Ransomware has become one of the most disruptive threats to hospital operations. When an attack lands, systems lock, records go dark, and care slows down. This page pulls together the current numbers on how often hospitals are attacked, what those attacks cost, how long systems stay down, and what happens to patients. Every figure is dated and attributed to the research that produced it, so you can check the year and the population behind any number before you quote it.
We are FaxSIPit, a HIPAA-compliant cloud fax platform used by hospitals and other regulated healthcare providers to move patient records, referrals, and prescriptions. We work with health systems on the document workflows that have to keep running when clinical systems do not, including the downtime procedures that take over during an outage. That is the vantage point this page is written from.
Key Takeaways
Hospitals are a primary target. More than 250 healthcare organizations were hit by ransomware in 2024, roughly 2.5 times the 2021 count, and Microsoft counted 389 affected US institutions in a single fiscal year.
Attacks harm patients, not just data. Among Medicare patients already admitted when an attack begins, in-hospital mortality rises 34% to 38%, and researchers tied 42 to 67 Medicare patient deaths to ransomware attacks over a five-year span.
Downtime is measured in weeks. Hospital patient volume drops 17% to 24% during the first week of an attack, and a healthcare breach now takes a global average of 279 days to identify and contain.
The economics are shifting. A healthcare data breach averages $7.42 million globally, the costliest of any industry for the 15th straight year, yet fewer providers worldwide are paying ransoms (36% in 2025, down from 61% in 2022).
The damage spreads outward. Neighboring hospitals that were never attacked see emergency-department strokes and ambulance arrivals surge when a nearby facility goes offline, a documented spillover effect.
Ransomware Attacks on Hospitals: The Big Picture
Ransomware attacks on hospitals now affect clinical outcomes, not just IT systems. Here are the headline numbers that frame the rest of this page.
389 US healthcare institutions were hit by ransomware in a single fiscal year, according to Microsoft Threat Intelligence, whose healthcare ransomware report published in October 2024. Microsoft counts on its own fiscal year, so this figure does not line up cleanly with the calendar-year counts below.
More than 250 healthcare organizations experienced ransomware attacks in 2024, about 2.5 times the 2021 figure and over five times the 2015 figure, per a Halcyon white paper on ransomware as a public health crisis.
181 confirmed ransomware attacks struck US healthcare providers in 2024, exposing 25.6 million patient records, per Comparitech's year-end healthcare analysis as reported by the HIPAA Journal.
A healthcare data breach costs $7.42 million on average, the most expensive of any industry, per the HIPAA Journal summary of IBM's global Cost of a Data Breach research.
Among Medicare patients already admitted to a hospital when a ransomware attack begins, in-hospital mortality increases by 34% to 38%, according to Medicare-claims research published in the American Economic Journal: Economic Policy (February 2026).
Ransomware attacks across all sectors have surged 300% since 2015, according to Microsoft Threat Intelligence, which attributes the growth to ransomware-as-a-service lowering the technical barrier to entry.
Downtime costs healthcare organizations up to $900,000 per day, a figure Microsoft Threat Intelligence cites from industry reporting in its October 2024 healthcare ransomware report.
An estimated 42 to 67 Medicare patients died as a result of ransomware attacks between 2016 and 2021, per the research team's estimate as reported by STAT News.
How Often Hospitals Get Hit
Healthcare is one of the most-targeted sectors for ransomware, and confirmed attacks on providers have risen year over year through 2024. The numbers below show the trend.

Confirmed ransomware attacks on US healthcare providers, 2022 to 2024. Source: Comparitech.
Ransomware grew from 0 healthcare breaches in 2010 to 31% of breaches (222 of 715) in 2021, then fell to 11% (61 of 566) in 2024, according to a study of HIPAA-covered entities published in JAMA Network Open in May 2025. The recent decline reflects both stronger defenses and a shift toward stealing data without encrypting systems.
Confirmed provider attacks climbed from 84 in 2022 to 143 in 2023, Comparitech found, part of a steady year-over-year rise that continued into 2024.
