Healthcare Ransomware: The $10.9M Breach and How to Prevent the Next One
Published by the 0g0 research team
The average cost of a healthcare data breach reached $10.9 million in 2024, according to IBM's Cost of a Data Breach Report — the highest of any industry for the 14th consecutive year. But for hospitals and health systems, the financial cost is only part of the story. When ransomware takes a hospital system offline, the consequences are measured not just in dollars but in patient outcomes: delayed surgeries, diverted ambulances, and in documented cases, patient deaths directly attributable to degraded care during a cyber incident.
Healthcare cybersecurity is a matter of public health. Understanding why healthcare is uniquely vulnerable — and what effective defence looks like — is essential for every healthcare executive, security officer, and board member.
Why Healthcare Is the Most Targeted Sector
The healthcare sector's vulnerability to ransomware stems from a combination of factors that are individually challenging and collectively devastating:
Life-critical operations: Unlike most businesses, hospitals cannot simply pause operations while dealing with a cyber incident. Emergency departments must continue operating. ICUs cannot go offline. This creates enormous pressure to pay ransom demands quickly to restore systems, making healthcare organisations statistically more likely to pay than organisations in other sectors.
High-value data: A complete patient health record sells for $250-$1,000 on criminal markets — more than 40 times the value of a credit card number. Medical records contain the full constellation of information needed for identity theft, insurance fraud, and targeted social engineering: name, address, Social Security number, insurance details, and comprehensive personal history.
Medical device attack surface: Modern healthcare environments are filled with networked medical devices — patient monitors, infusion pumps, imaging systems, laboratory equipment — that run embedded software that is rarely updated, often running operating systems years past end-of-life, and directly connected to clinical networks. These devices represent an enormous and largely undefended attack surface.
Connectivity requirements: Healthcare organisations must share patient data with a complex ecosystem of partners: insurance companies, specialist clinics, pharmacies, laboratories, public health agencies. This interconnectivity creates multiple entry points that attackers can exploit.
Budget constraints: Despite being the most targeted sector by data breach cost, healthcare organisations consistently underinvest in cybersecurity relative to their risk profile. The capital requirements of clinical equipment, facility costs, and staffing leave security budgets chronically underfunded.
The Anatomy of a Healthcare Ransomware Attack
The 2024 attack on Change Healthcare — a subsidiary of UnitedHealth Group that processes approximately 40% of US medical insurance claims — illustrates the catastrophic potential of a healthcare ransomware incident. The attack took the company's payment processing systems offline for weeks, causing an estimated $870 million in direct losses, disrupting insurance payments to hospitals and pharmacies across the country, and forcing thousands of healthcare providers to operate without insurance verification or electronic prescription processing.
The attack began with compromised credentials — a username and password obtained through unknown means (likely credential stuffing using data from a prior breach) used to access a Citrix remote access portal that did not have multi-factor authentication enabled.
From that single initial access, attackers moved laterally through the network over days, identifying the systems of highest value and establishing the persistence mechanisms needed to deploy their ransomware payload simultaneously across all targeted systems.
The technical entry point — a missing MFA control on a single system — cost the healthcare sector billions of dollars and disrupted patient care nationwide.
HIPAA Compliance vs. Actual Security
A persistent misconception in healthcare is that HIPAA compliance equals security. It does not. HIPAA's Security Rule establishes minimum standards for protecting electronic Protected Health Information (ePHI) that are necessary but far from sufficient for the current threat landscape.
HIPAA was written in 1996 and last substantially updated in 2013. Its requirements reflect the threat landscape of those periods, not the nation-state actors, ransomware-as-a-service operations, and sophisticated criminal networks that target healthcare in 2025. An organisation can pass a HIPAA audit while remaining profoundly vulnerable to modern cyberattacks.
Effective healthcare cybersecurity requires HIPAA compliance as a baseline, supplemented by:
- Continuous 24/7 monitoring of all networked systems
- Medical device security programme
- Regular penetration testing and red team exercises
- Tested incident response plans specific to clinical operations
- Staff training that goes beyond annual checkbox compliance
- Vendor and supply chain security assessment
Medical Device Security: The Invisible Attack Surface
Medical devices represent perhaps the most underappreciated cybersecurity risk in healthcare. A typical 500-bed hospital has between 5,000 and 10,000 networked medical devices. These devices share several security characteristics that make them uniquely vulnerable:
Long operational lifetimes: Medical devices are expensive capital equipment operated for 10-15 years or more. A device purchased in 2015 running Windows 7 Embedded is still operating in hospitals today — on a version of Windows that has not received security patches since 2020.
FDA regulatory constraints: Medical device software cannot be updated without FDA clearance, which can take months. This means that even when vulnerabilities are discovered and patches are developed, hospitals may be unable to deploy them promptly.
Direct patient connection: Compromised medical devices do not just represent a data breach risk. An attacker with control of an infusion pump, patient monitor, or implanted device has potential access to direct patient harm — a threat vector that has moved from theoretical to operationally demonstrated.
Flat networks: Many hospital networks place medical devices on the same flat network as administrative systems, meaning that a compromised administrative workstation provides direct access to medical device communications.
Effective medical device security requires network segmentation that isolates clinical systems, device inventory and vulnerability management, and monitoring for anomalous device behaviour — medical devices have very predictable communication patterns, and deviations from those patterns are highly detectable.
Building Effective Healthcare Cybersecurity
The healthcare organisations that successfully defend against ransomware share these characteristics:
Robust identity and access management, including MFA for all remote access — the single most impactful control based on the attack vectors that actually succeed against healthcare targets.
Network segmentation that isolates clinical systems, medical devices, and administrative networks from each other and controls the communications between them.
24/7 monitoring with healthcare-specific threat intelligence that understands clinical workflows and can distinguish normal from anomalous behaviour in clinical environments.
Tested incident response plans that address the specific operational continuity requirements of clinical settings — including manual backup procedures for clinical operations and pre-agreed patient diversion protocols with partner facilities.
Regular penetration testing and vulnerability assessment across the full scope of the healthcare environment, including medical devices and vendor-connected systems.
0g0 Aegis provides healthcare cybersecurity services that integrate security requirements with clinical operational realities. Our team understands that the patient care mission cannot be compromised by security implementations, and we design security programmes that protect clinical systems without disrupting care delivery. We work with hospital systems, outpatient networks, and public health agencies to implement the HIPAA-and-beyond security posture that today's threat landscape demands.
Need a product briefing?
Talk about the 0g0 Appliance for your environment — available now. Services are light support as the practice grows.
Request a BriefingFree Assessment Tools
Test your own security posture with our free tools — no account required.
Explore free toolsProtect your organisation
Request a briefing on the 0g0 Appliance. Research is context — the product conversation is next.
Request a Briefing