Ransomware attacks on hospitals rose 49% in 2025, and two of the largest breaches on record followed

By Mark Brooks, VP Partnerships, Videolab

Ransomware attacks against healthcare organizations rose 49% year over year in 2025, according to BlackFog's 2025 State of Ransomware Report — and BlackFog's own data suggests the real number is higher still, since an estimated 86% of attacks are believed to go undisclosed entirely. The trend has already produced two of the largest healthcare data incidents on record: a February 2026 breach of medical software used by thousands of French doctors, exposing roughly 15.8 million patient records, and the Change Healthcare breach, now confirmed by the US Department of Health and Human Services at 192.7 million individuals.

Both point to the same shift. Cybersecurity failures in hospitals are no longer just IT incidents — they disrupt care directly. When a hospital loses access to its systems, diagnostics get delayed, pharmacy services stall, surgeries get cancelled, and emergency patients get diverted elsewhere. In a sector where time routinely determines outcomes, digital resilience and clinical resilience are the same thing.

Why hospitals remain exposed

Part of the reason is architectural. Hospital networks were largely built on the assumption that anything already inside the network could be trusted. Modern attacks are built entirely around exploiting that assumption — a single compromised credential can unlock systems far beyond where it was issued.

"Healthcare is digitizing faster than many institutions can secure it," says Dag Flachet, co-founder of Codific. "Every connected device, platform, or collaboration tool becomes another potential entry point for attackers. Security needs to evolve at the same pace as digital healthcare innovation.

"Many institutions still budget for cybersecurity as a compliance line item rather than a clinical one — despite operating thousands of connected devices, from infusion pumps to imaging systems, that make up a hospital's Internet of Medical Things. Many of those devices were never designed with security in mind and can't easily be patched.

What institutions can do now

Zero trust architecture is the starting point: verifying every user, device, and application at every interaction with sensitive systems, rather than trusting anything already inside the perimeter. Palo Alto Networks' 2025 Unit 42 Incident Response Report found IAM-related gaps contributing to 41% of the incidents it investigated — exactly the kind of lateral movement zero trust is designed to stop.

Recovery matters as much as prevention. Tested offline backups and disaster recovery protocols remove ransomware's core leverage, because the threat only works if paying is genuinely faster than restoring. And none of this holds if the vendors behind billing, scheduling, EHR, and telehealth platforms aren't held to the same standard — supply chain compromises don't stay contained to one vendor, they ripple across every institution that vendor serves.

The bottom line

Cyberattacks on hospitals are systemic risks now, not isolated technical incidents, and hospitals increasingly operate as digital infrastructure whether they've budgeted for it that way or not. Protecting patients means protecting the systems behind their care with the same seriousness as sterile equipment or trained staff — because increasingly, they're the same job.

Scroll to Top