Ransomware in care delivery is a patient-safety event, not an IT incident

When systems go down in a hospital, clinical risk starts accumulating in minutes. Health organizations that plan for degraded operations — not just data recovery — protect what actually matters.

Cybersecurity PracticeMarch 25, 20262 min read

Every industry describes ransomware in the language of downtime and data. Healthcare is the industry where that language fails. When the electronic health record is unreachable, medication histories, allergies, imaging, and orders vanish from the point of care. Ambulances divert. Surgeries reschedule. Clinicians revert to paper workflows many have never used under pressure. A growing body of research and regulatory attention has converged on what frontline staff already knew: a cyberattack on a hospital is a clinical event, with clinical consequences.

Framing it that way is not rhetoric. It changes who owns the risk, how response is rehearsed, and what gets funded.

The estate is uniquely hard — and uniquely targeted

Care-delivery environments combine the worst structural conditions in security: thousands of connected clinical devices that cannot be patched on IT timelines; 24/7 operations with no maintenance window that does not affect a patient somewhere; workforces whose primary duty is speed of care, not credential hygiene; and data whose sensitivity makes extortion doubly effective. Attackers understand the asymmetry perfectly — the pressure to restore care makes healthcare among the most payment-prone sectors, which is precisely why it stays targeted.

Defense under these conditions is about ruthless prioritization: identity controls and phishing-resistant authentication where credential theft does the most damage; segmentation that keeps a compromised administrative network away from clinical systems; and — because prevention will sometimes fail — detection tuned to catch the hours-to-days of staging that precede encryption.

Plan for degraded care, not just recovery

The continuity plans we review in health organizations are usually restoration plans: how IT brings systems back. The plans that save patients are degradation plans: how care continues while systems are gone. Which clinical services keep operating on paper, and which must transfer. Where the downtime forms actually are, and when staff last drilled with them. How medication safety works without electronic checks. How long each department can run degraded before clinical risk becomes unacceptable — a number that should drive recovery sequencing more than any IT metric.

The organizations that handle major incidents well have rehearsed exactly this, jointly between clinical leadership and security, with the same seriousness as a mass-casualty exercise. The ones that struggle had a binder.

Resilience is a procurement discipline too

Care delivery increasingly runs on a handful of shared platforms — EHR vendors, revenue-cycle processors, imaging and lab networks. Recent years have shown that a single vendor’s outage can degrade care across an entire region. Third-party resilience — contractual recovery commitments, tested fallbacks, exit paths — belongs in clinical-risk governance, not just vendor management.

What to do about it

Put cyber risk on the patient-safety agenda formally, with clinical ownership beside the CISO. Run one full degraded-operations exercise this year — paper workflows, diverted services, real clinicians — and let its findings, not a framework, set the security roadmap. In this sector, the measure of a security program is not whether you can prevent every intrusion. It is whether patients stay safe on the day one succeeds.

Put this thinking to work

If this article describes a problem you are living with, the practice that wrote it can help.