Healthcare has quietly become the single most attractive target for ransomware operators anywhere in the global economy, and the numbers from the past eighteen months make the case with uncomfortable clarity. Ransomware attacks against healthcare practices, clinics and specialty groups surged 36 percent year-over-year in late 2025, with the sector now accounting for over a third of all reported ransomware activity across every industry tracked. In 2024 alone, healthcare experienced 739 data breaches affecting more than 276 million records — the highest figure ever recorded for the sector — with the average breach now costing $7.42 million to remediate and taking an average of 241 days simply to detect. Double-extortion tactics, in which attackers both encrypt hospital data and separately threaten to leak stolen patient records, have become standard practice in the overwhelming majority of confirmed healthcare incidents.
The structural reasons healthcare remains so exposed are well understood but stubbornly unresolved. Hospitals run enormous fleets of connected medical devices — infusion pumps, imaging systems, patient monitors — many of which cannot be patched without regulatory recertification or vendor involvement, leaving known vulnerabilities exposed for years. Perhaps the starkest statistic in this entire story: 99 percent of hospitals now manage at least one medical device carrying a known, exploitable vulnerability. Combine that with chronically thin cybersecurity budgets, understaffed security teams, and the sheer operational stakes of a hospital that cannot afford downtime the way a retailer or a bank can absorb a temporary outage, and the sector becomes close to an ideal target: high willingness to pay, low capacity to defend, and life-safety consequences that ransomware operators have learned to exploit as leverage.
What has genuinely shifted in the past year is not the attack surface itself but the governance response to it. Regulators in major markets now require public companies to disclose cybersecurity practices and material incidents, and that disclosure obligation is increasingly paired with personal liability exposure for board members who cannot demonstrate they exercised adequate oversight of cyber risk. This is pushing hospital boards — many of which have historically treated cybersecurity as a routine IT agenda item, reviewed annually and delegated entirely to the chief information security officer — to instead treat cyber risk on par with patient safety and financial solvency as a fiduciary matter requiring direct board-level engagement. That is a genuinely significant cultural shift for an industry sector where clinical quality committees have long dominated board attention, and it did not happen voluntarily; it happened because the cost of getting it wrong, in both ransom payments and regulatory consequence, became too large to delegate away.
India’s own experience with this threat predates the current global surge and offers a instructive, if sobering, case study. In late 2022, the All India Institute of Medical Sciences in New Delhi — one of the country’s most prestigious public hospitals — suffered a ransomware attack that knocked out its computer systems for roughly two weeks, forcing patients into extended waits and staff back onto paper records while more than 1.3 terabytes of patient data was reportedly encrypted. The attack landed as India was simultaneously pushing forward its Ayushman Bharat Digital Mission, the national programme to give every citizen a digital health ID and consolidate medical records into shareable digital format — more than 170,000 hospitals had already signed up at the time, registration being mandatory for government facilities. Technology researchers warned then that citizens were effectively being pushed toward digitisation without correspondingly robust security safeguards, a tension that has only intensified since: India’s ABHA digital health ID programme has since scaled to roughly 67 crore identities created, and separately, the 2026 breach of Star Health exposed 31 million patient records, underscoring that the AIIMS incident was a warning rather than an isolated event.
For NSH’s readers in hospital administration, health-tech and insurance, the preventive-governance framing that Western regulators are now enforcing through disclosure and liability rules deserves close attention regardless of whether India’s own regulatory regime moves as quickly. India’s healthcare sector reportedly faces attack rates roughly four times the global average on patient-data systems, according to risk-management assessments tied to ABDM compliance requirements — a gap between exposure and institutional preparedness that Indian hospital boards, insurers and health-tech vendors would be wise to close before, rather than after, their own AIIMS-scale reckoning arrives.
What would preventive governance actually look like for an Indian hospital board, translated from the disclosure-and-liability model now taking hold internationally? At minimum, it means board-level visibility into which legacy medical devices carry unpatched vulnerabilities rather than leaving that inventory entirely within the IT department; it means incident-response plans that account explicitly for the life-safety implications of a clinical systems outage, not just data-loss financial exposure; and it means treating cybersecurity investment as core operational spending rather than a discretionary line item cut in lean budget years — historically one of the more persistent failure patterns across healthcare systems globally, not just in India. None of this requires India to replicate Western disclosure regulation wholesale; it requires Indian hospital leadership to internalise the underlying lesson before a comparably scaled incident forces the issue.
As India’s digital health infrastructure continues expanding at a pace few health systems anywhere in the world are attempting simultaneously, the governance lesson coming out of Western boardrooms — that cybersecurity oversight is now a fiduciary duty, not a delegated IT function — is one India’s hospital leadership cannot afford to treat as someone else’s problem. The alternative, as AIIMS demonstrated and as Star Health’s far larger 2026 breach reinforced, is learning the lesson the expensive way, in full public view, with patient care itself as the immediate casualty.
– Rithvisha Kiran


