• Skip to main content
  • Skip to secondary menu
  • Skip to primary sidebar
  • Skip to secondary sidebar
  • Skip to footer

  • Opinion
  • Health IT
    • Behavioral Health
    • Care Coordination
    • EMR/EHR
    • Interoperability
    • Patient Engagement
    • Population Health Management
    • Revenue Cycle Management
    • Social Determinants of Health
  • Digital Health
    • AI
    • Blockchain
    • Precision Medicine
    • Telehealth
    • Wearables
  • Life Sciences
  • Investments
  • M&A
  • Value-based Care
    • Accountable Care (ACOs)
    • Medicare Advantage

State of Ransomware in Healthcare 2025: Exploited Vulnerabilities Top Cause, Staff Capacity Biggest Weakness

by Fred Pennic 11/21/2025 Leave a Comment

  • LinkedIn
  • Twitter
  • Facebook
  • Email
  • Print

What You Should Know: 

– Sophos’s State of Ransomware in Healthcare 2025 report reveals exploited vulnerabilities are now the leading technical cause of attacks (33%). 

– The study highlights a sector becoming more resilient to encryption but facing soaring extortion-only attacks and high pressure on IT teams.

Root Causes Shift: Capacity Gaps and Exploited Vulnerabilities Lead

The latest Sophos study, based on the experiences of 292 healthcare providers, shows a significant shift in the technical and organizational root causes of ransomware attacks:

  • Top Technical Cause: For the first time in three years, exploited vulnerabilities emerged as the most common technical root cause, used in 33% of incidents.
  • Top Organizational Cause: The most common organizational factor contributing to attacks was a lack of people/capacity (i.e., insufficient cybersecurity experts monitoring systems), named by 42% of victims. This was closely followed by known security gaps (weaknesses organizations were aware of but had not addressed), cited in 41% of attacks.

Extortion Soars Despite Decline in Data Encryption

While healthcare organizations appear to be improving defenses against successful encryption, adversaries are adapting their tactics to exploit the sensitivity of medical data.

  • Encryption Decline: The data encryption rate dropped to its lowest level in five years, with only 34% of attacks resulting in data encryption, down from a 74% peak in 2024.
  • Extortion Triples: The proportion of healthcare providers hit by extortion-only attacks (where data was stolen but not encrypted) tripled to 12% of attacks in 2025.

Ransom Payments and Recovery Costs Plummet

The economics of healthcare ransomware shifted sharply, making the sector “a tougher environment” for cybercriminals to extract large payouts.

  • Ransom Demands: The average (median) ransom demand plummeted 91% over the last year, from $4 million in 2024 to just $343K in 2025.
  • Ransom Payments: The average (median) ransom paid dropped from $1.47 million to just $150K, the lowest payment reported across all surveyed industries.
  • Recovery Costs: The mean cost of recovery (excluding ransom) fell by 60% to $1.02 million (down from $2.57 million in 2024).

Human Toll and Recovery Resilience

Every healthcare provider that had data encrypted reported direct repercussions for the IT/cybersecurity team.

  • Pressure & Stress: 39% reported increased pressure from senior leaders, and 37% cited increased anxiety or stress about future attacks.
  • Recovery Speed: Healthcare providers are recovering faster, with 58% recovered within a week in 2025, nearly triple the 21% reported in 2024.
  • Backup Use Slips: Despite improved recovery speed, the use of backups to restore encrypted data has fallen to 51% (down from 72% in 2022)—suggesting possible weaknesses or a lack of confidence in backup resilience.

Click here for more information about the report

  • LinkedIn
  • Twitter
  • Facebook
  • Email
  • Print

Tagged With: Cybersecurity

Tap Native

Get in-depth healthcare technology analysis and commentary delivered straight to your email weekly

Reader Interactions

Primary Sidebar

Subscribe to HIT Consultant

Latest insightful articles delivered straight to your inbox weekly.

Submit a Tip or Pitch

Featured Research Report

2026 Best in KLAS Awards: The Full List of Software & Services Winners

Most-Read

The "Platform" Squeeze: Epic Releases Native AI Charting, Putting Venture-Backed Scribes on Notice

The “Platform” Squeeze: Epic Releases Native AI Charting, Putting Venture-Backed Scribes on Notice

Analysis: Oracle Cerner’s Plans for a National EHR

Oracle May Cut 30k Jobs and Sell Cerner to Fund $156B OpenAI Deal

The $1.9B Exit: Why CommonSpirit is Insourcing Revenue Cycle and Tenet is Betting Big on Conifer AI

The $1.9B Exit: Why CommonSpirit is Insourcing Revenue Cycle and Tenet is Betting Big on Conifer AI

KLAS 2026 Rankings: Aledade and Guidehealth Named Top VBC Enablement Firms

KLAS 2026 Rankings: Aledade and Guidehealth Named Top VBC Enablement Firms

Beyond the Hype: New KLAS Data Validates the Financial and Clinical ROI of Ambient AI

Beyond the Hype: New KLAS Data Validates the Financial and Clinical ROI of Ambient AI

Anthropic Debuts ‘Claude for Healthcare’ and Opus 4.5 to Engineer the Future of Life Sciences

Anthropic Debuts ‘Claude for Healthcare’ and Opus 4.5 to Engineer the Future of Life Sciences

OpenAI Debuts ChatGPT Health: A ‘Digital Front Door’ That Connects Medical Records to Agentic AI

OpenAI Debuts ChatGPT Health: A ‘Digital Front Door’ That Connects Medical Records to Agentic AI

From Genes to Hackers: The Hidden Cybersecurity Risks in Life Sciences

From Genes to Hackers: The Hidden Cybersecurity Risks in Life Sciences

Utah Becomes First State to Approve AI System for Prescription Renewals

Utah Becomes First State to Approve AI System for Prescription Renewals

NYC Health + Hospitals to Acquire Maimonides in $2.2B Safety Net Overhaul

NYC Health + Hospitals to Acquire Maimonides in $2.2B Safety Net Overhaul

Secondary Sidebar

Footer

Company

  • About Us
  • 2026 Editorial Calendar
  • Advertise with Us
  • Reprints and Permissions
  • Op-Ed Submission Guidelines
  • Contact
  • Subscribe

Editorial Coverage

  • Opinion
  • Health IT
    • Care Coordination
    • EMR/EHR
    • Interoperability
    • Population Health Management
    • Revenue Cycle Management
  • Digital Health
    • Artificial Intelligence
    • Blockchain Tech
    • Precision Medicine
    • Telehealth
    • Wearables
  • Startups
  • Value-Based Care
    • Accountable Care
    • Medicare Advantage

Connect

Subscribe to HIT Consultant Media

Latest insightful articles delivered straight to your inbox weekly

Copyright © 2026. HIT Consultant Media. All Rights Reserved. Privacy Policy |