A new study shows ransomware attacks accounted for 69% of all patient records compromised in 2024.


A new study led by researchers from Michigan State University, Yale University, and Johns Hopkins University reveals that ransomware attacksโ€”which involve a hacker putting encryption controls into a file and then demanding a ransom to unlock the filesโ€”have become the primary driver of health care data breaches in the United States, compromising 285 million patient records over 15 years.

Published May 14 in JAMA Network Open, the study provides a comprehensive analysis of ransomwareโ€™s role in health care breaches across all entities covered by privacy lawsโ€”hospitals, physician practices, health plans, and data clearinghousesโ€”from 2010 to 2024.

โ€œRansomware has become the most disruptive force in health care cybersecurity,โ€ says John (Xuefeng) Jiang, PhD, Eli Broad Endowed Professor of accounting and information systems in the MSU Broad College of Business and lead author of the study, in a release. โ€œHospitals have been forced to delay care, shut down systems, and divert patientsโ€”all while sensitive patient data is held hostage.โ€

The study found that although ransomware accounted for just 11% of breaches in 2024 by number, those attacks alone were responsible for 69% of all patient records compromised that year. Since 2010, ransomware incidents have contributed to the exposure of 285 million patient recordsโ€”many of which likely involve multiple breaches of the same individuals.

In addition to Jiang, the research team includes Joseph Ross, MD, MHS, professor at the Yale School of Medicine, and Ge Bai, PhD, CPA, former doctoral student in the MSU Broad College of Business and now professor of accounting and health policy at Johns Hopkins University.

Ransomware Breaches Surge from Zero in 2010

Key findings of the study include:

  • Ransomware breaches increased from 0 in 2010 to 222 in 2021, accounting for nearly a third of all major health care breaches that year.
  • The overall share of breaches caused by hacking or information technology incidents surged from 4% in 2010 to 81% in 2024.
  • Of the 732 million total patient records exposed between 2010 and 2024, 88% (643 million records) were linked to hacking-related incidents, including 39% (285 million) specifically from ransomware.

These numbers likely underestimate the true extent of the problem due to underreporting, reluctance to disclose ransom payments, and the exclusion of smaller breaches affecting fewer than 500 individuals, note the researchers.

“Ransomware attacks expose just how fragile our digital health infrastructure has become. Healthcare organizations operate under immense pressure, and ransomware attacks donโ€™t just breach patient privacyโ€”they disrupt service delivery, erode trust, and lead to personnel spending time, effort, and expense on activities that do not improve patient care,โ€ says Ross in a release.

This new research builds on the teamโ€™s prior work documenting the scope and causes of data breaches in the health sector. Earlier studies showed that internal errors by health care providersโ€”not hackersโ€”were responsible for more than half of all breaches, including misdirected emails, lost devices, and unauthorized employee access. In a 2020 study, the team classified the specific types of information leaked in health care breaches, finding that over 70% of breaches compromised sensitive demographic or financial dataโ€”such as Social Security numbers, birthdates, and bank accountsโ€”that could lead to identity theft or financial fraud. In contrast, breaches involving sensitive medical information, such as mental health or cancer diagnoses, were far less frequent.

โ€œWhether itโ€™s insiders making mistakes or criminal groups deploying ransomware, the effect on patients is the same: their most personal data is at risk,โ€ says Bai in a release. โ€œBy understanding whatโ€™s being targeted, we can help health care organizations strengthen their defenses.โ€

Regulatory Actions to Mitigate Ransomware Risks

The researchers suggest several steps federal regulators can take to reduce future risks:

  • Require hospitals and insurers to report whether ransomware was involved in a breach.
  • Update breach severity assessments to reflect not just how many records were compromised, but how much care was disrupted.
  • Monitor cryptocurrency flows to make ransom payments harder for attackers to collect.

โ€œHealth care providers have limited cybersecurity resources, so itโ€™s essential to focus protection on the most sensitive types of information,โ€ says Jiang in a release. โ€œThe solutions are within reachโ€”what we need now is coordination, transparency, and urgency.

ID 124742804 ยฉ Andrey Popov | Dreamstime.com