1. HTTPS prevents ads/trackers/malware being injected into the page by unscrupulous ISPs. Man-in-the-middle attacks of this sort really have happened, [0] and remember that the browser itself may have exploitable security vulnerabilities.
2. Modern browsers will (rightly) warn users not to trust the site. This makes the site look bad.
3. Some fancy browser features are disabled if you use unencrypted HTTP. Likely irrelevant for a static site though.
4. Privacy matters. A medical website, or indeed Wikipedia, should prevent a snooping ISP from finding out you have been reading about an embarrassing condition. This is similar to the way librarians are extremely protective of their loan records [1]. Netflix use HTTPS for their streams, for the same reason (it does nothing to aid their DRM, it's purely about privacy) [2].
5. Let's turn the tables and ask why you wouldn't use HTTPS for a public-facing web server. There are just 3 reasons:
* Reduced admin overhead not having to bother with certs
* It enables caching web proxies, which is only relevant if you're running a serious distribution platform like Steam, or a Linux package-management repo [3]
* Better support for very old devices, such as old smartphones in the developing world
[0] https://doesmysiteneedhttps.com/
[1] https://www.theguardian.com/us-news/2016/jan/13/us-library-r...
[2] https://arstechnica.com/information-technology/2015/04/it-wa...
[3] https://web.archive.org/web/20200615045650/http://whydoesapt...
(Based on an old comment of mine at https://news.ycombinator.com/item?id=22147858 )