Ransomware Attacks on HIPAA Business Associates up 30% in 2025

A recent analysis has shown that healthcare ransomware attacks are continuing at the high levels seen in 2024, with 293 attacks on hospitals, clinics, and other direct care providers in the first 9 months of this year compared to 300 attacks in the corresponding period in 2024, according to a recent analysis by Comparitech. While the overall number of attacks has remained fairly constant, attacks have decreased each quarter since Q4, 2024, from 136 attacks to 123 in Q1, 2025, 91 in Q2, and 79 in Q3.

Out of the 293 attacks in Q1 to Q3, 2025, 94 attacks have been confirmed by the attacked entity, and 199 attacks are yet to be confirmed. The unconfirmed attacks include cyberattacks where ransomware is suspected but has not been disclosed, and additions to ransomware groups’ dark web data leak sites that have yet to be disclosed by the attacked entity. Across all 293 attacks, the protected health information of more than 7.4 million individuals has been breached, although that figure is certain to rise. The average ransom demand in confirmed attacks was $514,000.

While ransomware attacks on healthcare providers have plateaued, the same cannot be said for attacks on HIPAA business associates. In the first 9 months of 2025, there have been a further 130 attacks on these businesses – an increase of 30% from 2024. Business associates are attractive targets for ransomware groups, as an attack on one company can allow attacks to be conducted on their downstream clients. Out of the 130 attacks, only 23 have been confirmed, and the protected health information of more than 6 million individuals has been compromised.

2024 saw several mega data breaches due to ransomware attacks, and while these have reduced in 2025, there have been a handful of attacks that have involved the theft of large amounts of health data. The biggest known attack so far this year on the healthcare sector was the attack on the healthcare technology company Episource in January 2025, which affected several healthcare clients. Currently, at least 5,45,866 individuals are known to have been affected by the attack.

DaVita, the kidney dialysis company, suffered an Interlock ransomware attack that affected almost 2.7 million individuals, and an attack on Frederick Health affected almost 935,000 individuals.  One of the most recent attacks to be disclosed was a BianLian attack on Goshen Medical Center, which affected 456,385 individuals. The biggest confirmed ransom demand on a healthcare provider came from the Rhysida ransomware attack on Cookeville Regional Medical Center in July 2025, which faced a $1.15 million ransom demand. SimonMed Imaging suffered a Medusa ransomware attack and reportedly received a $1 million ransom demand. There may have been larger ransomware demands; however, ransomware groups often fail to publicly disclose how much they have demanded as payment.

With ransomware attacks continuing to occur in high numbers, it is vital for healthcare organizations to take a proactive approach to threat hunting through AI-powered intrusion detection systems, which can recognize anomalies and generate alerts. Fast detection can halt an attack in progress before sensitive data is stolen and files are encrypted. It is also strongly recommended to ensure that cybersecurity best practices are followed and the measures recommended by the HHS in its Cybersecurity Performance Goals are adopted.

HIPAA
Compliance
Checklist

Simple Guidelines
Immediate PDF Download

Immediate Access

Privacy Policy

Download Free Checklist

About Liam Johnson

Liam Johnson has produced articles about HIPAA for several years. He has extensive experience in healthcare privacy and security. With a deep understanding of the complex legal and regulatory landscape surrounding patient data protection, Liam has dedicated his career to helping organizations navigate the intricacies of HIPAA compliance. Liam focusses on the challenges faced by healthcare providers, insurance companies, and business associates in complying with HIPAA regulations. Liam has been published in leading healthcare publications, including The HIPAA Journal. Liam was appointed Editor-in-Chief of The HIPAA Guide in 2023. Contact Liam via LinkedIn: https://www.linkedin.com/in/liamhipaa/