During SANS CTI Summit Solutions Track 2025, Microsoft’s Director of Threat Intelligence Strategy, Sherrod DeGrippo, discussed the growing ransomware threat and its impact on patient care. These discussions included the increasing sophistication of cyber threats, the rise of ransomware-as-a-service (RaaS), and the financial burden on healthcare institutions.
According to DeGrippo, the emergence of RaaS has significantly increased the accessibility of sophisticated ransomware tools, allowing cybercriminals to launch attacks with little expertise. Some of the most notable threat actors targeting healthcare include:
In 2024 alone, 389 healthcare institutions in the US suffered ransomware attacks, placing the industry among the top 10 most impacted sectors.
The report also indicates that the average cost of downtime due to ransomware is $900K per day, with IBM estimating the total financial impact per ransomware incident to be nearly $11 million.
Furthermore, a 2023 study on ransomware attacks associated with disruptions at adjacent emergency departments in the US found ransomware attacks directly impact patient health and survival rates. More specifically, the study revealed:
Healthcare organizations must develop an enterprise-wide cybersecurity strategy to combat the risk of ransomware attacks and improve their cyber defenses. Some of the actions include:
However, if in-house resources are limited, outsourcing cybersecurity expertise may be a viable solution to improve cyber defenses and protect patient lives.
Read also: HIPAA compliance in vulnerable communities
Ransomware is malicious software that encrypts a victim's data, with attackers demanding payment to restore access or prevent data leaks.
Affected individuals must monitor their financial accounts, change passwords, and use the identity theft protection services offered by the organization.
They can adopt measures like multi-factor authentication, regular audits, employee training, and advanced encryption methods to protect patient data.
Learn more: HIPAA Compliant Email: The Definitive Guide