Desk live·
ForensicPost
Ransomware/Healthcare/File 26-0304

US Healthcare Downtime Costs Around $900,000 per Day

US healthcare downtime is put at around $900,000 per day. Set against the Brockton hospital’s two weeks of paper procedures, the arithmetic explains a great deal about payment decisions.

Constructed geometry · not a chart of case data
JurisdictionUSAthe affected organisation’s jurisdiction, not the actor’s suspected origin
TargetUS healthcare providers
ActorMultiple
D. Kennedy10 min readConfidence: medium2 sources reviewed

Published analysis places average US healthcare downtime cost at approximately $900,000 per day. The same research notes encryption rates in US healthcare incidents falling to around 34% from 74% the previous year, with extortion-only attacks tripling to roughly 12% of cases.

The Arithmetic Is Uncomfortable And Worth Stating

Two weeks of downtime procedures, as at Brockton in 26-0407, implies costs in the region of twelve million dollars on that figure — against ransom demands this desk regularly sees in the low millions.

That comparison is precisely why we do not publish demands as headline figures. Printing a demand next to a downtime cost constructs an argument for payment, and it is an argument built on the attacker’s number.

Payment Does Not Buy The Recovery Time Back

The comparison is also technically wrong in a way that matters. A decryption key does not restore a hospital. Systems must still be validated, data integrity confirmed, and clinical records reconciled before staff can safely rely on them.

Organisations that pay frequently spend a similar period recovering. The cost avoided is smaller than the daily rate multiplied by the outage, and considerably harder to estimate in advance.

Falling Encryption Changes The Calculation Entirely

The shift from 74% to 34% encryption, with extortion-only tripling, means a growing share of healthcare incidents involve no encryption at all — nothing to decrypt, and therefore no operational argument for payment.

In those cases the only thing purchased is a promise of deletion, which the Instructure file at 26-0501 established cannot be verified. It is the same shift this desk observed in the claims data at 26-0603, and it is the likeliest explanation for falling payment rates.

How we reported this

This is an analysis file built on published sector research, listed below. Cost figures are averages across varied institution sizes and should be treated as indicative. Corrections: corrections@forensicpost.com.

Sources
  1. Ransomware in healthcare 2026: the attack timelineCybelAngel
  2. Healthcare ransomware roundup: H1 2026Comparitech
D. Kennedy
Identity and access reporter. Former DFIR consultant. Signal on request.
// the chain of custody — tuesdays

Get the next file first.

One incident a week, taken apart properly. Logs, timelines, and what the filing left out.

PGP-signed edition · no tracking pixels · one-click unsubscribe
© 2026 ForensicPost Media · the desk · newsletter · searchGlossary