Quick Summary
The Securityish Brief
In 2025, PIH Health Hospitals in California faced a ransomware attack that locked their systems, impacting over 3 million patients. This attack is part of a troubling trend, as healthcare is the most targeted industry for ransomware, with 40-45% of all breaches involving this type of attack. The average cost of a breach in healthcare is $4.44 million, highlighting the financial implications of these incidents.
Several notable breaches occurred in 2025, including SimonMed Imaging, which affected 1.27 million patients, and Anne Arundel Dermatology, which had a second breach impacting 1.9 million individuals. These incidents not only disrupt services but also compromise sensitive patient data, including names, addresses, medical records, and insurance information.
Why Healthcare is Ransomware’s Perfect Target
Healthcare organizations face unique challenges that make them attractive targets for ransomware attacks. Hospitals often cannot afford prolonged downtime, leading them to pay ransoms that can be significantly higher than in other industries. Additionally, many healthcare facilities rely on outdated technology, with systems that are decades old and lack modern security updates.
Medical records are highly valuable on the dark web, selling for $250 to $1,000 each, making them a lucrative target for cybercriminals. The underfunding of IT security in healthcare, where only 2-4% of budgets are allocated to IT, exacerbates the problem, as organizations prioritize patient care over cybersecurity.
Furthermore, the massive attack surface in hospitals, which includes various systems for patient care, administrative functions, and third-party connections, increases vulnerability. The high turnover of staff and reliance on temporary workers also contribute to security lapses, as new employees may lack proper training.
Compliance with regulations like HIPAA does not equate to actual security, as organizations can be compliant yet still fall victim to ransomware. The need for a shift towards security-first thinking is critical for healthcare organizations to protect against these persistent threats.
- PIH Health Hospitals: Experienced a ransomware attack affecting over 3 million patients.
- SimonMed Imaging: Breach impacted 1.27 million patients.
- Anne Arundel Dermatology: Second breach in a year affected 1.9 million individuals.
- Average breach cost in healthcare: $4.44 million.
- 40-45% of all breaches involve ransomware.
Key Takeaways
- Test your backups to ensure they can be restored effectively.
- Implement multi-factor authentication for all administrative access to enhance security.
- Review third-party vendor access and monitor their security practices.
- Conduct a ransomware tabletop exercise to identify gaps in your response plan.
- Assess your incident response readiness by ensuring you have documented playbooks and designated response teams.
Key Terms & Concepts
- Ransomware: In this article, ransomware refers to malicious software that locks systems and demands payment for access.
- HIPAA: HIPAA stands for the Health Insurance Portability and Accountability Act, which sets standards for protecting sensitive patient information.
- EMR systems: EMR systems are electronic medical record systems used by healthcare providers to manage patient data.
- Multi-factor authentication (MFA): MFA is a security measure that requires multiple forms of verification before granting access to systems.
- Incident response: Incident response refers to the process of preparing for, detecting, and responding to cybersecurity incidents.
Your 5-Minute Securityish Brief
A weekly digest of cybersecurity news, phishing alerts, privacy tips, and emerging threats, simplified so anyone can understand what matters and why.
Securityish
Securityish explains cybersecurity, scams, data breaches, and privacy risks in simple language so you know what’s happening and how to protect yourself.
Navigation
Your 5-Minute Cybersecurity Brief
A weekly digest of cybersecurity news, phishing alerts, privacy tips, and emerging threats, simplified so anyone can understand what matters and why.