I remember exactly where I was when the Change Healthcare attack hit the news. Pharmacies could not process claims. Clinicians could not verify eligibility. Hospitals that had never met the company by name suddenly could not get paid, and patients stood at the counter wondering why their prescription would not go through. Before it was over, the incident had touched roughly 192.7 million people, nearly two out of every three Americans, and cost the company more than $3 billion. One vendor, one point of failure, and the entire healthcare supply chain felt it.

That is what ransomware looks like today. It is not a hooded figure guessing passwords in the dark. It is a business, and healthcare has become its most profitable customer.

Understanding What Ransomware Really Does

Ransomware encrypts an organization's data and holds the decryption key hostage until a payment is made, usually in cryptocurrency. Most attacks now come with a second lever: before encrypting anything, the criminals quietly copy the data and threaten to publish it if the ransom is not paid. This is double extortion, and it is why paying no longer guarantees that a patient's protected health information stays private. The criminals keep a copy either way.

Much of this activity now runs on a franchise model called ransomware-as-a-service. A small group builds the malware and the payment infrastructure, then rents it to affiliates who carry out the attacks and split the profit. The barrier to entry has never been lower, and the margins have never been better.

The Cost To Healthcare Is Not Theoretical

The healthcare industry has absorbed the highest average data breach cost of any sector for fourteen consecutive years, reaching $7.42 million per incident in 2025. Industry analysts project that figure will cross $12 million before the end of 2026. Across the sector, direct and indirect ransomware losses topped $10.8 billion in 2025 alone, and downtime from ransomware attacks between 2018 and 2024 totaled an estimated $21.9 billion across 654 attacks that compromised 88.8 million patient records.

The FBI's Internet Crime Complaint Center recorded 460 ransomware incidents in the healthcare and public health sector in 2024, more than any other critical infrastructure subsector. Sixty-eight percent of healthcare institutions experienced at least one ransomware attack in 2025, with average ransom demands exceeding $1.3 million.

Year to date in 2026, 139.7 million individuals have had their protected health information exposed across 772 reported breaches affecting 500 or more people. Hacking and IT incidents drive nearly every one of them, and ransomware is no longer the exception in HIPAA enforcement. It is the standard.

OCR Is Already Enforcing The Standard It Has Not Yet Finalized

Here is what most of the industry has not caught up to. In January 2025, the HHS Office for Civil Rights proposed sweeping amendments to the HIPAA Security Rule, including mandatory encryption of protected health information at rest and in transit, required multi-factor authentication, network segmentation, and an explicit requirement to deploy anti-ransomware measures and remove extraneous software from every system that touches ePHI. That rule is still a proposal. The Office of Management and Budget has pushed final action out to July 2027, a full year later than OCR's original target.

Do not read that delay as breathing room. Four recent OCR ransomware settlements have already used the proposed rule's standard as the enforcement bar, penalizing organizations for exactly the gaps the NPRM would codify: incomplete risk analyses, missing MFA, and the absence of basic anti-ransomware controls. OCR is enforcing tomorrow's rule today. If your organization is waiting for a final rule before it invests, you are already behind.

The Supply Chain Is Now The Front Door

Change Healthcare was not an outlier. It was a preview. Healthcare's dependence on billing vendors, imaging providers, and clinical software means that a single compromised business associate can cascade into hundreds of covered entities at once. I have said for years that our risk posture is only as strong as our weakest vendor, and 2026 has proven that point at a scale none of us wanted.

Layered on top of this is a governance gap I find genuinely alarming. More than 57 percent of home- and community-based care providers are actively using, testing, or evaluating AI tools, often without the oversight structures that would catch a hallucinated clinical recommendation or an unsecured data flow before it reaches a patient. We are moving faster on adoption than we are on accountability, and that gap is where the next generation of incidents will originate.

The Economics Of Extortion

Here is the uncomfortable truth I keep returning to. Ransomware will not stop because we ask nicely, and it will not stop because we get better at incident response alone. It will stop when it costs the criminals more to run the attack than it costs the victim to refuse the demand.

