1
Ransomware Risk in Health Care: Building Resilience Beyond Paying
Neil Roshan Shah
FairFax
March 14, 2026
2
Ransomware Risk in Health Care
Ransomware has emerged as one of the most critical operational risks to health care
systems. It is no longer a question of cybersecurity or data protection. The loss of access to the
digital systems by the hospitals may slow down the care provided to the patient, cancel
appointments, and redirect the emergency capabilities to alternative hospitals. These impacts
suggest that ransomware creates a risk to the security of both information and the provision of
medical services. That is why many researchers now think that the ransomware is the problem
which should be treated as the problem of patient safety and operational resilience and not as the
problem of computer technologies.
What makes ransomware a high-impact risk
Ransomware blocks access to systems and data until a payment is made. It can freeze
electronic records, imaging platforms, laboratory platforms and scheduling tools that support
daily clinical work in the health care. The inability of these systems to operate also compels
physicians and nurses to revert to manual systems that slow the treatment process and introduce
the risk of a medical error. It is even evidenced that the scope of ransomware attacks is growing
at an extremely fast rate. Ransomware activities targeting health care delivery organizations in
the US have grown over 2 times in 2016-2021 and almost half of these incidents have resulted in
care delivery (Neprash et al., 2022). The frequency of restoring the backups declined over the
time which implies that attackers and attack strategies are evolving quicker than organizational
security. This is important since many risk plans assume that backups will be an effective
recovery process despite the reality that recovery may take days or weeks in reality (Neprash et
al., 2022).
3
The risk is also linked to data breach harm. In a national survey of US health care
breaches in 2010-2024, hacking or IT incidents were the leading cause of reported breaches, and
in the past few years, ransomware made up a very large share of reported patient records (Jiang
et al., 2025). This implies the reason ransomware is an information risk and operational risk. The
leaders are unable to find the boundary between the system offline and the damage to privacy
since in many cases it may be the same event that will motivate both sides (Jiang et al., 2025).
Whenever hackers gain access to hospital systems, they are likely to steal valuable information
and lock files that will result in more damage, both in terms of money and reputation.
Organizations should therefore consider ransomware attacks as technical downturns but also
after huge privacy and compliance catastrophes. This can also create regulatory questions, legal
costs and loss of patient trust all of which can be added to the impact of the attack.
Why common controls are not enough
One of the critical limitations of most ransomware risk programs is that they rely on
isolated security controls. Organizations can either create a backup or educate employees and
believe that the risk is sufficiently addressed. However, existing evidence indicates that such
confidence is misplaced in many cases. According to Neprash et al. (2022), the effectiveness of
recovery following backups in health care organizations following a ransomware incident
decreases. This trend indicates that even the use of backups is not a strong defense, particularly
when they are poorly tested, unfinished, or are even targeted by hackers. In most situations,
organizations find out only in a crisis that there are weak points and systems have to be brought
up again under extreme time constraints. Risk management hence should involve multiple layers
of defense as opposed to relying on a single technical implementation. The powerful programs
4
are the combination of prevention, detection, response planning, and recovery testing in order to
ensure that disruptions may be mitigated without significant damage to patient care.
The other weakness is that not all organisations have the explicit means of connecting
cyber threats to business priorities. Technical alerts may be gathered by risk programs. However,
neglecting the most important aspect of care delivery. A more powerful measure is to match
threat intelligence with the criticality of an asset and the effectiveness of its control, such that the
leaders would know what to secure to access first and what to retrieve first. Kure et al. (2022)
follow such logic of integrated risk management of the critical infrastructure by combining
structured asset identification with the predictive and categorized types of risks methods. Health
care is not necessarily the same as other sectors with critical aspects, but the need of risk is the
same: it is necessary to make decisions based on the most important services and possible paths
of failures (Kure et al., 2022).
Real-world effects: Spillover turns one attack into a regional event
Ransomware should also be analyzed as a community risk rather than only an
organizational problem. In one study, one month of a ransomware attack on local hospitals
revealed that the emergency departments adjacent to the direct targets had a heavy load,
including taking in more patients, extending wait time, and putting stress on operations (Dameff,
et al., 2023). These spillover effects denote that the incidence of cyber incidents may spread
carnage to a whole regional health system. The most notable fact is that hospitals do not act
within a vacuum. When one system fails the hospitals that are around are forced to pick up the
additional service and continue with their services. This is why the planning must include
regional coordination, surge capacity plans, and share common communication systems among
other emergency and disaster planning (Dameff et al., 2023).
