Part 6 of 6 · Chapter 1 of 4

Why Hospitals Are a Common Ransomware Target

Hospitals can't afford downtime the way most businesses can, which is exactly what makes them an attractive ransomware target. Walk through one attack scenario below and see how a handful of basic defenses stop most of them before they start.

Advanced9 min read

Most businesses hit by ransomware can wait a few days to pay or recover before real damage sets in. A hospital cannot — its systems control which patient gets which medication, right now — and that single difference is exactly why hospitals are one of the most common ransomware targets in existence.

Hospitals are a common ransomware target, and here's why

Ransomware works by locking an organisation out of its own systems until it pays. That threat only has teeth if the organisation cannot simply wait it out — and a hospital, unlike almost any other kind of business, cannot pause patient care for a week while IT rebuilds servers from backup. Attackers know this. It is exactly why healthcare gets targeted disproportionately relative to how much money actually flows through it.

What a single breach actually costs a hospital

Walk through what one real attack looks like, from the moment it lands to what stopping it would have required.

The basic defenses that stop most attacks

Key takeaways

  • Hospitals are a disproportionate ransomware target because they cannot pause patient care to wait out an attack the way most businesses can.
  • A single employee clicking one attachment can cascade into a hospital-wide shutdown by the next morning, postponing surgeries and diverting ambulances.
  • Staff training, network segmentation, and offline tested backups stop most of these attacks before they start, and none of the three are exotic.
  • What actually fails is not the technology — it's the ongoing discipline of maintaining these defenses when there's no urgent deadline forcing it.