• Skip to main content
  • Skip to secondary menu
  • Skip to primary sidebar
  • Skip to secondary sidebar
  • Skip to footer

  • Opinion
  • Health IT
    • Behavioral Health
    • Care Coordination
    • EMR/EHR
    • Interoperability
    • Patient Engagement
    • Population Health Management
    • Revenue Cycle Management
    • Social Determinants of Health
  • Digital Health
    • AI
    • Blockchain
    • Precision Medicine
    • Telehealth
    • Wearables
  • Life Sciences
  • Investments
  • M&A
  • Value-based Care
    • Accountable Care (ACOs)
    • Medicare Advantage

State of Ransomware in Healthcare 2025: Exploited Vulnerabilities Top Cause, Staff Capacity Biggest Weakness

by Fred Pennic 11/21/2025 Leave a Comment

  • LinkedIn
  • Twitter
  • Facebook
  • Email
  • Print

What You Should Know: 

– Sophos’s State of Ransomware in Healthcare 2025 report reveals exploited vulnerabilities are now the leading technical cause of attacks (33%). 

– The study highlights a sector becoming more resilient to encryption but facing soaring extortion-only attacks and high pressure on IT teams.

Root Causes Shift: Capacity Gaps and Exploited Vulnerabilities Lead

The latest Sophos study, based on the experiences of 292 healthcare providers, shows a significant shift in the technical and organizational root causes of ransomware attacks:

  • Top Technical Cause: For the first time in three years, exploited vulnerabilities emerged as the most common technical root cause, used in 33% of incidents.
  • Top Organizational Cause: The most common organizational factor contributing to attacks was a lack of people/capacity (i.e., insufficient cybersecurity experts monitoring systems), named by 42% of victims. This was closely followed by known security gaps (weaknesses organizations were aware of but had not addressed), cited in 41% of attacks.

Extortion Soars Despite Decline in Data Encryption

While healthcare organizations appear to be improving defenses against successful encryption, adversaries are adapting their tactics to exploit the sensitivity of medical data.

  • Encryption Decline: The data encryption rate dropped to its lowest level in five years, with only 34% of attacks resulting in data encryption, down from a 74% peak in 2024.
  • Extortion Triples: The proportion of healthcare providers hit by extortion-only attacks (where data was stolen but not encrypted) tripled to 12% of attacks in 2025.

Ransom Payments and Recovery Costs Plummet

The economics of healthcare ransomware shifted sharply, making the sector “a tougher environment” for cybercriminals to extract large payouts.

  • Ransom Demands: The average (median) ransom demand plummeted 91% over the last year, from $4 million in 2024 to just $343K in 2025.
  • Ransom Payments: The average (median) ransom paid dropped from $1.47 million to just $150K, the lowest payment reported across all surveyed industries.
  • Recovery Costs: The mean cost of recovery (excluding ransom) fell by 60% to $1.02 million (down from $2.57 million in 2024).

Human Toll and Recovery Resilience

Every healthcare provider that had data encrypted reported direct repercussions for the IT/cybersecurity team.

  • Pressure & Stress: 39% reported increased pressure from senior leaders, and 37% cited increased anxiety or stress about future attacks.
  • Recovery Speed: Healthcare providers are recovering faster, with 58% recovered within a week in 2025, nearly triple the 21% reported in 2024.
  • Backup Use Slips: Despite improved recovery speed, the use of backups to restore encrypted data has fallen to 51% (down from 72% in 2022)—suggesting possible weaknesses or a lack of confidence in backup resilience.

Click here for more information about the report

  • LinkedIn
  • Twitter
  • Facebook
  • Email
  • Print

Tagged With: Cybersecurity

Tap Native

Get in-depth healthcare technology analysis and commentary delivered straight to your email weekly

Reader Interactions

Primary Sidebar

Subscribe to HIT Consultant

Latest insightful articles delivered straight to your inbox weekly.

Submit a Tip or Pitch

2026 Predictions & Trends

Healthcare 2026 Forecast: Executives on AI Survival, Financial Reckoning, and the End of Point Solutions

2026 Healthcare Executive Predictions: Why the AI “Pilot Era” Is Officially Over

Most-Read

NYC Health + Hospitals to Acquire Maimonides in $2.2B Safety Net Overhaul

NYC Health + Hospitals to Acquire Maimonides in $2.2B Safety Net Overhaul

KLAS Report: Why Hospitals Are Choosing Efficiency Over 'Agentic' AI Hype in 2025

KLAS Report: Why Hospitals Are Choosing Efficiency Over ‘Agentic’ AI Hype in 2025

Advanced Primary Care 2026: Top 6 Investments for Health Systems According to Harvard Medical School

Advanced Primary Care 2026: Top 6 Investments for Health Systems According to Harvard Medical School

AI Nutrition Labels: The Key to Provider Adoption and Patient Trust?

AI Nutrition Labels: The Key to Provider Adoption and Patient Trust?

Kristen Hartsell, VP of Clinical Services, RedSail Technologies

The Pharmacy Closures Crisis: How Independent Pharmacies Are Fixing Pharmacy Deserts

HHS Launches 'OneHHS' AI Strategy to Integrate AI Across CDC, CMS, and FDA for Efficiency and Public Trust

HHS Launches ‘OneHHS’ AI Strategy to Integrate AI Across CDC, CMS, and FDA for Efficiency and Public Trust

From Overwhelmed to Optimized: How AI Agents Address Staffing Challenges and Burnout in Healthcare

From Overwhelmed to Optimized: How AI Agents Address Staffing Challenges and Burnout in Healthcare

The VBC Paradox: Why Hospitals Are Doubling Down on Value-Based Care While Revenue at Risk Lags

The VBC Paradox: Why Hospitals Are Doubling Down on Value-Based Care While Revenue at Risk Lags

Tebra Secures $250M to Challenge Legacy EHRs with AI-Powered Automation

Tebra Secures $250M to Challenge Legacy EHRs with AI-Powered Automation

AstraZeneca Selects Salesforce Agentforce Life Sciences to Deploy AI-Powered Global Customer Engagement

AstraZeneca Selects Salesforce Agentforce Life Sciences to Deploy AI-Powered Global Customer Engagement

Secondary Sidebar

Footer

Company

  • About Us
  • Advertise with Us
  • Reprints and Permissions
  • Op-Ed Submission Guidelines
  • Contact
  • Subscribe

Editorial Coverage

  • Opinion
  • Health IT
    • Care Coordination
    • EMR/EHR
    • Interoperability
    • Population Health Management
    • Revenue Cycle Management
  • Digital Health
    • Artificial Intelligence
    • Blockchain Tech
    • Precision Medicine
    • Telehealth
    • Wearables
  • Startups
  • Value-Based Care
    • Accountable Care
    • Medicare Advantage

Connect

Subscribe to HIT Consultant Media

Latest insightful articles delivered straight to your inbox weekly

Copyright © 2026. HIT Consultant Media. All Rights Reserved. Privacy Policy |