- A 2021 study in Health Affairs found hospitals hit by ransomware saw a 4.4% increase in mortality among emergency patients in the year after the attack.
- FBI Internet Crime Complaint Center data shows healthcare ransomware incidents jumped 94% from 2021 to 2022, hitting over 200 organizations.
- The average healthcare ransomware incident cost $10.1 million in 2023 — the highest of any industry sector — with recovery typically taking 15 to 20 days.
- 62% of healthcare organizations were hit by ransomware in 2023, and 67% of those attacks successfully encrypted data.
What We Found
As of July 24, 2026, the case that still anchors every conversation about ransomware and patient death happened six years ago in Germany. In September 2020, a ransomware attack knocked out IT systems at Düsseldorf University Hospital. A woman in need of emergency care had to be redirected to a hospital roughly 20 miles away. She died. German prosecutors opened an investigation into involuntary manslaughter — then, after review, concluded the patient likely would have died regardless of which hospital treated her. That reversal is the reason cybersecurity researchers still argue about whether Düsseldorf is "the first ransomware death" or just the first one anyone tried to prove in court.
According to Google News, aggregating coverage built on an analysis from Cybersecurity Insiders, that ambiguity is precisely the problem. Individual cases are hard to prove causally. Patterns across hundreds of hospitals are not.
The Evidence
Health Affairs, the peer-reviewed health policy journal, published research in 2021 quantifying what individual case studies couldn't: hospitals struck by ransomware experienced a 4.4% increase in mortality rates for emergency patients in the year following an attack. The same research identified a statistically significant 0.21 percentage point increase in mortality specifically among heart attack and stroke patients — the two conditions where minutes of delayed treatment matter most.
WIRED's investigation into Ryuk ransomware cases at U.S. hospitals adds the mechanism behind that number: during active incidents, electronic health records, lab results, and imaging systems go dark simultaneously, forcing clinicians to make decisions blind or divert patients entirely. The 2022 CommonSpirit Health attack illustrated the scale this can reach — 142 hospitals across 21 states were forced to divert ambulances and delay procedures, though CommonSpirit never officially confirmed a direct fatality link.
FBI Internet Crime Complaint Center data shows this isn't a shrinking problem. Healthcare ransomware attacks rose 94% from 2021 to 2022, hitting more than 200 organizations. As of the most recent full-year figures reported for 2023, 62% of healthcare organizations experienced a ransomware attack, and 67% of those attacks successfully encrypted data. The average incident cost $10.1 million — the highest of any sector — and full recovery took 15 to 20 days, a window during which critical systems remain degraded or offline.
Chart: Healthcare ransomware trend, FBI IC3 and industry data cited through 2023.
The source divergence worth naming: German prosecutors' walk-back on Düsseldorf caused some outlets to treat the "ransomware death" framing as overstated. But that divergence is about attribution in a single case, not about the population-level mortality data Health Affairs published. Those are two different questions, and conflating them undersells the second one.
What It Means
The threat actor profile here is uncomfortable: ransomware groups including LockBit and ALPHV/BlackCat publicly pledged, after Düsseldorf, to avoid targeting healthcare facilities. Those pledges have been broken repeatedly — the 2024 Change Healthcare attack, which disrupted prescription processing and insurance claims for millions of Americans, is the clearest recent proof that healthcare remains an active target regardless of stated intent. The FBI and CISA's joint advisory put it plainly: cyber threats to healthcare are "unique and concerning because they directly threaten patient care and safety, unlike attacks on other critical infrastructure sectors."
The blast radius isn't the encrypted data itself — it's every downstream clinical decision that depends on systems being available. EHRs, lab pipelines, and imaging are single points of failure dressed up as IT infrastructure. A layered defense stack has to treat clinical continuity as the actual asset being protected, not just PHI. That means network segmentation isolating clinical systems from general IT, offline and immutable backups tested for actual restore speed (not just backup completion — the gap between the two is where hospitals lose their 15-to-20-day recovery window), and a documented incident response plan that includes manual downtime procedures clinicians have actually rehearsed. Organizations comparing backup platforms for exactly this reason should note the tradeoffs Picks recently laid out between Backblaze, IDrive, and Acronis — restore speed under pressure matters more than storage price in a clinical setting.
The U.S. Department of Health and Human Services issued mandatory cybersecurity performance goals for healthcare organizations in late 2023, requiring specific controls tied to patient safety rather than generic data protection. That regulatory shift signals HHS treats this as a patient-safety problem first, a compliance problem second — a framing worth adopting internally even if your organization isn't a hospital.
The AI Angle
AI cuts both ways in this fight. Threat actors use it to identify vulnerable healthcare targets faster and to write phishing emails convincing enough to bypass the security awareness training most staff have already sat through. Defensively, AI-powered anomaly detection and automated threat hunting are increasingly what catches lateral movement inside a hospital network before encryption starts — the difference between an incident response team acting in minutes versus discovering the breach when systems start failing. Threat intelligence platforms that flag unusual authentication patterns across clinical systems are doing quietly important work here.
How to Act on This
A backup that takes four days to restore doesn't help during a 15-to-20-day recovery window. Run a full restore drill on clinical or mission-critical systems and time it.
If a compromised front-office laptop can reach the same network segment as an imaging system, that's the control to ship first — not the next tabletop exercise.
Staff who have never used paper charting or manual lab orders under pressure will make slower, riskier decisions during an actual outage. Practice it before you need it.
Frequently Asked Questions
Can ransomware attacks kill people?
Direct causation is hard to prove in any single case, but population-level data supports the connection. A 2021 Health Affairs study found hospitals hit by ransomware saw a 4.4% increase in mortality for emergency patients in the following year, including a 0.21 percentage point increase in heart attack and stroke mortality specifically.
What happened in the Düsseldorf hospital ransomware attack?
In 2020, a ransomware attack disabled Düsseldorf University Hospital's IT systems, forcing a woman needing emergency care to be redirected to a hospital about 20 miles away. She died, and German prosecutors opened a manslaughter investigation before later concluding she likely would have died regardless of the redirection.
How long does it take hospitals to recover from ransomware?
The average hospital ransomware attack requires 15 to 20 days for full recovery, during which core systems like electronic health records, lab results, and imaging are often unavailable — directly affecting patient care quality throughout the outage.
Disclaimer: This article is for informational purposes only and does not constitute professional security consulting advice. Always consult with a qualified cybersecurity professional for your specific needs. Research based on publicly available sources current as of July 24, 2026.