Interlock held access to a dialysis provider for nineteen days, per 25-0412. Other operations worked hospitals, health systems and provider services through 2025 at the volumes this desk filed at 26-0426.
The Old Convention Was Always Marketing
Several established ransomware operations historically published rules claiming they would not target hospitals, and would supply free decryption if they hit one by accident.
That was never a constraint anyone could enforce. It was reputational positioning aimed at affiliates and at the law enforcement attention that healthcare attacks attract. Where it was observed at all, it was observed inconsistently.
The Affiliate Model Makes Stated Policy Meaningless
A ransomware-as-a-service operation does not choose its victims. Affiliates do, using access bought from brokers who sell whatever they have.
An operator publishing a healthcare exclusion is describing a preference it cannot implement, because the first time it knows the victim’s sector is frequently after encryption. This desk filed the affiliate dynamic at Qilin in 26-0705.
Why Healthcare Gets Hit Regardless Of Stated Ethics
The sector combines urgency that produces fast decisions, thin security capacity relative to data sensitivity, regulatory obligations that guarantee public disclosure, and the exact conditions this desk set out at 26-0330 for municipalities.
Graded medium: this is analysis across published incidents rather than a single sourced event, and stated group policies are self-reported claims we do not treat as evidence of behaviour.
This is an analysis file built on published incident reporting, listed below, read against files in this database. Group-published policies are actor claims and are labelled as such. Corrections: corrections@forensicpost.com.