Right now, that math favors the attacker. The cost of launching a ransomware campaign is low, the potential payout is high, and the odds of facing real consequences remain slim for most operators, particularly those working from jurisdictions that will not extradite them. Every dollar paid confirms that the model works and funds the next campaign. This is not a hostage negotiation. It is a subscription renewal.

Changing that math means raising the cost of the attack itself, not just the cost of defending against it. That requires sanctions with teeth, seizure of the infrastructure that hosts these operations, and international cooperation that follows the money instead of only cleaning up after it lands.

How Other Nations Are Fighting Back

A few of our allies are not waiting for the private sector to solve this alone.

Australia has been building toward this for five years. Its 2021 Ransomware Action Plan laid the groundwork, and in late 2022 the Australian Federal Police and the Australian Signals Directorate stood up Operation Aquila, a permanent 100-person joint taskforce dedicated to investigating and disrupting ransomware groups, including LockBit and BlackCat. In May 2025, Australia became the first country in the world to require ransomware victims to report extortion payments to the government within 72 hours. After an education-first grace period, enforcement penalties took effect in January 2026. Australia is not just defending. It is hunting.

The United Kingdom took a different but complementary approach. After the 2024 ransomware attack on Synnovis, a pathology provider for the NHS, disrupted patient care across London hospitals, the UK government proposed banning ransomware payments outright for public sector and critical national infrastructure organizations, including schools, hospitals, and transport systems. The measure was confirmed in 2025 with 72 percent public support, paired with mandatory incident reporting. The logic is straightforward: if the public sector cannot legally pay, it stops being a target worth pursuing.

Internationally, the Counter Ransomware Initiative now coordinates dozens of member nations on exactly the kind of deterrence I am describing. Its policy work includes building effective crypto asset seizure regimes, with the Netherlands leading research on best practices, and pushing members to adopt the Financial Action Task Force's Recommendation 15 to regulate virtual asset service providers and choke off the laundering pipeline. That work is not abstract. In July 2026, the U.S. Treasury sanctioned Aeza Group, a Russia-based bulletproof hosting provider, for enabling ransomware infrastructure. That is what raising the cost of doing business looks like.

The United States has not banned ransom payments, and I understand the argument against a blanket ban. A poorly designed prohibition could push desperate hospitals toward unreported, off-the-books payments, which would leave regulators and law enforcement with even less visibility than they have today. But visibility, sanctions, and seizure authority are not mutually exclusive with a ban, and we should be pursuing all three with far more urgency than we currently are.

What This Means For You

If you build, secure, or manage healthcare technology, this is not someone else's problem to solve.

  • Harden the supply chain. Extend your monitoring and access controls to every vendor and business associate that touches patient data, not just the systems you own directly. Change Healthcare was someone else's blind spot until it was everyone's emergency.
  • Build to the NPRM standard now, not at finalization. OCR is already enforcing encryption, MFA, and anti-ransomware baseline controls through settlements. Waiting for the final rule to publish before you invest means you are building to yesterday's floor.
  • Track ransom payment history internally, even without a mandate. Australia and the UK are leading indicators, not outliers. Regulatory reporting requirements for ransom payments are coming to more jurisdictions, and organizations that already have this data will not be scrambling when the rule lands.
  • Govern AI before you scale it. If your organization is among the 57 percent evaluating or deploying AI in patient-facing or operational workflows, put a governance framework in place before adoption outpaces oversight, not after an incident forces the conversation.
  • Build resilience, not ransom readiness. Immutable, tested backups and a rehearsed incident response plan are what make refusing to pay a viable option instead of a theoretical one.
  • Support deterrence, not just defense. Advocate for the sanctions, seizure authority, and international cooperation that make attacking healthcare a losing proposition, not only a survivable one for the criminals who try.

The Path Forward

Ransomware persists because it pays. Every ransom transferred is a vote for the business model, and every unpatched vendor connection is an invitation to test it. Australia and the UK are showing that deterrence is possible when governments treat ransomware as organized crime instead of an IT inconvenience. Healthcare cannot outsource that fight to policymakers alone, and policymakers cannot win it without an industry that reports honestly, defends its supply chain, and refuses to make paying the easy answer.

The ransom will stop when the math stops working for the people demanding it. That is the fight worth having.