Healthcare Cyberattack Losses Balloon in 2025

A new report from Netwrix has revealed that almost half of organizations in the healthcare sector experienced at least one intrusion between March 2024 and March 2025, and the losses caused by cyberattacks are higher than in any other sector. Cyberattack-related losses have increased significantly year-over-year, with four times as many healthcare organizations experiencing losses of more than $200,000 compared to the same period in 2024. In 2025, 12% of healthcare organizations experienced cyberattack-related losses in excess of $500,000 compared to 6% in all other industries studied. Only 2% of healthcare organizations reported cyberattack-related losses of more than $500,000 in 2024.

For the study, Netwrix surveyed 2,150 IT professionals from 121 countries in March 2025 and compared the findings with previous studies dating back to 2020. Across all industry sectors, 51% of organizations experienced at least one security incident that demanded a dedicated response from the IT security team rather than automated remediation. Phishing was the most common threat, reported by 76% of respondents, up from 73% in 2024 and 58% in 2023. User/admin account compromise was the next biggest threat, reported by 46% of organizations, down from 55% in 2024.  Ransomware and other malware incidents have remained constant, with 30% of respondents experiencing an incident in 2025, compared to 31% in 2024 and 29% in 2023. It was a similar story with attacks targeting cloud infrastructure – 28% in 2025 and 2024, and 30% in 2023.

Cyberattacks do not necessarily result in any damage, but the percentage of victims that do not suffer any harm is declining. In 2023, 45% of respondents said they had not experienced any damage from a cyberattack, compared to 38% in 2024 and 36% in 2025. The most common consequences of cyberattacks are unexpected costs to address security gaps (43%), loss of competitive edge (17%), compliance fines (15%), customer churn (13%), and decrease in company value (10%). In 2025, 25% of respondents said they suffered financial damage due to cyberattacks, up from 60% in 2024.

The biggest security challenges were understaffed IT and security teams, a lack of funds for data security initiatives, mistakes/negligence by business users, and a lack of cybersecurity expertise within the IT department. AI is reshaping business processes across all sectors, but threat actors are ahead of the curve and have embraced AI and are using AI tools to improve the sophistication and scale their campaigns. “Research strongly suggests that attackers are ahead in AI adoption, which is pushing defenders into a reactive posture,” explained Jeff Warren, Chief Product Officer, Netwrix. “Indeed, 37% of survey respondents say AI-driven threats forced them to adjust — that’s a direct reaction to the offensive use of AI by adversaries. At the same time, 30% haven’t even started AI implementation and are in “considering” mode, indicating a significant lag in adoption. It’s fair to say that attackers are moving faster with AI, and defenders are scrambling to catch up. This asymmetry is not new in cybersecurity, but AI appears to be accelerating it.”

Healthcare has long been targeted by cyber attackers due to the value of patient data and intolerance of disruption to business operations. Ransomware actors know all too well that there is a higher probability of a ransom being paid than in many other sectors because healthcare organizations cannot afford disruption. “These attacks often start with compromised credentials, which is why identity has to be the first line of defense for patient data.”

About Liam Johnson

Liam Johnson has produced articles about HIPAA for several years. He has extensive experience in healthcare privacy and security. With a deep understanding of the complex legal and regulatory landscape surrounding patient data protection, Liam has dedicated his career to helping organizations navigate the intricacies of HIPAA compliance. Liam focusses on the challenges faced by healthcare providers, insurance companies, and business associates in complying with HIPAA regulations. Liam has been published in leading healthcare publications, including The HIPAA Journal. Liam was appointed Editor-in-Chief of The HIPAA Guide in 2023. Contact Liam via LinkedIn: https://www.linkedin.com/in/liamhipaa/