Ransomware is not a big-hospital problem that trickles down to small practices. In 2025, healthcare was the single most targeted sector, and independent practices are squarely in the blast radius. According to Sophos's State of Ransomware in Healthcare 2025, 66 percent of healthcare organizations were hit by ransomware. The question for a practice is no longer whether attackers are interested. They are. The question is whether your environment gives them an easy way in.
Here is why medical practices are such a target, how these attacks have shifted, and the specific controls that actually stop them.
Why attackers focus on healthcare
Three things make a medical practice attractive to a ransomware crew.
- The data is valuable and sensitive. Protected health information is worth more than a credit card number on the underground market, and the sensitivity gives attackers leverage. A practice facing patient-data exposure has a powerful incentive to make the problem go away.
- Downtime is intolerable. When a clinic cannot access schedules, charts, or e-prescribing, care stops. That urgency is exactly what attackers are counting on. Pressure is the product they are selling.
- Security is often thinner than the data deserves. Large systems have security teams. Independent and small-group practices frequently run on aging equipment, a part-time IT arrangement, and tools that were installed once and never revisited. The gap between the value of the data and the strength of the defense is widest in exactly these practices.
The attacks have changed, and it matters for how you defend
The old mental model of ransomware was encryption: your files get locked, you pay for the key. That is no longer the main threat. In 2025, 96 percent of healthcare ransomware attacks involved data exfiltration, meaning attackers stole the data before, or instead of, encrypting it. Encryption fell to its lowest level in five years.
This shift changes the math. A clean backup will get your systems running again, but it does nothing about a copy of your patient data sitting on an attacker's server. That is why the modern defense is not just "have backups." It is preventing the intrusion in the first place, detecting it fast when it happens, and being able to prove what did and did not leave the building.
It is also why paying the ransom has fallen out of favor. Only 36 percent of healthcare providers paid in 2025, down from 61 percent in 2022, and average recovery costs still ran to 2.73 million dollars. Paying does not un-steal the data, and it does not guarantee recovery.
What actually prevents ransomware
There is no single product that makes a practice ransomware-proof. Prevention is a layered posture, and each layer catches what the others miss. The controls below are also, not coincidentally, the ones cyber insurance carriers now require before they will write or renew a healthcare policy.
- Multi-factor authentication everywhere it matters. Most small-practice breaches start with one compromised email account. MFA on email, remote access, and any system touching PHI closes the most common front door. Carriers increasingly require phishing-resistant MFA on privileged and remote access.
- Endpoint detection and response, not just antivirus. Traditional antivirus catches known malware by signature. EDR watches behavior and catches a process doing something it should not, even if the file has never been seen before. EDR has moved from recommended to required.
- Email security beyond the defaults. Phishing filtering and attachment scanning that go past the standard Microsoft 365 protections, because the standard configuration is not the secure one.
- 24/7 monitoring with real humans. Attacks do not wait for business hours. A Security Operations Center watching the environment around the clock, with analysts investigating real alerts, is what turns a 3 a.m. intrusion into a contained event instead of a morning catastrophe.
- Tested, offline backups. Backups are your recovery path, but only if they are isolated from the network and you have actually restored from them. An untested backup is a guess.
- A documented incident response plan. When something does get through, the difference between a bad week and a reportable disaster is having a playbook, practicing it, and being able to produce the documentation regulators want.
Miss a layer and you have left open the exact door attackers are trained to find.
The cost of an unprepared practice
The financial picture is stark. IBM's 2025 Cost of a Data Breach Report put the average healthcare breach at 7.42 million dollars, the highest of any industry for the 14th year running, and healthcare breaches took an average of 279 days to identify and contain. For an independent practice, recovery time is measured in days when the environment is prepared and in weeks or months when it is not. The layered controls above are not expensive relative to that downside. The breach is the expensive option.
There is also the compliance overlay. A ransomware incident that exposes patient data is very likely a reportable HIPAA breach, with the OCR penalty exposure that comes with it. Prevention and compliance are the same project.
What Galleon does about it
We configure each of these layers and, just as importantly, operate them together as a system. We run managed EDR across every device, a 24/7 Security Operations Center monitored by real human analysts, email security that goes past the Microsoft 365 defaults, and tested backup and disaster recovery. Base-level cybersecurity is included in our managed IT pricing, with tiered packages for practices that need more robust protection. We have walked practices through real ransomware, business email compromise, and data-exposure incidents, and our focus is always to contain, restore, and document so any reporting obligation is met cleanly.
The best time to find your gaps is before an attacker does.
Explore our Cybersecurity and Backup and Disaster Recovery services, take the free IT Risk Assessment for a fast picture of where you stand, or schedule a discovery call.