The Growing Cybersecurity Crisis in Healthcare: 2025 Report Analysis
When Ransomware Targets Hospitals: Insights from Claroty’s Latest Report
Claroty scanned millions of connected medical devices and found the exposure is nearly universal. Here is what is most at risk - and the five-step plan to fix it.
Nearly every hospital is running connected devices attackers can already exploit - and in healthcare, that is not just a data problem, it is a patient-safety problem.
Hospitals depend on thousands of connected devices, from MRI machines to patient monitors to building controls. Claroty's healthcare report shows how many of those devices carry flaws attackers actively use - and how many are needlessly exposed to the internet. Here is the scale of the problem, who is exploiting it, and the practical plan the report recommends for getting ahead of it.
The Scale of the Exposure
Known-exploited vulnerabilities are almost everywhere - but concentrated in a few systems.
Hospital information systems and imaging devices carry the most known-exploited vulnerabilities - and they hold the most sensitive data.
Across the dataset, 99% of organizations had at least one device with a known-exploited vulnerability, and 89% had medical systems with ransomware-linked flaws that were also insecurely connected to the internet. The most exposed are the systems that matter most: hospital information systems, which hold patient records and financial data, and imaging systems, which are essential to diagnosis.
Who Is Attacking Healthcare
Ransomware crews target hospitals because they cannot afford downtime.
When a hospital goes down, patient care is on the line - which is exactly why ransomware groups see healthcare as a payer.
- Black Basta. A Russian ransomware-as-a-service operation whose affiliates have hit more than 500 organizations. It was tied to the 2024 Ascension attack, which forced patient diversions and drove roughly $1.8 billion in losses.
- BlackCat / ALPHV. A Russia-affiliated crew behind the 2024 Change Healthcare attack, using triple extortion. The FBI believes it compromised over 1,000 organizations and took more than $300 million in ransoms.
- Why hospitals get targeted. Attackers know care cannot stop, so hospitals are among the critical-infrastructure targets most likely to pay - which keeps the attacks coming.
- How they get in. Exploits against exposed devices and phishing provide the foothold, then double- and triple-extortion pressure follows.
The 5-Step Plan to Fix It
Claroty's framework goes beyond "patch everything" to "fix what actually matters."
The goal is to find the small set of devices that are both genuinely exploitable and reachable - then remediate those first.
- Scope. Account for the critical clinical processes by device type and department, so you know what a compromise would actually disrupt.
- Discover. Identify every connected device, its detailed attributes, and how it communicates - you cannot protect what you cannot see.
- Validate. Confirm which exposures are real and externally reachable, filtering out the theoretical from the truly dangerous.
- Prioritize. Rank by business impact and exploitability using a security framework, not just raw vulnerability counts.
- Mobilize. Apply practical mitigations - patching, closing open ports, segmentation, and endpoint protection - starting with the highest-risk devices.
In healthcare, a hacked MRI or patient monitor is not just stolen data - it can delay care. That raises the stakes and is exactly why exposed, exploitable devices have to be found and fixed first.
Device and Network Security for Healthcare
CinchOps helps Houston-area healthcare and clinical practices find exposed devices, segment their networks, and remediate the exploitable ones first - through our cybersecurity and managed IT services.
Explore CinchOps cybersecurity →How CinchOps Helps Secure Your Business
CinchOps is a Katy, Texas managed IT services provider serving businesses across the Houston metro, including healthcare practices with connected devices to protect.
- Device and exposure assessment. We find every connected device and flag the ones that are exploitable and internet-reachable.
- Secure network design. Segmentation that keeps a compromised device from reaching critical systems.
- 24/7 monitoring and response. Continuous detection so an intrusion is caught before it spreads.
- Zero Trust for critical systems. Verify every access request to the systems that hold sensitive data.
- Audits and staff training. Regular reviews and awareness training to keep exposure low.
Do not wait to become the next headline. Contact CinchOps to protect your patients, staff, and reputation.
Frequently Asked Questions
What did the Claroty healthcare report find?
Its State of CPS Security: Healthcare Exposures 2025 report analyzed 2.25 million IoMT and 647,000 OT devices across 351 hospitals. It found 99% of organizations have devices with known-exploited vulnerabilities, and 89% run medical systems with ransomware-linked flaws that are insecurely internet-connected.
Which medical systems are most at risk?
Hospital information systems and imaging devices. Around 45% of hospital information systems and 28% of imaging devices carry known-exploited vulnerabilities - and both hold or support highly sensitive clinical data.
Why do ransomware groups target hospitals?
Because care cannot stop. Hospitals are among the critical-infrastructure targets most likely to pay to restore operations, which makes them attractive to crews like Black Basta and BlackCat that were behind the Ascension and Change Healthcare attacks.
Is patching every device the answer?
No - it is not realistic, and many medical devices cannot be patched easily. The report recommends finding the devices that are both genuinely exploitable and externally reachable, and fixing those first through a scope-discover-validate-prioritize-mobilize approach.
What is a KEV?
A Known Exploited Vulnerability - a flaw that attackers are actively using in the real world, tracked in the U.S. CISA KEV catalog. A device carrying a KEV and exposed to the internet is a top-priority risk.