Ransomware Has Moved Down Market in Healthcare: What Mid-Market Practices Must Do Now

For years, ransomware in healthcare was seen as a big-system problem. For an IT administrator for 200-person medical group, thinking they were too small to be worth the trouble was a comforting thought. But those days are over. Even though community hospitals and physician groups still have the same kinds of protected health information as large national health systems, what’s changing is how profitable they can be to attack when they have fewer security resources standing in the way.
The Numbers Tell the Story
During the first half of 2026, Comparitech recorded 410 ransomware attacks against healthcare organizations worldwide, an average of 2.3 per day and a nearly 14% increase from the second half of 2025. Hospitals, clinics, and other direct care providers accounted for 247 of those attacks.1 And it’s only getting worse: August saw a 23% increase from July.2 With less people, technology, and infrastructure to protect them, smaller healthcare organizations can become easy targets.
Ransomware now makes up 48% of all breaches and small organizations are disproportionately affected by these attacks given that they have less resources to defend themselves.3
Consolidation doesn’t necessarily help. Becoming part of a larger organization doesn’t automatically make the individual practice easier to protect. When practices join larger multi-specialty groups, more locations, systems, vendors, and complexity are added, requiring more technical resources that don’t always grow at the same pace.
The Threat Has Changed. So Should the Security.
The risk isn’t just that ransomware attacks are increasing, but that attackers are also changing where and how they apply pressure.
Recovery is now a target. Attackers know backups allow are your path to restore your systems without paying. They try to encrypt or delete your backups to take away your fastest path to recovery and increase the pressure to meet their demands. To address this, be sure your backups are isolated, protected, and regularly tested.
The inbox is easier to exploit. AI helps attackers create more convincing phishing emails. One employee mistake can give ransomware access to the systems clinicians relay on the care for your patients.
Delay is a risk decision. The FBI recorded 460 ransomware complaints last year involving healthcare and public health organizations, more than for any other critical infrastructure sector. 4 Leaving a known security gap in your infrastructure gives attackers more time to find and exploit it.
The compliance bar is rising. The U.S. Department of Health and Human Services (HHS) has proposed stronger HIPAA Security Rule requirements for multi-factor authentication (MFA), encryption, asset inventories, and audits.5 The rule isn’t final, but it’s clear that healthcare organizations need to know where their risks are and show what they’re doing about them.
Five Questions to Ask Your IT Provider Now
The answers to these questions will show you how well your provider understands healthcare and is prepared for its risks.
1. Are you HIPAA compliant?
A simple “yes” isn’t enough. Ask how patient data is encrypted, who can access it, what gets logged, and how the provider helps document those controls in an audit.
2. Do you have experience in healthcare specifically?
Ask who they’ve actually supported. Experience with physician groups, mental health nonprofits, and health equity foundations, backed by real case studies, is much more revealing than a healthcare page on a website.
3. Can you support our Electronic Health Record (her) system?
Many IT providers don’t manage the HER application itself, but they should manage everything it depends on: hosting, network, security, performance, and recovery The should also know how to work with your EHR vendor when there’s a problem.
4. What happens if our systems go down during patient care hours?
You need specifics: who responds, how fast they respond, and how your systems will be restored. Listen for 24/7 monitoring, tested recovery plans, protected backups, and a clear escalation path.
5. How do you handle our patient data?
You should get a plain answer about where the data lives, how it’s protected, and who can reach it. Access should be limited, activity should be logged, and the provider should be willing to put its responsibilities in a Business Associate Agreement (BAA).
Your First Step with NexusTek
Not sure where your biggest gaps are? A good place to start is with a security or HIPAA compliance assessment to help you compare controls that are in place today with what’s needed in the frameworks relevant to you, see what’s missing, and decide what to fix first..
Get started today. https://www.nexustek.com/contact-us
Sources:
1. Comparitech, Healthcare Ransomware Roundup: H1 2026 stats on attacks, ransoms, and data breaches, July 2026
2. Comparitech, Ransomware Roundup: August 2026, September 2026
3. Verizon, 2026 Data Breach Investigations Report, May 2026
4. FBI, Internet Crime Report 2025, April 2026
5. U.S. Department of Health and Human Services, HIPAA Security Rule Notice of Proposed Rulemaking to Strengthen Cybersecurity for Electronic Protected Health Information, accessed August 2026
