Hospitals are why I don't "blame" underinvestment into cybersecurity. Their #1 goal is saving people's lives, not messing with IT issues. You want hospitals to be paying for important equipment, important people, important skills. The whole IT part is just supporting the administrative tasks.
But yes, it means that paying the ransom is the better move a lot of the time than to actually try to restore IT services.
--------
At some point, it becomes more efficient to go after the hackers, rather than trying to defend every single Hospital.
Ex: When REvil accidentally hacked an oil-pipeline (instead of a more passive target), the blowback was so severe that REvil disbanded and ran away. It caused an international incident, to the point where Russia has caught the attackers and is offering them up to the USA as a peace offering.
What is rather unfortunate, is that we put more importance to our oil-infrastructure than our hospital infrastructure. But these ransomware attacks on health care has been going on for years. Its not new.