Immune — Self Heal, an iStudio Technologies product
Industry Analysis14 Aug 2026 · 5 min read

Healthcare ransomware by the numbers: what 2025 and early 2026 tell us

The headline numbers on healthcare ransomware can feel numbing after a while. But read together, the 2025 and early-2026 figures tell a coherent story: the volume isn't easing, the breaches are getting bigger, and the economics are shifting under attackers' feet.

By Immune Threat Research

Attack volume stayed high

Independent tracking recorded 445 ransomware attacks on hospitals, clinics, and other direct-care providers across 2025, according to Comparitech's roundup — roughly level with the prior year rather than declining. Separate reporting put the surge in recorded healthcare attacks at around 30% for the year.

Early 2026 offered no relief. Comparitech counted 410 healthcare ransomware attacks worldwide in the first half of 2026, up nearly 14% on the second half of 2025, as reported by Becker's. Whatever dip some quarters showed, the trend line has not bent downward.

Breaches hit a record

The exposure side broke records. A HIPAA Journal analysis of federal data found the HHS Office for Civil Rights logged at least 772 large healthcare data breaches in 2025 — those affecting 500 or more individuals — edging past the previous high. UpGuard's tracking put the number of individuals affected at roughly 138.5 million, an average of about two breaches a day.

Fewer victims are paying

The economics are moving. The share of healthcare victims paying a ransom fell to about 36% in 2025, down from 61% in 2022, per figures compiled from industry research. Payments dipped sharply mid-year as more organizations refused or negotiated hard.

That is encouraging, but it comes with a caveat: attackers respond to falling payment rates by leaning harder on data-theft extortion and by deliberately maximizing disruption to force a decision. Not paying is the right long-term posture — but only if you can actually keep operating and recover without the key.

What the numbers mean for security leaders

The cost of getting this wrong remains enormous — healthcare has been the most expensive sector for data breaches for years running, with averages well above seven figures. But the shift away from paying points to the real lever: resilience. The organizations that can refuse to pay are the ones that can detect fast, contain the spread, and restore clean systems on their own.

That is exactly what Immune is built to deliver — detection in seconds, containment before an intrusion becomes a hospital-wide outage, and self-healing recovery from immutable backups. The goal is to make not paying a safe operational choice, not a gamble.

Sources

Figures are drawn from the cited sources and were current as of publication. Content was rephrased for compliance with source licensing.

Turn this threat intelligence into resilience

See how Immune detects ransomware in seconds, contains it before it spreads, and self-heals clinical systems — whatever group is behind the next attack.

Talk to us

See Immune protect your organization

Tell us about your environment and our team will show you exactly how Immune detects, contains, and self-heals through a ransomware attack — including the connected devices your current tools can't reach. We respond within one business day.

  • A working demo on a realistic scenario
  • Agentless coverage for medical and connected devices
  • On-premises and data-sovereignty deployment options
  • A frank look at where Immune fits alongside your stack

Request your demo

Tell us a little about your organization and we'll be in touch.

By submitting, you agree to be contacted about Immune. We respect your privacy and never share your details. See our privacy policy.