Hospitals are some of the highest-value targets in the ransomware world. Not because they’re careless (most of them are trying) but because the math works in the attacker’s favor. When a hospital goes down, people can’t get care, revenue stops by the hundreds of thousands per day, and the pressure to pay is enormous. Attackers know this.
Healthcare is one of ArcLight Group’s biggest focus areas, and I’ve spent the better part of two decades watching this problem get worse. I want to walk you through what actually happens when a hospital gets hit, using publicly reported incidents, including the ransomware attack on Stillwater Regional Medical Center right here in Oklahoma, to illustrate the lessons every healthcare organization needs to learn before it’s their turn.
Why Hospitals Are Prime Targets
Here’s the thing most people don’t realize: ransomware operators aren’t some kid in a hoodie. These are professional organizations. They have call centers. They have customer service reps. They have negotiation teams. And they pick their targets based on one simple metric: who’s most likely to pay, and pay fast?
Hospitals check every box. A manufacturing plant that loses its network might lose production for a week and eat the cost. A hospital that loses its network is diverting ambulances, canceling surgeries, and watching revenue evaporate at a staggering rate. When you’re bleeding that kind of money every single day, even a seven-figure ransom starts to look like the cheaper option.
That urgency is the product. That’s what they’re selling back to you.
What Happens When a Hospital Gets Hit
The Stillwater Regional Medical Center ransomware attack was widely reported in the news, and it follows a pattern we’ve seen over and over across the healthcare industry. Here’s what that pattern typically looks like.
It usually starts quietly. An attacker gains access (phishing email, compromised credentials, an unpatched VPN) and sits inside the network for days or weeks. They map out the infrastructure. They identify critical servers. They find the backups. And then, at the worst possible moment, usually a Friday night or a holiday weekend, they flip the switch.
In a hospital environment, you’re looking at 100-plus servers going dark. Electronic health records. Imaging systems. Lab systems. Pharmacy. Billing. Email. Everything. Staff are suddenly working with paper charts, verbal orders, and a whole lot of confusion.
And here’s the part that surprises people: when the attackers encrypt the domain controllers and DNS servers, they actually slow themselves down too. Those are the systems that let you move laterally across a network. So in a twisted way, encrypting the core infrastructure can sometimes limit how far the attack spreads, but by that point, the damage is already catastrophic.
The Ransom Decision
This is where it gets really uncomfortable. You’ve got a hospital that’s losing massive revenue every day it’s down. Insurance might cover some of the lost revenue, but those policies have sub-limits and conditions that make the actual payout a fraction of what you’d expect. And the clock is ticking.
Ransomware operators know exactly what they’re doing. They provide per-device encryption keys, so you can buy decryption for individual servers rather than paying one lump sum for everything. It’s sophisticated. It’s transactional. They’ll even walk you through the process on the phone.
What most organizations end up doing, and this is well-documented across public incidents, is buying keys only for the most critical servers. The EHR. The billing system. Maybe imaging. Everything else gets rebuilt from scratch. You’re making triage decisions about your own infrastructure the same way an ER doctor triages patients.
Why Backups Fail When You Need Them Most
I’m here to tell you, this is the part that keeps me up at night. Every organization I talk to says, “We have backups.” And almost every time, those backups wouldn’t survive a real attack.
Here’s why: if your backup system is on the same network as everything else, it gets encrypted too. Same domain. Same credentials. Same blast radius. It doesn’t matter if the backup server is in a closet down the hall or in a data center across town. If it’s reachable over the same network with the same admin credentials, it’s gone.
I’ll give you a real example. A Tulsa-based asphalt company got hit with ransomware. They had offsite backups. Smart, right? Except they used the same admin password for the offsite backup system as they used for everything else. The attackers enumerated credentials across the environment, found the backup system, and destroyed the backups before they ever encrypted the production servers. By the time anyone noticed the ransomware, the safety net was already gone.
This is the pattern. Attackers specifically hunt for backups. They know that’s the one thing standing between them and a big payout. If your “offsite” backup is connected via VPN tunnel back to your main network, it’s not really offsite. It’s just another server on the same network with a longer cable.
Real backup protection means three things: separate network, separate authentication, separate encryption. If any one of those is shared with your production environment, you have a vulnerability.
The Insurance Trap
Most healthcare organizations carry cyber insurance, and they should. But I want you to understand what actually happens after you file a claim.
First, the insurance company is going to investigate whether the incident was your fault. If they can demonstrate that you failed to maintain reasonable security controls (missed patches, weak passwords, no MFA on remote access), they will use that to reduce or deny your claim. They’re not your advocate. They’re a business, and their job is to minimize what they pay out.
Second, even if they do pay, the aftermath is brutal. After a major ransomware claim, your premiums don’t just go up a little. I’ve seen organizations hit with 10 to 30 times their previous premium at renewal. Some carriers drop you entirely, and finding replacement coverage with a ransomware incident on your record is incredibly difficult and expensive.
So the insurance that was supposed to protect you ends up being a one-time parachute that costs you enormously on the back end.
The Long Tail Nobody Talks About
Here’s what the news articles don’t cover: what happens in the months and years after a ransomware attack.
Even after you’ve paid for decryption keys, even after you’ve restored critical systems, you’re not done. Not even close. The infrastructure gets rebuilt over months. Sometimes years. And it’s shocking how many systems never get fully rebuilt. You end up with workarounds on top of workarounds. Shadow infrastructure. Systems that were “temporarily” set up during the crisis that become permanent because nobody has time to do it right.
I’ve seen organizations that are still dealing with the aftereffects three, four, five years later. Legacy configurations that nobody fully understands. Compliance gaps that crept in during the rebuild. Technical debt that compounds every year.
The ransomware attack isn’t an event. It’s a before-and-after line in the life of your organization.
What Healthcare Organizations Should Do Differently
If you’re running IT for a healthcare organization, or you’re the executive responsible for one, here’s what I’d tell you to do this week:
- Audit your backup architecture. Not whether you have backups, but whether they’d survive an attack. Are they on a separate network? Separate authentication? Would an attacker who owned your domain admin also own your backups? If the answer is yes, fix it now.
- Test your recovery. When’s the last time you actually restored from backup? Not a single file, but a full server. A full system. If you haven’t tested it, you don’t have a backup. You have a hope.
- Get MFA on everything remote. VPN, RDP, email, cloud admin consoles. Every remote access point that uses only a password is an open door.
- Understand your insurance policy. Read the exclusions. Know the sub-limits. Understand what your carrier expects you to maintain in terms of security controls, because they will check after an incident.
- Segment your network. Clinical systems, administrative systems, IoT medical devices, guest Wi-Fi: these should not all be on one flat network. Segmentation limits blast radius.
- Get an outside assessment. Internal IT teams are too close to their own environment to see the gaps. A third-party risk assessment, before an incident, is one of the highest-ROI investments in cybersecurity.
ArcLight’s Work in Healthcare
Healthcare has been a core focus for ArcLight Group since we started in 2008. We understand HIPAA. We understand the operational reality of keeping a medical practice or facility running while maintaining real security. And we know that healthcare organizations can’t afford the kind of downtime that comes from reactive, break-fix IT.

Brian Largent
Father to five, husband to one, founder, CEO, and all around swell fella (or so I'm told)



