBM Cost of a Data Breach Report 2025.

And then there's the Change Healthcare catastrophe — the single most damaging healthcare cyberattack in history.

As of July 31, 2025, the U.S. Department of Health and Human Services confirmed that the Change Healthcare ransomware attack impacted approximately 192.7 million individuals — nearly two-thirds of the entire US population.

These aren't just abstract statistics. They represent breached diagnoses, stolen insurance details, and compromised social security numbers for millions of real patients.


Why Hospitals Are Such Attractive Targets

Cybercriminals are rational actors. They follow the money — and healthcare offers a uniquely profitable combination of vulnerabilities.

Extraordinarily Valuable Data

Electronic health records (EHRs) contain a wealth of personally identifiable information (PII) and protected health information (PHI), making them highly valuable targets for cybercriminals seeking to exploit this data for financial gain.

Beyond the immediate threat of ransomware, the comprehensive nature of EHRs makes them particularly appealing to cybercriminals — these records are a repository of personal information, encompassing everything from patient addresses and insurance details to social security numbers.

The Pressure to Pay

Healthcare organisations, under pressure to deliver uninterrupted life-saving patient care, often find themselves in a vulnerable position, making them more inclined to pay ransoms promptly.

Attackers know this. When a hospital can't access patient records, every minute of downtime is a clinical risk — and that urgency is exactly what ransomware groups exploit.

Legacy Systems and Expanding Attack Surfaces

Many healthcare providers still rely on legacy IT systems that lack vendor support and critical security updates. These outdated systems create easy entry points for criminals who exploit known vulnerabilities.

Add to this the explosion of connected medical devices, and the problem compounds rapidly.

The wide array of technologies that hospitals and healthcare providers rely on — from EHR systems to diagnostic equipment and interconnected devices within the Internet of Medical Things (IoMT) — enhance patient care and operational efficiency, but also introduce potential vulnerabilities.

Understaffed Security Teams

The most common contributing factor — cited in 42% of attacks — was a lack of people and capacity, as many healthcare organisations reported having an insufficient number of cybersecurity experts monitoring systems at the time of an attack.

This is closely followed by known security gaps, which were a factor in 41% of attacks, while exploited vulnerabilities were identified as the most common technical root cause, present in 33% of incidents.


The Real-World Impact on Patients

This is where the conversation shifts from cybersecurity to patient safety — and the data is deeply sobering.

Research found that in-hospital mortality increased 33% during ransomware incidents, equal to 42–67 preventable deaths over five years, with mortality rising from three in 100 Medicare patients to four in 100 under attack conditions.

Ransomware was the attack type most likely to result in longer lengths of stay (67%) and an increase in patients diverted or transferred to other facilities (50%).

Per Ponemon research, ransomware caused procedure or test delays at 64% of victim organisations, longer patient stays at 59%, increased patient transfers at 65%, and complications from medical procedures at 36%.

Ransomware attacks led to an average of nearly 19 days of downtime for U.S. healthcare organisations.

Nearly three weeks without functional digital systems in an environment where split-second decisions save lives.

Neighbouring hospitals absorb diverted patients, resulting in longer waits, more cardiac arrests, and higher stroke activations — and in rural areas, a single attack can cut off urgent care for entire communities.


How Modern Ransomware Attacks Work: The Double Extortion Model

Today's ransomware attacks have grown far more sophisticated than simply encrypting files and demanding payment to unlock them. Hospitals now face what security researchers call "double extortion."

A significant number of the reported hacks in 2024 and 2025 were ransomware attacks accompanied by data theft — a tactic known as double-layered extortion.

In practice, this means attackers steal sensitive patient data before deploying encryption, giving them two separate levers to demand payment: restore access to your systems, or we publish your patients' most private records online.

Attackers are increasingly focused on data extortion, or data theft, rather than encryption, with the percentage of providers that had their data extorted but not encrypted tripling since 2023 — the highest rate reported across sectors.

Exposure frequently begins with phishing, stolen credentials, or unpatched internet-facing systems, then spreads across flat networks to critical platforms such as EHR, imaging, and revenue cycle.

Qilin, INC Ransom, and RansomHub were among the most active threat actors against healthcare in 2025, with Akira, BianLian, LockBit, Play, SafePay, Medusa, and Rhysida also frequently implicated.

Third-party breaches comprised 40–45% of healthcare ransomware incidents in 2025

, meaning a hospital with excellent internal security can still be compromised through a vulnerable billing provider, cloud vendor, or medical device manufacturer.


Building a Defence: Core Cybersecurity Strategies for Hospitals

The good news is that there is a clear, evidence-based playbook for defending against ransomware. Here's what every hospital and healthcare organisation should be implementing today.

1. Zero Trust Architecture

The era of "trust everyone inside the firewall" is over.

Zero-trust architecture — a security approach that treats every access request as potentially dangerous regardless of source — has shifted from optional modernisation to essential defence for healthcare organisations in 2025.

