|7 min read|Yvann Lièvre

Cyberattacks on Hospitals: Healthcare as Target #1

ANSSI statistics, healthcare-targeted ransomware, NIS2 requirements for hospitals, and defense strategies.

SantéRansomware

In 2025, healthcare was the sector most targeted by ransomware in France according to ANSSI. Every week, a healthcare facility is hit. The consequences are no longer just financial: they are medical. Postponed surgeries, redirected patients, medical records inaccessible for weeks.

Threat Landscape: The ANSSI Numbers

ANSSI's 2025 cyber threat overview is damning:

  • 30% of incidents reported to ANSSI involve the healthcare sector

  • Average downtime after ransomware: 23 days

  • Average incident cost for a hospital: 1.5 to 10 million euros

  • 80% of affected facilities had unpatched systems identified before the attack

Why Hospitals Are Ideal Targets

Time Pressure

A hospital cannot "shut down" while restoring systems. The life-critical pressure on care delivery pushes toward paying ransom or rushing restoration at the expense of security. Attackers know this.

Aging IT Infrastructure

Biomedical equipment running Windows XP, flat networks without segmentation, business software without security updates for years. The IT investment deficit in healthcare creates fertile ground for attackers.

High-Value Data

A medical record sells for 10 to 50 times more than a credit card on the dark web. Health data cannot be cancelled: you cannot "change" your medical history like a card number.

NIS2 and the Healthcare Sector

The NIS2 directive, transposed into national law in 2024-2025, classifies healthcare facilities as essential entities. This means:

  • Mandatory incident notification to the competent authority within 24 hours

  • Proportionate risk management measures: risk analyses, continuity plans, supply chain security

  • Management accountability: the facility director is personally responsible

  • Penalties: up to 10 million euros or 2% of turnover

Defense Strategy for Healthcare Facilities

Network Segmentation

Separate the biomedical network from the administrative network and guest network. Ransomware entering through an administrative workstation must not reach care equipment.

Immutable Backups

Offline backups, regularly tested, with sufficient retention. Modern ransomware specifically targets online backups.

Rapid Detection and Response

ThreatClaw provides continuous monitoring adapted to healthcare environments, with behavioral detection and automated response to contain an attack before it spreads.

Staff Training

Phishing remains the #1 entry vector. Regular awareness campaigns and phishing simulations reduce risk measurably.

Our experts support healthcare facilities in their NIS2 compliance and security posture improvement. Check our plans.

FAQ

Should a hospital pay the ransom?

ANSSI recommends never paying. Payment does not guarantee data recovery, funds criminals, and makes you a recurring target. Invest instead in immutable backups and a response plan.

Which groups target hospitals?

LockBit, BlackCat/ALPHV, Rhysida, and their affiliates regularly target the healthcare sector. Some groups claim an "ethical code" excluding hospitals, but the facts say otherwise.

Are biomedical devices vulnerable?

Yes. Many devices run obsolete operating systems, cannot be patched without manufacturer certification, and communicate in cleartext. Network segmentation is the first line of defense.

What security budget for a hospital?

ANSSI recommends dedicating 5 to 10% of the IT budget to cybersecurity. In practice, most facilities are below 2%. The French Ministry of Health's CaRE program provides dedicated funding.

Related articles