• Skip to main content
  • Skip to secondary menu
  • Skip to primary sidebar
  • Skip to secondary sidebar
  • Skip to footer

ecw Leaderboard Ad
  • Opinion
  • Health IT
    • Behavioral Health
    • Care Coordination
    • EMR/EHR
    • Interoperability
    • Patient Engagement
    • Population Health Management
    • Revenue Cycle Management
    • Social Determinants of Health
  • Digital Health
    • AI
    • Blockchain
    • Precision Medicine
    • Telehealth
    • Wearables
  • Life Sciences
  • Investments
  • M&A
  • Value-based Care
    • Accountable Care (ACOs)
    • Medicare Advantage

State of Ransomware in Healthcare 2025: Exploited Vulnerabilities Top Cause, Staff Capacity Biggest Weakness

by Fred Pennic 11/21/2025 Leave a Comment

  • LinkedIn
  • Twitter
  • Facebook
  • Email
  • Print

What You Should Know: 

– Sophos’s State of Ransomware in Healthcare 2025 report reveals exploited vulnerabilities are now the leading technical cause of attacks (33%). 

– The study highlights a sector becoming more resilient to encryption but facing soaring extortion-only attacks and high pressure on IT teams.

Root Causes Shift: Capacity Gaps and Exploited Vulnerabilities Lead

The latest Sophos study, based on the experiences of 292 healthcare providers, shows a significant shift in the technical and organizational root causes of ransomware attacks:

  • Top Technical Cause: For the first time in three years, exploited vulnerabilities emerged as the most common technical root cause, used in 33% of incidents.
  • Top Organizational Cause: The most common organizational factor contributing to attacks was a lack of people/capacity (i.e., insufficient cybersecurity experts monitoring systems), named by 42% of victims. This was closely followed by known security gaps (weaknesses organizations were aware of but had not addressed), cited in 41% of attacks.

Extortion Soars Despite Decline in Data Encryption

While healthcare organizations appear to be improving defenses against successful encryption, adversaries are adapting their tactics to exploit the sensitivity of medical data.

  • Encryption Decline: The data encryption rate dropped to its lowest level in five years, with only 34% of attacks resulting in data encryption, down from a 74% peak in 2024.
  • Extortion Triples: The proportion of healthcare providers hit by extortion-only attacks (where data was stolen but not encrypted) tripled to 12% of attacks in 2025.

Ransom Payments and Recovery Costs Plummet

The economics of healthcare ransomware shifted sharply, making the sector “a tougher environment” for cybercriminals to extract large payouts.

  • Ransom Demands: The average (median) ransom demand plummeted 91% over the last year, from $4 million in 2024 to just $343K in 2025.
  • Ransom Payments: The average (median) ransom paid dropped from $1.47 million to just $150K, the lowest payment reported across all surveyed industries.
  • Recovery Costs: The mean cost of recovery (excluding ransom) fell by 60% to $1.02 million (down from $2.57 million in 2024).

Human Toll and Recovery Resilience

Every healthcare provider that had data encrypted reported direct repercussions for the IT/cybersecurity team.

  • Pressure & Stress: 39% reported increased pressure from senior leaders, and 37% cited increased anxiety or stress about future attacks.
  • Recovery Speed: Healthcare providers are recovering faster, with 58% recovered within a week in 2025, nearly triple the 21% reported in 2024.
  • Backup Use Slips: Despite improved recovery speed, the use of backups to restore encrypted data has fallen to 51% (down from 72% in 2022)—suggesting possible weaknesses or a lack of confidence in backup resilience.

Click here for more information about the report

  • LinkedIn
  • Twitter
  • Facebook
  • Email
  • Print

Tagged With: Cybersecurity

Tap Native

Get in-depth healthcare technology analysis and commentary delivered straight to your email weekly

Reader Interactions

Primary Sidebar

Subscribe to HIT Consultant

Latest insightful articles delivered straight to your inbox weekly.

Submit a Tip or Pitch

Featured Interview

ConcertAI VP Shares View on AI Hallucinations and the Fabricated Data Crisis in Scientific Publishing

Most-Read

GE HealthCare Acquires Intelerad for $2.3B to Create Cloud-First, AI-Enabled Imaging Ecosystem

GE HealthCare Acquires Intelerad for $2.3B to Create Cloud-First, AI-Enabled Imaging Ecosystem

Humana Partners with Sunrise to Expand Digital Sleep Apnea Diagnostics

Humana and Epic Launch Coverage Finder to Deliver Digital-First Medicare Advantage Check-In

Cleveland Clinic and Khosla Ventures Form Strategic Alliance to Accelerate Healthcare Innovation

Cleveland Clinic and Khosla Ventures Form Strategic Alliance to Accelerate Healthcare Innovation

Northwell Health Selects to Deploy Abridge’s Ambient AI Across 28 Hospitals

Northwell Health to Deploy Abridge’s Ambient AI Across 28 Hospitals

Omada Health Launches "Nutritional Intelligence" with AI Agent OmadaSpark

Omada Health Launches AI-Powered Meal Map to Transform Nutrition for Cardiometabolic Patients

From Overwhelmed to Optimized: How AI Agents Address Staffing Challenges and Burnout in Healthcare

From Overwhelmed to Optimized: How AI Agents Address Staffing Challenges and Burnout in Healthcare

Qualtrics Acquires Press Ganey Forsta for $6.75B to Create the Most Comprehensive AI Experience Platform

Qualtrics Acquires Press Ganey Forsta for $6.75B to Create the Most Comprehensive AI Experience Platform

Pfizer and Trump Administration Announce Landmark Agreement to Lower Drug Costs

Pfizer and Trump Administration Announce Landmark Agreement to Lower Drug Costs

KLAS Report: Epic's Native Ambient Speech Tool Reshapes Customer AI Strategies

KLAS Report: Epic’s Native Ambient Speech Tool Reshapes Customer AI Strategies

Epic Unveils MyChart Central and New APIs to Advance Interoperability at Open@Epic

Epic Outlines Roadmap for Next-Generation Data Sharing at Open@Epic

Secondary Sidebar

Footer

Company

  • About Us
  • Advertise with Us
  • Reprints and Permissions
  • Op-Ed Submission Guidelines
  • Contact
  • Subscribe

Editorial Coverage

  • Opinion
  • Health IT
    • Care Coordination
    • EMR/EHR
    • Interoperability
    • Population Health Management
    • Revenue Cycle Management
  • Digital Health
    • Artificial Intelligence
    • Blockchain Tech
    • Precision Medicine
    • Telehealth
    • Wearables
  • Startups
  • Value-Based Care
    • Accountable Care
    • Medicare Advantage

Connect

Subscribe to HIT Consultant Media

Latest insightful articles delivered straight to your inbox weekly

Copyright © 2025. HIT Consultant Media. All Rights Reserved. Privacy Policy |