This containment strategy can reduce ransomware spread by up to 70% by preventing lateral movement within your network.

The updated HIPAA Security Rule, published in December 2024, has eliminated the distinction between "required" and "addressable" specifications, making network segmentation and advanced cybersecurity measures mandatory for all healthcare organisations handling electronic protected health information (ePHI).

In practice, zero trust means enforcing multi-factor authentication on every access point, applying least-privilege access controls, and continuously verifying every user and device — inside or outside the network perimeter.

2. Network Segmentation

Implementing network segmentation limits an attacker's ability to move laterally once inside the system — for example, electronic health records, medical devices, and administrative systems should be placed in separate network zones with restricted access between them.

By dividing a network into sections, organisations can limit the spread of an attack. When a ransomware attack is detected in a segmented network, the organisation can quarantine a single segment without shutting down the entire network, allowing a large portion of the hospital's network to continue operating.

3. Robust, Tested Backups

One highly effective strategy is the use of secure, air-gapped backups — physically isolated from your organisation's network, meaning they remain secure even if hackers breach your infrastructure.

This matters enormously:

on average, only 64.8% of data is restored after paying a ransom, and just 2% of organisations that paid the ransom recovered all their data.

Paying ransoms is not a recovery strategy. Reliable, regularly tested, offline backups are.

4. Rigorous Third-Party Risk Management

With so many EHRs being exchanged among care providers, third parties, service lines and organisations, hospitals may have a murky understanding of where their data is, which third-party providers have access, and the volume of data they hold — making a strategic third-party risk management programme critical.

Vet EHR hosts and billing processors rigorously, as their breaches cascade to your practice, and include robust security clauses in vendor contracts while regularly auditing their compliance measures.

5. Staff Training and Phishing Simulation

Insufficient preparedness has made email phishing the leading entry point for cyberattacks, responsible for 63% of all access point breaches in 2024.

People are both the biggest vulnerability and the most powerful defence layer.

Phishing simulations expose employees to real-world scenarios without the risk, allowing them to practise their response to phishing attempts in a controlled environment — reinforcing training and increasing the likelihood that employees will recognise and respond appropriately to actual threats.


Practical Tips You Can Implement Right Now

Whether you're a CISO, IT manager, practice administrator, or clinical leader, here are concrete actions to start strengthening your organisation's ransomware defences immediately:

Verify every access request through multi-factor authentication, especially for remote staff and IoMT devices.

Regularly update software and operating systems with the latest vendor patches. The window between the discovery of a vulnerability and its exploitation by attackers can be incredibly short.

72% of providers used backups to regain access to data post-ransomware attack

— make sure yours are tested and recoverable.

Your plan should include clear communication protocols for staff, patients, and regulators, system isolation procedures to prevent attack spread, and recovery prioritisation based on critical patient care functions — with regular tabletop exercises to identify plan weaknesses.

Before you can protect against data theft, you need to figure out what exactly you need to protect.

Know where your ePHI lives, who touches it, and which vendors have access.

Real-time monitoring leveraging AI and machine learning can identify suspicious activities and automatically respond to threats — including flagging unusual user behaviour, compromised devices, or unauthorised access attempts.

A comprehensive HIPAA risk assessment helps identify vulnerabilities before attackers exploit them, providing a roadmap for security improvements.

Nearly 60% of providers now report recovering within one week — up from just 21% the previous year — which reflects real progress in preparedness and recovery planning.

Investment in prevention and recovery capability is what makes the difference.


The Regulatory Landscape Is Tightening

Healthcare organisations can no longer treat cybersecurity as optional.

The 2025 HIPAA Security Rule updates — representing the first major overhaul in over a decade — now elevate network segmentation from an "addressable" specification to a mandatory requirement, making microsegmentation a compliance necessity rather than just a best practice.

Failure to comply carries severe consequences: HIPAA violations, breach notification obligations, civil penalties, and — increasingly — litigation from affected patients.

Healthcare organisations with comprehensive cybersecurity measures reduce average breach costs by $200,000 to $600,000 compared to those with only basic protections.

The business case for investment is as clear as the moral one.


Conclusion: Protecting Patients Means Protecting Their Data

Ransomware in healthcare is no longer a niche cybersecurity problem — it is a patient safety crisis.

Protecting digital systems is now directly tied to protecting patient safety, trust, and continuity of care.

Every unpatched vulnerability, every unprotected login, every untrained employee is a potential door through which attackers can walk in, shut down systems, and put lives at risk.

The organisations that are winning this fight are those treating cybersecurity not as an IT checkbox but as a clinical priority — embedding it into governance, operations, vendor relationships, and staff culture at every level.

Is your organisation truly prepared? Now is the time to audit your defences, review your incident response plan, and close the gaps before attackers find them. Partner with experienced healthcare cybersecurity professionals, conduct a thorough HIPAA risk assessment, and start building the resilient, zero-trust infrastructure that modern patient care demands. The next attack won't announce itself — but your response to it starts today.