Skip to content
Kentron Technologies

CybersecurityHospitalsCERT-In

Hospital ransomware in 2026: CERT-In, DPDP and a checklist

Healthcare ransomware attacks rose 14 percent in the first half of 2026 and India's provider attacks grew eightfold. What CERT-In and the DPDP Rules now expect.

Author
Kentron Technologies
Published
Reading time
5 min read
A doctor at a desk

Ransomware groups attacked healthcare organisations 410 times in the first half of 2026, up 14 percent on the previous six months, and India's provider attacks grew eightfold from a small base. CERT-In issued an advisory in April, a blueprint in May and vendor guidelines in June on AI-accelerated attacks, and the DPDP Rules add a 72-hour reporting duty from 2027. This article summarises what hospitals and labs are now expected to do.

The numbers

Comparitech's healthcare roundup, published on 9 July 2026, counted 410 ransomware attacks on healthcare in the first half of 2026, 247 on providers such as hospitals and 163 on healthcare businesses, a rate of 2.3 a day and a 14 percent rise over the 360 attacks in the second half of 2025. The median ransom demand on providers was $310,000. Confirmed attacks on providers exposed 424,740 records. For India, the report notes provider attacks grew by 700 percent between the two halves, and it lists a confirmed attack on Rajagiri Hospital in March 2026 by the group The Gentlemen. Qilin was the most active group against providers, with eight confirmed attacks.

The Indian Journal of Critical Care Medicine published a paper in May 2026 describing ransomware as a patient-safety problem for ICUs. It recalls the November 2022 attack on AIIMS Delhi, which compromised about 50 servers and left the hospital information system inaccessible for over two weeks, with inpatient, outpatient and laboratory services reverting to paper.

IndicatorFirst half of 2026Source
Healthcare ransomware attacks worldwide410 (247 providers, 163 businesses)Comparitech
Change from second half of 2025up 14% from 360Comparitech
Attacks per day2.3Comparitech
Median ransom demand on providers$310,000Comparitech
India provider attacks, change from second half of 2025up 700% from a small baseComparitech
Records breached at providers in confirmed attacks424,740Comparitech

What CERT-In has said this year

CERT-In issued an advisory titled Defending Against Frontier AI Driven Cyber Risks on 26 April 2026, followed on 25 May by a blueprint on AI-assisted exploitation that Medianama summarised on 27 May 2026. The blueprint is advisory, not mandatory, and names healthcare among the sectors facing higher exposure. Its remediation timelines are specific: a known exploited vulnerability on an internet-facing system should be contained or patched within 12 hours where feasible, a critical externally exposed vulnerability within one day, a critical internal vulnerability on a high-value system within three days, and a high-severity vulnerability within five days.

On 10 June 2026 CERT-In published guidelines for OEMs and technology providers, explicitly including software vendors, cloud and managed service providers and system integrators supplying Indian organisations. They ask vendors to run continuous vulnerability assessment on deployed products, to test with AI-assisted methods as well as conventional ones, and to supply a bill of materials covering hardware, software, cryptography and AI to their Indian customers. The document names healthcare among the exposed sectors. For a hospital, this is a checklist to hand to its HMIS and LIMS vendors.

The older obligations still stand. CERT-In's 2022 directions require covered organisations to report specified incidents within six hours of noticing them and to keep system logs for 180 days.

What the DPDP Rules add

Rule 7 of the DPDP Rules 2025 requires a data fiduciary that becomes aware of a breach to inform affected individuals without delay, to give the Data Protection Board an initial description without delay, and to file a detailed report within seventy-two hours. The rule takes effect eighteen months after publication of the Rules in November 2025, which is May 2027. Failure to maintain reasonable security safeguards carries a penalty of up to ₹250 crore, and failure to notify a breach up to ₹200 crore. Hospitals, clinics and diagnostic labs are data fiduciaries under the Act.

What this means for hospitals and labs

The IJCCM paper's tiered framework is the most useful thing in this article, because it starts with what a district hospital can do with no budget.

  • Tier 1, the minimum: pre-printed admission and escalation orders, paper medication charts, a downtime kit for high-alert drugs, named roles for a downtime lead and a documentation marshal, quarterly tabletop drills and an annual simulated downtime.
  • Tier 2, mid-resource: a weekly refreshed offline device with protocols and drug references, network segmentation that isolates clinical devices from administrative networks, and a restoration order that puts laboratory and pharmacy systems first.
  • Tier 3, tertiary: redundant data centres, immutable backups with routine restoration tests, and a security operations function.

Add the compliance layer on top: a six-hour CERT-In report, a 72-hour DPDP report, the patch timelines from the blueprint, and a vendor bill of materials.

  1. Ask each software vendor, in writing, for its patch timelines, bill of materials and breach-notification commitment, citing the June 2026 guidelines.
  2. Test a restore from backup this month, and time it.
  3. Put the ICU monitors and lab analysers on a separate network segment from the office network.
  4. Write the six-hour and 72-hour notifications now as templates with blanks.
  5. Run a two-hour downtime drill with the front desk, pharmacy and lab.

For our part, Healthixio and Pathixio are hosted in India with encrypted backups and audit logs, and the vendor questions above are ones we expect to be asked. Ask the same of every vendor you have.

Frequently asked questions

Is a small hospital really a target?

Comparitech's data shows attacks on Indian providers rising sharply from a small base, and the groups involved use automated scanning that does not check bed count. The 2022 AIIMS attack shows the operational impact: over two weeks on paper. A 50-bed hospital with an internet-facing HMIS and no tested backup is an easier target than a tertiary centre.

What has to be reported, and to whom?

Under CERT-In's 2022 directions, specified cyber incidents must be reported to CERT-In within six hours of being noticed, with logs retained for 180 days. From May 2027, Rule 7 of the DPDP Rules also requires affected patients to be told without delay and a detailed report to reach the Data Protection Board within 72 hours of becoming aware of the breach.

What is the first thing to fix?

Backups you have actually restored. The IJCCM framework puts tested restoration and paper downtime procedures ahead of everything else, and CERT-In's blueprint puts patching of internet-facing systems within hours. Do the restore test, segment the clinical network, write the notification templates, and only then spend money on tools.

Kentron Technologies

Editorial team

Builds and runs Kentron Technologies’s products. Writes here when a decision was hard enough to be worth explaining.

Next step

Tell us what you are running, and what is slow.

A demo of any product, or a conversation about something that does not exist yet. Either way, you will talk to someone who builds the software.

CallWhatsAppTalk to us