OCR reported a 264% increase in large breaches involving ransomware between 2018 and 2024, per an HHS Office for Civil Rights settlement announcement from October 2024.
Healthcare and public health ranked among the 10 most-impacted industries for ransomware in the second quarter of 2024, according to Microsoft Threat Intelligence.
The confirmed-attack count from a single consistent tracker shows the year-over-year rise clearly.
Year | Confirmed ransomware attacks on US healthcare providers (Comparitech) |
|---|---|
2022 | 84 |
2023 | 143 |
2024 | 181 |
These counts measure different things. Comparitech tracks confirmed attacks from public reporting and dark-web disclosure, which is why its totals run higher than counts drawn only from breaches formally reported to federal regulators. Read the trend within a series, not across them.
For the broader picture of every reported healthcare breach, not just ransomware, see our healthcare data breach statistics page, which tracks total records exposed and breach counts across all causes.
What Ransomware Costs Hospitals
Healthcare is the most expensive industry for data breaches, but the money story is shifting: breach costs are falling from their peak, and by 2025 fewer providers were paying ransoms. Survey findings differ by panel and year, so treat the direction as the signal rather than any single percentage. Here is where the dollars go.

A single day of ransomware downtime cost the average US healthcare organization about $1.9 million. Source: Comparitech.
Healthcare breach costs have fallen 32% from their 2023 peak, dropping from $10.93 million to $9.77 million to $7.42 million across IBM's three most recent Cost of a Data Breach reports.
A day of ransomware downtime cost the average US healthcare organization about $1.9 million, based on recovery costs disclosed by 15 attacked organizations, per Comparitech.
Applied across 2018 to 2024, that downtime totals an estimated $21.9 billion, across 654 attacks that compromised 88.8 million patient records, the same Comparitech analysis found.
Ransom demands to healthcare providers fell 91% to a median of $343,000 in 2025, down from about $4 million a year earlier, according to Sophos's global survey of healthcare organizations.
The median ransom actually paid by healthcare victims worldwide dropped to roughly $150,000 in 2025, Sophos found, and only 36% of providers paid at all, down from 61% in 2022.
Among organizations that did pay and disclosed the amount, the median payment was $1.5 million and the average was $4.4 million, Microsoft reported from a sample of 99 healthcare organizations.
Mean recovery cost worldwide, excluding any ransom, fell to $1.02 million in 2025, down about 60% from the year before, per Sophos.
The cost trend is clearest when you line up the three most recent annual breach-cost figures.
IBM Cost of a Data Breach Report | Average healthcare data breach cost |
|---|---|
2023 | $10.93 million |
2024 | $9.77 million |
2025 | $7.42 million |
How Long Systems Stay Down
The hardest part of a hospital ransomware attack is not the ransom, it is the weeks of disruption that follow. Staff revert to paper charts, electronic ordering stops, results turn up late, and ambulances get diverted to other hospitals. Nurses at Ascension told CNN the 2024 attack was "putting patients' lives in danger" as teams tracked medications on paper. The numbers below put a clock on that disruption.

How long a hospital ransomware attack disrupts operations. Sources: American Economic Journal: Economic Policy; IBM, via HIPAA Journal.
Hospital patient volume drops 17% to 24% during the first week of a ransomware attack, with recovery taking about three weeks, according to the Medicare-claims study published in the American Economic Journal: Economic Policy.
The global average time to identify and contain a healthcare breach was 279 days, about five weeks longer than the cross-industry average and the longest of any sector, per the HIPAA Journal's reporting on IBM data.
The Ascension attack disrupted care across roughly 140 hospitals, with projected costs between $1.1 billion and $1.6 billion, Comparitech reported, one of the largest US health-system outages on record.
The 2017 WannaCry outbreak forced UK hospitals to cancel about 19,000 appointments and disrupted at least 81 of 236 NHS trusts in England, each of which runs multiple hospitals and clinics, according to the American Hospital Association.
