Ransomware attacks are declining in many sectors, but not in healthcare, where there has been a sustained increase. According to a new research report by security company Sophos, incidents in healthcare have reached a 4-year high.
Important findings
- 66% of health organizations surveyed reported ransomware attacks last year.
- The average recovery time after an attack exceeds 1 month for 37% of organisations.
- 74% of attacks resulted in data encryption.
- Ransomware payments are often supported by insurance providers.
Rise of Ransomware Attacks in Healthcare
According to the Sophos survey of 5,000 IT leaders from 15 sectors and 14 countries between January and February, 2 thirds of the 402 healthcare organisations surveyed suffered a ransomware attack in the previous year. This is an increase from 60% in 2023. By comparison, the proportion of respondents across all sectors affected by ransomware attacks fell to 59%, from 66% in 2023.
Extended recovery times
Healthcare organisations are taking longer to recover from ransomware attacks. 37% of respondents said they needed more than 1 month to recover, up from 28% in 2023. Only 22% of healthcare organisations reported a full recovery within 1 week, a significant decline from 47% in 2023 and 54% in 2022.
Causes and effects
The increasing severity and complexity of attacks are factors in the longer recovery times. John Shier, Field CTO at Sophos, explained that the possibility of affecting patient care is a big concern. In the past, some ransomware groups had a “red line” against attacks on healthcare, but this rule was abandoned by many gangs, especially Russian cybercriminals, after the Ukraine war.
Data Encryption and Ransomware Payments
About 74% of ransomware attacks on healthcare organizations resulted in data encryption, which is almost the same level of encryption as in 2023, but higher than the global average of 70%. 25% of respondents said their attacks were stopped before data could be encrypted. In 22% of cases where data was encrypted, data was also stolen, an improvement from 37% in the previous year.
Ransomware Payments and Insurance Support
In healthcare, 39% of ransomware payments were supported by insurance providers, either directly or through an appointed incident-response specialist. The median ransom demand was $4.4 million when backups were compromised, compared with $1.3 million when they were not.
Conclusion
The current healthcare situation requires urgent action to improve cyber security. Patching vulnerabilities and using multifactor authentication are critical to preventing attacks. Nevertheless, there is resistance to measures that could hinder the rapid access of clinicians to key patient systems. It is important to make architectural considerations to ensure that threat actors cannot access critical systems.
Sources
- Sophos: Attacks Drop in Nearly All Sectors But Healthcare, BankInfoSecurity.



