A Sector Under Sustained Attack
Hospitals and direct care providers recorded 445 confirmed ransomware attacks in 2025, according to tracking research, with a further 191 attacks hitting healthcare-adjacent businesses like medical billing firms and pharmaceutical manufacturers - a category that rose sharply as attackers shifted toward softer, less-defended targets connected to the same patient data. Attacks on healthcare providers actually surged 50% in the final quarter of the year alone, reversing what had briefly looked like a decline. Some trackers put the year-over-year global increase in healthcare ransomware attacks at around 45%.
Why Hospitals Are Such Attractive Targets
Ransomware gangs target healthcare for a straightforward reason: hospitals cannot simply stop operating while systems are restored, which makes them far more likely to pay quickly. Patient records also combine financial, personal, and medical information in a single highly valuable package, making stolen data doubly profitable - useful both for extortion and for resale. Meanwhile, healthcare IT infrastructure is often a patchwork of legacy systems, medical devices that can't easily be patched, and third-party vendors, all of which expand the attack surface well beyond what a single hospital's security team can fully control.
The Human Cost, Not Just the Financial One
The financial numbers are large - healthcare remains the single most expensive sector for a data breach, averaging $7.42 million per incident. But the more serious cost is clinical. A 2024 ransomware attack on a UK laboratory services provider, Synnovis, caused widespread delays in blood-test results across London hospitals, and in June 2025 an NHS trust confirmed a patient's death was contributed to in part by those delays. This is not a hypothetical worst case - it's a documented instance of a cyberattack contributing directly to patient harm, and it illustrates why healthcare ransomware is treated as a patient-safety issue by regulators, not merely a data protection one.
How These Attacks Actually Unfold
Most healthcare ransomware attacks now use "double extortion" - attackers don't just encrypt hospital systems, they also steal data first and threaten to publish it regardless of whether the ransom is paid, applying pressure on two fronts at once. Confirmed attacks in 2025 exposed millions of patient records with an average ransom demand exceeding $500,000. Even when hospitals do pay, there is no guarantee data won't still leak or that systems will be fully restored - one of the reasons cybersecurity agencies in most countries now formally advise against paying.
What This Means If You're a Patient
There is little an individual patient can do to prevent a hospital-side breach, but it's worth knowing the signs: an unexpected notification about a data breach from a provider you've used, unusual account activity on health insurance portals, or unfamiliar medical bills, all warrant a quick check. More broadly, the trend is a reminder that healthcare providers - like any organisation holding sensitive data - are only as secure as their weakest connected vendor, which is precisely the gap ransomware groups have been exploiting most aggressively through 2025 and into 2026.