• /
  • Blog
  • /
  • Business
  • /
  • Ransomware in Healthcare: When Cyberattacks Become Patient Safety Incidents

Ransomware in Healthcare: When Cyberattacks Become Patient Safety Incidents

2 minutesBusiness
Sophia Barnett photoSB
Sophia Barnett

Technical Marketing Writer


Healthcare organizations face a much more serious ransomware threat than any other industry since their patients themselves can be collateral. For example, when systems go down in manufacturing, production gets delayed. But when systems go down in healthcare, patient care can be delayed, disrupted, or, in the worst cases, jeopardized. 

The healthcare sector has become a prime target for bad actors because they understand the urgency behind getting systems up and running, since patients’ lives can depend on it. The result is a growing threat that extends far beyond IT teams and security departments. 

In this article, we’ll discuss: 

  • What factors make the healthcare industry a prime ransomware target 

  • How a typical ransomware attack progresses from initial access to extortion 

  • How ransomware impacts patient care 

  • The role of reliable, immutable backups in restoring systems safely and quickly

Why healthcare is a top ransomware target 

According to HIPAA Journal, ransomware attacks in healthcare increased 278% between 2018 and 2023, while hacking and IT incidents now account for most healthcare data breaches. What fueled such an increase? A unique combination of risks that makes them particularly attractive to cybercriminals—an inability to have critical systems down for very long, highly sensitive data, and sprawling attack surfaces. 

Little tolerance for downtime 

Modern healthcare depends on digital systems. Electronic health records (EHRs), imaging platforms, pharmacy systems, laboratory services, scheduling applications, and communications tools all play a life-or-death role in daily operations. 

When ransomware encrypts these systems, hospitals and clinics cannot simply pause operations until the issue is resolved. Care must continue, often through slower manual processes that increase operational strain and the risk of transcription errors. 

Highly sensitive data 

Healthcare organizations store large volumes of protected health information (PHI), including patient medical history, insurance information, personal identifiers, billing records, and treatment data. 

Unlike a compromised password or credit card, medical information cannot easily be changed or replaced. As a result, healthcare records remain valuable to cybercriminals for fraud, identity theft, and extortion activities. 

Large and complex attack surfaces 

Healthcare environments often include: 

  • Legacy systems 

  • Specialized medical devices 

  • Third-party technology providers 

  • Billing partners 

  • Insurance partners 

  • Cloud-based healthcare applications 

This interconnected ecosystem creates more opportunities for attackers to gain access and move through networks. 

Comparitech researchers have also observed that ransomware groups are increasingly targeting organizations across the broader healthcare supply chain, including healthcare technology vendors, billing providers, and pharmaceutical organizations. 

How a ransomware attack typically unfolds 

While every incident is different, most healthcare ransomware attacks follow a similar pattern. 

Stage 1: initial access 

Attackers typically gain access through: 

  • Exploitation of software vulnerabilities 

  • Phishing emails 

  • Stolen credentials 

  • Third-party compromises 

 

According to Verizon's analysis of 1,492 healthcare security incidents, the leading attack vectors in healthcare were exploitation of vulnerabilities (20%), phishing attacks (14%), and stolen credentials (11%).  

Stage 2: reconnaissance and data theft 

Once inside the environment, attackers often spend days or weeks identifying critical systems, escalating privileges, and locating sensitive data. The Change Healthcare attackers followed this very pattern. They gained access to the environment on February 12, 2024, remained undetected for multiple days, and exfiltrated data before deploying ransomware, ultimately disrupting healthcare operations nationwide.  

Stage 3: encryption and disruption 

The attack enters its most visible phase when systems become encrypted and inaccessible. 

Affected systems may include: 

  • Electronic health records 

  • Scheduling systems 

  • Diagnostic imaging platforms 

  • Laboratory systems 

  • Billing applications 

  • Internal communications tools 

At this point, normal workflows can grind to a halt. 

Stage 4: extortion and recovery 

Following system disruption, attackers typically demand payment in exchange for decryption keys or guarantees that stolen data will not be released. 

However, paying a ransom does not guarantee a successful recovery. Organizations may still face prolonged restoration efforts, regulatory scrutiny, operational downtime, and reputational damage. 

This is why recovery readiness has become as important as prevention. 

The human impact of ransomware on healthcare 

Ransomware is often discussed in terms of downtime, financial losses, and breach notifications. Yet the greatest concern is its potential impact on people. 

When critical healthcare services become unavailable, the consequences are severe. 

Potential patient impacts 

A successful ransomware attack can result in: 

  • Delayed emergency care 

  • Postponed surgeries and procedures 

  • Delayed access to life-saving medications 

  • Ambulance diversions to other facilities 

  • Delayed diagnostic testing 

  • Disruptions to laboratory services 

  • Reduced access to patient histories and medical records 

  • Delays in cancer screenings and treatment plans 

  • Increased risk of documentation and medication errors when staff must rely on manual workflows 

  • Reduced healthcare access for patients in rural or underserved areas 

Increased mortality rates 

Beyond delayed procedures and disrupted workflows, ransomware attacks have been linked to measurable impacts on patient outcomes. Research cited in Halcyon's Ransomware: A Public Health Crisis white paper found that hospitals affected by ransomware experienced a roughly one-third increase in in-hospital mortality among Medicare patients. The researchers estimated that ransomware-related disruptions were associated with 42 to 67 additional Medicare patient deaths over a five-year period. 

Decreased patient admissions 

When critical systems become unavailable, hospitals may be forced to divert patients, postpone services, and operate through manual processes. Studies cited by Halcyon found that patient admissions dropped between 17% and 24% during the first week following a ransomware attack, reflecting the difficulty healthcare organizations face when electronic systems that support patient care are inaccessible. 

Lingering affects overtask hospital workers 

The effects of a ransomware attack often persist long after the initial outage. The average healthcare breach takes 279 days to identify and contain, requiring months of investigation, remediation, regulatory response, and operational recovery. This lengthy recovery timeline can place sustained strain on healthcare staff, IT teams, and administrative resources long after systems have been restored. 

Recovery depends on backup data that ransomware can't destroy 

The ability to recover is more valuable than the ability to negotiate. Attackers may provide decryption tools after payment, but recovery still remains a complex process. Systems must be restored, data integrity verified, applications restarted, and clinical workflows safely resumed. 

However, paying a ransom is not a guarantee that stolen data will be recovered or deleted. During the 2024 ransomware attack, Change Healthcare paid a $22 million ransom. However, the hackers—a BlackCat ransomware affiliate—retained copies of the stolen data and continued extortion efforts afterward under a different name, RansomHub.  

Relying on cybercriminals to honor their promises (providing decryption keys and deleting sensitive data) is not a recovery plan. A company's ability to recover backup data ultimately determines how quickly operations can be restored.  

Healthcare organizations need a recovery strategy built on certainty. If backup data can be altered, deleted, or encrypted, recovery becomes slower and more difficult. If backup data cannot be changed, organizations have a trusted starting point for restoring systems and returning services to normal. 

Object First's Ootbi appliances ensure Absolute Immutability, preventing backup data from being modified or deleted after it is written. That means healthcare organizations can focus on restoring patient-facing services, clinical applications, and business operations rather than worrying about whether their backup data survived the attack. And at the end of the day, this ensures the best outcomes for their patients’ well-being, too. 

Resilience matters as much as prevention. The organizations best positioned to withstand an attack are those that can quickly restore critical systems and continue caring for patients. Ransomware-proof backup data provides the foundation for that level of recovery.