Where have all the big health system cyberattacks gone?

Advertisement

For years, one of the most consequential storylines in health system operations was the cyberattack that took multiple hospitals offline.

Chicago-based CommonSpirit Health in 2022, then Change Healthcare and St. Louis-based Ascension in 2024, showed how a single intrusion could divert ambulances, freeze claims and expose millions of records. More recently, that kind of headline has grown scarce, even as total healthcare breaches, by one measure, have never been worse.

The HHS Office for Civil Rights logged at least 772 large healthcare data breaches — those affecting 500 or more individuals across hospitals, health plans, vendors and other business associates — in 2025, a record that edged past the 746 reported in 2023, according to a HIPAA Journal analysis of federal breach data.

However, a closer look at health system breaches tells a different story. Eight of the 18 biggest healthcare breaches in 2020 hit hospitals or health systems directly — many of them ransomware attacks that disrupted care, HIPAA Journal reported. By 2025, just four of the 23 largest did.

The picture also changes when you measure by people affected rather than breach count. The number of individuals whose information was exposed fell roughly 52%, to about 139.7 million in 2025 from 289.8 million in 2024, per the news outlet. That 2024 peak was an outlier created almost single-handedly by the Change Healthcare attack, which compromised the data of 192.7 million people — the largest healthcare breach in U.S. history — as well as the Ascension ransomware attack that forced ambulance diversions across the organization’s footprint of more than 140 hospitals.

Still, industry experts caution against interpreting the smaller figures as a relief. “We have become somewhat desensitized to the large numbers and the true impact of these crimes,” the American Hospital Association’s John Riggi, national advisor for cybersecurity and risk, and Scott Gee, deputy national advisor, wrote in October.

By spring 2024, the old ransomware order had fractured: International law enforcement severely disrupted LockBit that February, and ALPHV/BlackCat — the crew behind the Change Healthcare incident — imploded weeks later, pulling an apparent exit scam tied to the reported $22 million ransom it collected from that very attack.

Ransomware economics deteriorated in tandem: Total payments fell about 36% in 2024, according to cryptocurrency analyst Chainalysis, and median healthcare ransom demands and payments both dropped about 90% in 2025, per cybersecurity firm Sophos, as more victims refused to pay and defenses improved.

Attackers also changed tactics. Encryption — the technique that locks up systems and forces the operational shutdowns that make headlines — appeared in just 34% of healthcare ransomware attacks in 2025, down from 74% a year earlier and a five-year low, Sophos found. In its place came (quieter) data extortion: the theft of records followed by a threat to leak them. It can expose just as much information but rarely takes a hospital offline, so it draws far less attention even as breach counts climb.

The action has also continued moving to third-party vendors. Business associates figured in 34% of large healthcare breaches on average from 2018 through 2026, and 43% in the first half of 2026 — up from 20% in the nine years prior, according to HIPAA Journal. By victim count, the shift is even clearer: The share of people whose data was exposed through a business associate jumped to 65% in 2025, from just 5% in 2015. Two of the three largest healthcare breaches on record — Change Healthcare and 2025’s Conduent breach, which exposed the data of more than 62 million people — were both vendors.

In the past several years, the AHA’s Mr. Riggi and Mr. Gee wrote, “over 80% of the stolen protected health information records were not stolen from hospitals — they were stolen from third-party vendors, business associates, and nonhospital providers and health plans.”

That concentration is the point, the experts noted: “By gaining access to the hub — a third party’s technology — they gain access to all the spokes: the healthcare organizations that are the customers of the third party.”

At the other end of the spectrum, smaller and rural hospitals have become attractive marks. As large health systems have become more secure, hackers have turned their attention to their less-resourced counterparts, Brad Reimer, chief technology and digital officer of Sioux Falls, S.D.-based Sanford Health, told Becker’s in July 2025.

Aging systems, thin budgets and little or no dedicated security staff make them an easier payday even when the ransom is modest. The concern is broad enough that Microsoft launched a free security program now covering roughly 700 rural hospitals — more than a third of the nation’s total. As healthcare organizations lose an average of $1.9 million for every day of downtime, per an analysis by researcher Comparitech, a hack can be catastrophic for a small facility. Ransomware attacks have even been blamed for temporary or permanent hospital closures.

Some of this perceived calm may be a matter of timing. A 43-day federal government shutdown from Oct. 1 to Nov. 12, 2025, froze new entries to the OCR breach portal, and reporting has lagged since, which means 2025’s totals could still climb as delayed cases post. Healthcare also remains the most-targeted sector for reported cyberthreats, according to the FBI. And the vendor-concentration risk exposed by Change Healthcare — a single clearinghouse breach cascading across thousands of downstream providers — remains unresolved. The AHA calls this effect the “ransomware blast radius”: In third-party hacks, “there is often a cascading disruptive effect that extends to all of the customers of the victim of the attack,” according to Mr. Riggi and Mr. Gee.

The takeaway is less that big healthcare cyberattacks have disappeared than that they have evolved. The loud, operationally catastrophic hack has given way to quieter, more numerous breaches aimed at weaker (and potentially more valuable) points in the system: the vendors upstream and the small hospitals with the least ability to defend themselves.

At the Becker's 11th Annual IT + Revenue Cycle Conference: The Future of AI & Digital Health, taking place September 14–17 in Chicago, healthcare executives and digital leaders from across the country will come together to explore how AI, interoperability, cybersecurity, and revenue cycle innovation are transforming care delivery, strengthening financial performance, and driving the next era of digital health. Apply for complimentary registration now.

Register to Attend Webinar

The hidden cost of lost clinical time and how leading health systems are responding

Friday, August 7
12:00 PM - 1:00 PM CDT

Presenters: Kassaundra McKnight-Young, Zebra TechnologiesGregory Carras, Zebra TechnologiesJennifer Gene, Levata

Advertisement

Next Up in Cybersecurity

Advertisement