Liat Hayun, senior vice president of product management at cybersecurity firm Tenable, says the FAIR framework provides the healthcare industry with the discipline it needs more than most industries to keep it accountable.
“For too long, the sector has relied on subjective heat maps and severity scores that fail to communicate actual business exposure to executives,” Hayun says.
The framework assigns a dollar amount to potential losses based on the frequency and financial magnitude of potential cyberattacks. Hayun explains that health systems face difficulties in convincing finance teams to invest in cybersecurity because of the organizations’ standard vulnerability ratings.
“FAIR gives healthcare security teams a common unit for comparing risks that otherwise look completely unrelated, like a ransomware scenario versus a third-party vendor breach,” Hayun says. “By evaluating the likelihood of an attack and its financial magnitude, a CISO can prioritize budget requests in the context of actual impact instead of simply reacting to whichever finding is loudest.”
Why Ransomware Attacks in Healthcare Are So Expensive
Ransomware is particularly costly in healthcare because health providers cannot shut down their systems during an attack. Disconnected electronic health record (EHR) software, imaging tools and medical devices directly affect patient care. Shutdowns from ransomware attacks also lead to canceled procedures, diverted ambulances and stalled billing cycles, Hayun says.
“Because an IT outage in healthcare directly impacts patient safety, connected infrastructure and immediate cash flow, ransomware becomes exponentially more damaging than in almost any other sector,” she explains.
Not only is ransomware costly in dollars, but these incidents increase in-hospital mortality by up to 38%, according to a February 2026 study in American Economic Journal: Economic Policy. Ransomware at hospitals also drives up cardiac arrests at these facilities by 81% per an April 2024 study by University of California, San Diego researchers in Critical Care Explorations.
READ MORE: Quantify cyber risk to justify strategic cybersecurity investments.
HIPAA exposure from ransomware attacks, along with an aging device fleet, also puts healthcare systems at financial risk. Compromised patient data leads to mandatory breach notifications as well as credit monitoring, regulatory fines and legal fallout, Hayun notes.
“Ultimately, the ransom demand is just the down payment,” she says. “The true fee is the combined burden of weeks of operational downtime, infrastructure restoration and the lasting legal consequences.”
Healthcare is targeted because it is a highly regulated industry with sensitive protected health information (PHI), Dunn says.
“Criminals know this, so they go where they’re going to make the most money,” Dunn says.
