Skip to main content
Ransomware Hit Healthcare 100 Million Times in 2024Incident Management
4 min readFor IT Governance Teams

Ransomware Hit Healthcare 100 Million Times in 2024

In February 2024, the Change Healthcare breach compromised the data of about 100 million individuals, marking the largest healthcare breach in US history. This incident underscored a harsh reality: healthcare's ransomware problem is worsening, not improving.

Evolving Threats

Ransomware operators have shifted tactics. The Qilin group's June 2024 attack on Synnovis, which disrupted NHS pathology services, exemplifies the move to double extortion. They steal data, threaten to publish it, and watch healthcare organizations scramble. The University of Mississippi Medical Center had to close all clinics in February 2026 after an attack. Tragically, a patient at King's College Hospital NHS Foundation Trust died during the Synnovis incident, with delayed blood test results cited as a contributing factor.

The attack surface has expanded beyond what traditional backup strategies can handle. Patient data now resides across electronic health records, imaging systems, legacy platforms, connected devices, and third-party vendor systems. Without a clear map of where sensitive data is, you can't protect it or confidently state what was taken after an attack.

Key Findings

Encryption-less extortion is now standard. Threat actors focus on data exfiltration and threatening to leak stolen information. Unlike the 2017 WannaCry attack, which didn't threaten data publication, groups like Clop and Qilin use the threat of releasing compromised healthcare data as their primary tactic.

Medical records can't be reissued. The New York City Health and Hospitals breach in May exposed personal data, medical records, and biometric information, including fingerprints, for at least 1.8 million people. You can cancel a credit card, but you can't cancel your fingerprints.

Data sprawl creates unknown exposure. Your information asset inventory is your first line of defense and your last line of accountability. If you don't know precisely where sensitive data sits, you can't apply appropriate controls. Post-incident, that uncertainty can turn a contained event into a full breach notification, regulatory exposure, and lost patient trust.

Backups alone won't restore operations. When systems go down, clinicians lose access to records, treatment gets delayed, and staff revert to manual processes that slow care and introduce risk. The Synnovis incident left patients unable to get blood tests for months. Booking systems, ambulance routing, and internal communications all fail simultaneously.

Third-party risk is your risk. Change Healthcare processes a substantial proportion of US healthcare claims. Synnovis provides pathology services. One vendor compromise can cascade across the entire care delivery chain.

What This Means for Your Team

You're defending against persistent, evolving threats with security models designed for isolated incidents and perimeter defense. That mismatch is structural and worsening.

Data governance must shift from a compliance checkbox to a pillar of operational resilience. ISO/IEC 27001 provides the framework, but you need to implement it with ransomware-specific intent:

Information asset inventory (A.5.9) becomes your attack surface map. You can't protect, recover, or accurately report on data you haven't cataloged. Every imaging system, connected device, and vendor integration point needs documentation.

Classification (A.5.12, A.5.13) drives proportionate controls. Not all data carries equal risk. Patient biometrics and treatment records require stronger access restrictions than appointment schedules.

Retention and deletion (A.8.10) shrink your exposure. Every piece of data you hold is potential leverage for an extortion demand. If you don't need it, delete it.

Least privilege and access restriction (A.5.15, A.8.3) contain breaches. A single compromised credential shouldn't expose your entire electronic health record system. Segregate access by role, system, and data classification.

ICT readiness and backup (A.8.13, A.5.29, A.5.30) mean tested restoration, not theoretical recovery. You need documented procedures, verified backups, and evidence that you can restore critical systems under pressure.

ISO 22301 for Business Continuity Management addresses the operational side: how you maintain care delivery when systems fail. Your continuity plans must account for simultaneous loss of multiple systems and prolonged vendor outages.

Action Items by Priority

Immediate (next 30 days):

Map your information assets. Start with systems that directly support patient care: electronic health records, imaging, lab results, and prescription management. Document where data lives, who can access it, and what classification applies. Use A.5.9 as your baseline.

Audit third-party data flows. List every vendor with access to patient data. Verify what they hold, where it's stored, and what happens if they're compromised. Your vendor risk is your patient risk.

Short-term (next 90 days):

Implement data minimization. Review retention policies against A.8.10 requirements. Delete data you're not legally required to keep. Every record you eliminate is one less piece of leverage in an extortion scenario.

Test your backup restoration procedures under realistic conditions. Don't just verify that backups exist; prove you can restore critical systems within your recovery time objectives. Document the results as evidence for A.8.13.

Run a tabletop exercise focused on double extortion. What happens when attackers threaten to publish patient biometrics? Who makes the decision? What's your communication plan? How do you maintain care delivery during an investigation?

Long-term (next 12 months):

Conduct multi-agency cybersecurity drills at least annually. Work with fire services, police, and other critical infrastructure partners. Put your incident response and business continuity plans under realistic pressure.

Build cross-domain visibility. Traditional siloed security can't address attacks that move laterally across electronic health records, imaging, and vendor systems. You need unified monitoring and coordinated response capabilities.

Embed cybersecurity into organizational decision-making. Cyber resilience can't live only in IT or security teams. Clinical leadership, operations, and procurement all need to understand how their decisions affect your ransomware exposure.

You Might Also Like