A February 2026 ransomware attack on the University of Mississippi Medical Center hit its Epic electronic health record system, closing clinics statewide and cancelling elective surgeries, while emergency services stayed open, as reported by the Mississippi Free Press.
How Ransomware Harms Patients
Ransomware attacks measurably raise in-hospital mortality and degrade emergency care, including at nearby hospitals that were never attacked. This is the clearest evidence that a hospital ransomware attack is a patient-safety event, not just a data problem.

Increases recorded at a neighboring emergency department that was never attacked. Source: JAMA Network Open.
Ransomware attacks on US health care delivery organizations more than doubled between 2016 and 2021, from 43 to 91 a year, and 44% disrupted care delivery, according to research in JAMA Health Forum. The study counted hospitals alongside clinics, laboratories, pharmacies, and emergency medical services.
61% of surveyed healthcare organizations experienced a ransomware attack, averaging five successful attacks each, according to the Ponemon Institute study on cyber insecurity in healthcare.
67% of organizations hit by ransomware said it negatively affected patient care, the Ponemon Institute found, and across all cyberattack types an average of 29% reported increased patient mortality.
At an emergency department next to an attacked hospital, stroke-code activations rose from 59 to 103, a 74.6% jump, according to a study in JAMA Network Open.
Confirmed strokes at that neighboring hospital rose 113.6%, from 22 to 47 cases, the same JAMA Network Open study found, as diverted patients overwhelmed unprepared staff.
Ambulance arrivals at the neighboring hospital increased 35.2% during the attack, JAMA Network Open reported, stretching emergency capacity at a facility that was never breached.
Cardiac-arrest cases surged 81% at neighboring hospitals during an attack, IBM reported on University of California San Diego research into the spillover effect.
The Synnovis attack on UK hospitals delayed blood tests, transfusions, cancer treatments, and elective procedures, IBM reported, showing how a single vendor compromise ripples across care.
How Attackers Get In
Most hospital ransomware traces back to a handful of entry points, and unpatched software leads the list. Knowing the vector matters because it shows where document and communication systems sit in the attack path.
Exploited software vulnerabilities were the most common technical root cause, used in 33% of healthcare ransomware attacks worldwide in 2025, Sophos reports.
The Change Healthcare attackers entered through a Citrix remote-access service that lacked multifactor authentication, per the HIPAA Journal's incident reporting, a single missing control behind the largest healthcare breach in US history.
Notable Hospital Ransomware Attacks
Two incidents show the scale of operational and financial fallout when ransomware hits a large health system or its lab partner.

Change Healthcare, 2024: the largest healthcare data breach on record, with weeks of nationwide billing and pharmacy disruption. Source: HIPAA Journal.
Change Healthcare (2024) was the largest healthcare data breach in US history, affecting an estimated 192.7 million people, with weeks of nationwide billing and pharmacy disruption, per the HIPAA Journal.
Synnovis / NHS (2024) delayed blood tests, transfusions, and cancer care across London hospitals, IBM reported.
Ransomware Reporting and Enforcement
Regulators are tracking the surge and settling more cases. OCR reported a 264% rise in large ransomware breaches between 2018 and 2024, and by April 2026 had completed 19 investigations arising from ransomware breaches.
HHS settled four ransomware investigations for a combined $1,165,000, affecting more than 427,000 individuals, according to the HHS Office for Civil Rights.
Covered entities must notify affected individuals within 60 days of discovering a breach, per HHS breach-notification rules. For the enforcement and penalty detail behind these cases, see our HIPAA violation statistics page.
Frequently Asked Questions
How common are ransomware attacks on hospitals?
Ransomware attacks on hospitals are common and frequent. More than 250 healthcare organizations experienced attacks in 2024 (Halcyon), Microsoft counted 389 affected US institutions in a single fiscal year per its October 2024 report, and Comparitech confirmed 181 US provider attacks exposing 25.6 million records that year. Healthcare has ranked among the most-targeted critical-infrastructure sectors for several years running.
