Real incidents. Real patient impact. Real framework gaps. Every entry represents patients whose care was disrupted — ransomware attacks on healthcare are attacks on human life, not just data.
Most trackers count records breached. This one asks what happened to patient care. Each incident is scored only on care-disruption factors a public report actually confirmed — emergency diversion, cancelled treatment, EHR downtime, paper charting, multi-facility spread, documented patient-safety impact — weighted by clinical triage priority. A data-only breach scores zero on continuity no matter how many records leaked; that gap between records lost and care disrupted is the point. — Chaunda C. Dallas, DFR Framework
Attacks on healthcare businesses — vendors, MSPs, billing providers — surged 30% in 2025. Hitting one vendor cascades disruption across hundreds of providers at once.
For the first time in three years, exploited vulnerabilities (33%) passed credential-based attacks as the leading technical root cause.
In H1 2026, Qilin and The Gentlemen led healthcare ransomware claims, with INC Ransom and NightSpire most active against healthcare businesses. Medusa, Anubis, and Genesis each surfaced in major Q1 hospital incidents tracked above.
Health-sector security pros now rank AI-enabled attacks as the top threat for 2026 — surpassing ransomware for the first time.
Kettering was breached April 9, triggered May 20 — six weeks undetected. Early detection remains the highest-impact defensive investment.
No framework adequately covers the clinical continuity dimension — what happens to patients during downtime. HIPAA, NIST, and HHS 405(d) protect data, not care delivery. That's the gap this lab documents.