72% of healthcare organizations say cyberattacks caused care delays, longer hospital stays
Cyberattacks on healthcare institutions tend to disrupt patient care, carrying risks that impact safety and clinical outcomes, a new report shows.
According to a survey of healthcare organizations that experienced “common cyberattacks”—ransomware, supply chain attacks, cloud compromise and business email compromise—72% reported delays in patient care, including longer hospital stays and slowed intake.
That number is up from 69% last year.
The survey was conducted by cybersecurity firm Proofpoint and data privacy researchers at Ponemon Institute.
The results are based on answers provided by 677 health IT and cybersecurity professionals working at U.S.-based healthcare organizations—93% of which were hit with a cyberattack within the last 12 months.
Over the last two years, the number of healthcare entities that suffered data loss or exfiltration as a result of a cyber incident rose to 96%. The report adds that most incidents caused some form of patient care disruption. Of the types of cyberattacks listed in the report, supply chain disruptions were the most likely to victimize patients, as 87% of incidents resulted in care delays.
Supply chain disruptions would include incidents where testing or procedures were impacted, creating less-than-desirable outcomes for patients.
“Patient safety is inseparable from cyber safety,” Ryan Witt, vice president of industry solutions at Proofpoint, said in a statement. “This year’s report highlights a stark reality: Cyber threats aren’t just IT issues, they’re clinical risks. When care is delayed, disrupted, or compromised due to a cyberattack, patient outcomes are impacted, and lives are potentially put at risk.”
“This report underscores the urgent need for healthcare organizations to adopt a human-centric cybersecurity approach—one that not only protects systems and data but also preserves the continuity and quality of care,” he added.
Millions of dollars in damages
The report also highlights the current financial costs associated with cyberattacks, with “most significant” attacks carrying an average cost of $3.9 million per incident, as a result of downtime and remediation. In 2024, these noteworthy incidents—those that caused downtime—carried an average price tag of $4.7 million.
Meaning, things have improved in 2025.
However, ransomware attacks are becoming more prevalent and more expensive. Incidents of ransomware have increased 60% since last year, with events carrying an average cost of $1.2 million, compared to $1.1 million in 2024.
According to analysis, 33% of healthcare organizations that suffer ransomware attacks paid the ransom. The increased ransom largely accounts for the rise in overall damages accrued.
AI fights back—but it’s complicated
Defenses backed by artificial intelligence and moving data to the cloud were the most popular protective strategies deployed by healthcare organizations. Thirty percent said they have embedded AI into their cybersecurity systems, while the same number also reported migrating clinical applications to the cloud.
Of respondents, 57% stated their organizations have embedded AI in either cybersecurity (30%) or both cybersecurity and patient care (27%). However, interoperability remains a hurdle to adoption, as does data accuracy. Sixty percent said they struggle to protect systems, even with AI—especially since the criminals are using AI tools in their strikes.
When it comes to security risks, most organizations (55%) said mobile devices and apps are a primary culprit. Those owned by employees were perceived to be the biggest threat to patient safety, as 49% of respondents added that their top concern was employee-owned mobile devices. If compromised, these can be—and have been—used to gain access to internal networks at hospitals, health systems and other healthcare businesses.
The full report is available here.