How much does a hospital ransomware attack cost?
A healthcare data breach costs $7.42 million on average, the highest of any industry, per IBM's global research summarized by the HIPAA Journal. On top of that, downtime alone runs up to $900,000 per day for a healthcare organization (Microsoft, October 2024) and averaged $1.9 million per day across the US healthcare organizations Comparitech analyzed, and ransom demands to healthcare providers recently fell to a global median of $343,000 (Sophos).
Do ransomware attacks on hospitals kill patients?
Research links ransomware attacks to higher patient mortality. Among Medicare patients already admitted when an attack begins, in-hospital mortality rises 34% to 38%, roughly the difference between 3 in 100 and 4 in 100, according to Medicare-claims research in the American Economic Journal: Economic Policy. The same researchers estimated that ransomware attacks killed between 42 and 67 Medicare patients from 2016 to 2021. JAMA Network Open separately documented stroke and ambulance surges at neighboring hospitals.
How long do hospitals take to recover from ransomware?
Recovery stretches for weeks. Patient volume typically drops 17% to 24% during the first attack week and takes about three weeks to normalize (American Economic Journal: Economic Policy), while a healthcare breach takes a global average of 279 days to fully identify and contain (HIPAA Journal, on IBM data). Large attacks run longer: Ascension's disruption spanned roughly 140 hospitals.
Are ransomware attacks on hospitals increasing?
It depends on the measure. Confirmed provider attacks tracked by Comparitech rose from 84 in 2022 to 143 in 2023 to 181 in 2024. But ransomware's share of large healthcare breaches reported to regulators fell from 31% in 2021 to 11% in 2024 (JAMA Network Open), partly because more attackers now steal data without encrypting systems. Ransom economics moved the same direction: only 36% of healthcare victims worldwide paid in 2025, down from 61% in 2022 (Sophos). The volume of attacks is up; the classic encrypt-and-extort model is a smaller share of it.
The Bottom Line
Ransomware is now a patient-safety issue for hospitals, not just an IT problem. The data is consistent across independent sources: attacks raise in-hospital mortality among already-admitted patients, knock patient volume down for weeks, and cost millions per incident even as ransom payments decline. The real damage shows up in delayed care, diverted ambulances, and the manual workarounds staff fall back on when digital systems fail.
Those weeks of manual workaround are where downtime procedures earn their keep. Referrals, orders, and prescriptions still have to move, and the documented fallback in most health systems is fax. We run FaxSIPit as a HIPAA-compliant cloud fax platform: TLS-encrypted transmission on every fax, intelligent multi-carrier retry that reroutes automatically if one carrier path has trouble, and full audit trails that record every transmission for compliance review. It is one layer among many, and it is not a defense against ransomware. It is the layer that decides how well the paper-and-phone weeks actually go.
Related data lives on our healthcare cybersecurity statistics and healthcare downtime statistics pages. To see how we handle encrypted, HIPAA-compliant fax for healthcare, including BAA signing and audit trails, visit our HIPAA compliance page.
Sources
Comparitech: Ransomware Attacks on US Healthcare Organizations
HIPAA Journal: 2024 Was Another Bad Year for Healthcare Ransomware Attacks
American Economic Journal: Economic Policy, Ransomware Attacks on Hospitals
IBM: When Ransomware Kills, Attacks on Healthcare Facilities
JAMA Network Open: Ransomware Attacks and Data Breaches in US Health Care Systems (2025)
HHS Office for Civil Rights: Ransomware Breach Increase (October 2024)
HHS Office for Civil Rights: Ransomware Investigation Settlements
JAMA Health Forum: Ransomware Attacks and Healthcare Delivery
JAMA Network Open: Ransomware Disruptions at Adjacent Emergency Departments
American Hospital Association: Ransomware Attacks on Hospitals Have Changed
CNN: Nurses Say Ransomware Attack Is Stressing Hospital Operations











