Medusa Ransomware Surge Threatens Healthcare Systems Nationwide

2 min readSources: National Law Review

Medusa ransomware attacks on unpatched healthcare systems have surged in 2026.

Why it matters: Healthcare legal teams face heightened ransomware litigation risks and evolving data privacy regulations amid these attacks. Understanding attack vectors helps in compliance and defense.

  • Medusa ransomware impacted over 500 critical infrastructure organizations by April 2026, with healthcare a key target.
  • Attacks exploit unpatched vulnerabilities like ScreenConnect authentication bypass and Fortinet EMS SQL injection.
  • Healthcare ransomware attacks rose 14% in H1 2026, totaling 410 incidents compared to late 2025.
  • Medusa affiliates exploit new software vulnerabilities within 24 hours, sometimes before public disclosure.

Medusa ransomware continues to escalate as a major threat to the healthcare sector, targeting unpatched systems and exploiting recently disclosed software flaws. According to an American Hospital Association update, more than 500 critical infrastructure organizations have experienced Medusa attacks by April 2026, with healthcare providers among the most affected.

The ransomware operates via a ransomware-as-a-service (RaaS) model, where initial access brokers receive payments ranging from $100 to $1 million to breach networks, according to Becker's Hospital Review. Once inside, Medusa exploits specific unpatched vulnerabilities such as ScreenConnect authentication bypass, Fortinet EMS SQL injection, Fortra GoAnywhere deserialization, and BeyondTrust remote code execution.

Agencies including CISA, FBI, and HHS have warned that Medusa affiliates aggressively weaponize newly disclosed vulnerabilities, often within 24 hours of announcement and sometimes even prior to public disclosure. This aggressive timeline challenges healthcare IT teams to deploy patches rapidly.

The healthcare industry is already feeling the impact: ransomware attacks increased 14% in the first half of 2026 compared to the last six months of 2025, with 410 incidents recorded, as reported by TechTarget. John Riggi, AHA National Advisor for Cybersecurity and Risk, noted, "Medusa ransomware has been used by threat actors to conduct malicious activity against U.S. hospitals and health systems over the last several years."

For healthcare legal teams, these developments elevate the urgency to prepare for ransomware litigation risks and to anticipate further tightening of data privacy regulations. Ensuring timely patch management, vulnerability assessments, and incident response plans will be critical in mitigating legal and compliance exposure.

By the numbers:

  • 500+ critical infrastructure organizations affected — as of April 2026 by Medusa ransomware
  • $100 to $1 million — payments to initial access brokers facilitating breaches
  • 410 ransomware attacks — on healthcare organizations in the first half of 2026, a 14% increase from late 2025