Scripps Health, a CA-based healthcare provider with 25 facilities including 5 hospitals, says it expects to lose ~$106.8M after a ransomware attack in May 2021
Context & Ripple Effects
The Scripps disclosure is one stop on a steep cost curve for hospital ransomware that this coverage has been tracking since Hollywood Presbyterian went dark for more than a week in 2016 facing a $3.6M demand, followed by UCSF paying roughly $1.14M in bitcoin mid-pandemic in 2020. What changed by 2021 is that the bill stopped being dominated by ransoms at all — Scripps is booking a $106.8M expected loss across its five hospitals, implying most of the damage is downtime and remediation rather than payment.
That pattern has only intensified since: the FBI investigated the Prospect Medical Holdings attack on 16 hospitals two years later, and UnitedHealth put the Change Healthcare hit at $872M for Q1 2024 alone. Scripps matters because it was among the first multi-hospital systems to publicly quantify a nine-figure total, giving the sector a benchmark between the early million-dollar incidents and the later mega-losses.
First-order effects
- Scripps Health absorbs a ~$106.8M expected loss across its 25-facility network — a direct revenue and recovery hit borne by the system itself, not an insurer or payer.
- The disclosure forces other California hospital operators to price downtime, not ransom demands, as the dominant line item when they model their own attack scenarios.
Second-order effects
- Cyber insurers covering hospital systems reprice coverage upward as realized losses climb from the ~$1.14M UCSF payment toward nine figures, squeezing provider security budgets further.
- Rivals and peer systems respond by shifting spend toward resilience and recovery capability — backup infrastructure and incident response — since the Scripps figure shows extortion is a minor fraction of the true cost.
Third-order effects
- If the trajectory from Scripps' $106.8M through Prospect to UnitedHealth's $872M quarter holds, healthcare becomes a sector where single cyber events are systemically material, inviting regulator involvement of the kind already seen with the FBI's Prospect investigation.
- Hospital groups may consolidate security operations and shared services across systems, because standalone facilities cannot absorb nine-figure tail risks on their own balance sheets.
The trend: Healthcare ransomware economics have shifted from small ransom payments toward hundred-million-plus operational losses, turning cyber resilience into a balance-sheet issue for hospital systems.