5
Cyber insurance as a risk response: help, harm, and hard tradeoffs
Cyber insurance is commonly regarded as a financial solution to the ransomware risk.
The problem is that ransomware is defined by human choice. Attackers might be encouraged
when it gets easier to pay. Meanwhile, health care executives might be compelled to rebuild
services quickly. Insurance can be a form of governance (Baker & Shortland, 2023). However, it
can also be employed in large to ensure the business continues to run when the crime is
interrupted rather than prevented. This creates a collision between enterprise and security. Risk
decision does not simply mean can we pay, but what is behavior supported by payment over time
(Baker & Shortland, 2023).
Decisions concerning payment are also more complicated than they are suggested
through the public debate. Cartwright et al. (2023) state that the context can either push the
decisions in one of the directions or another with the participation of insurance depending on the
extent of the business interruption and access to stolen information. Insurance may provide
professional help and design but it may reduce the actual price of payment also. It means that
cyber insurance is not likely to be viewed as a risk transfer instrument. It alters incentives and
may change expectations of attackers. Mature risk strategy acknowledges that insurance is a
single line that is supposed to be geared towards prevention and recovery agenda (Cartwright et
al., 2023).
Conclusion
Ransomware has emerged as a significant health care threat due to its ability to disrupt
patient care, disclose sensitive information, and put pressure on neighboring hospitals. It has
been determined that attacks are increasing and some of the recovery practices that are widely
used such as the use of backups are not always effective. This highlights the fact that more
6
integrated and stronger risk management plans need to be in place. Health care organizations
should make cybersecurity planning related to patient safety and continuity of services. The
identification of the critical systems is also part of the preparations as well as testing of the
recovery plans and alignment of other hospitals in case of a disruption. Additionally, leaders are
advised to approach cyber incidents as operational emergencies that require immediate decision-
making, response teams and regular resiliency exercises. Ultimately, the goal is resilience.
Hospitals should be capable of continuing safe and reliable care even in case of cyber incidents,
so that the key medical services should be provided even in case of a significant disruption.
7
References
Baker, T., & Shortland, A. (2023). Cyber insurance and the governance of ransomware. The
Geneva Papers on Risk and Insurance - Issues and Practice, 48(3), 516–
538. [Link]
Cartwright, A., Cartwright, E., MacColl, J., Mott, G., Turner, S., Sullivan, J., & Nurse, J. R. C.
(2023). How cyber insurance influences the ransomware payment decision: Theory and
evidence. The Geneva Papers on Risk and Insurance - Issues and Practice, 48(2), 300–
331. [Link]
Dameff, C., Tully, J., Chan, T. C., Castillo, E. M., Savage, S., Maysent, P., Hemmen, T. M.,
Clay, B. J., & Longhurst, C. A. (2023). Ransomware attack associated with disruptions at
adjacent emergency departments in the US. JAMA Network Open, 6(5),
e2312270. [Link]
Jiang, J. X., Ross, J. S., & Bai, G. (2025). Ransomware Attacks and Data Breaches in US Health
Care Systems. JAMA network open, 8(5), e2510180.
[Link]
Jiang, J. X., Ross, J. S., & Bai, G. (2025). Ransomware attacks and data breaches in US health
care systems. JAMA Network Open, 8(5),
e2510180. [Link]
Kure, H. I., Islam, S., & Mouratidis, H. (2022). An integrated cyber security risk management
framework and risk predication for the critical infrastructure protection. Neural
Computing and Applications, 34, 15241–15271. [Link]
06959-2
8
Neprash, H. T., McGlave, C. C., Cross, D. A., Virnig, B. A., Puskarich, M. A., Huling, J. D.,
Rozenshtein, A. Z., & Nikpay, S. S. (2022). Trends in ransomware attacks on US
hospitals, clinics, and other health care delivery organizations, 2016–2021. JAMA Health
Forum, 3(12), e224873. [Link]