Skip to content
The Cyber Security Place

Health

The sector where a breach is measured in minutes

Everywhere else the unit is money. Here it is waiting time in an emergency department, and it is charged to hospitals that were never attacked.

Last reviewed August 30, 2026

Research published in early 2026 found in-hospital mortality among patients already admitted when an attack begins rises by 34 to 38%. Across 374 studied attacks, 44.4% disrupted care delivery, for an average of15.8 days. The attacked hospital's own volume falls 17 to 24% in the first week — and the load lands next door: emergency arrivals at hospitals that were not attacked rise about 35%, with documented increases in stroke activations and cardiac arrests among diverted patients. Healthcare remains the costliest sector for the 13th consecutive year at about $6.64m, though that figure fell 10.5% while the global average rose — and breach-cost studies count what the breached organisation spends, never the waiting time at the hospital that absorbed its patients.

Where do the patients go?

Take a hospital offline and its patients do not stop existing. They arrive somewhere else, at facilities that were not attacked, had no say in the matter and are now running above their normal load.

If City General goes offline

HospitalArrivals a dayWaitChange
City General· offline208—systems down
University Hospital37366 min+15 min
District Hospital16849 min+11 min
Rural Trust7029 minunchanged

If University Hospital goes offline

HospitalArrivals a dayWaitChange
City General33159 min+17 min
University Hospital· offline248—systems down
District Hospital17853 min+15 min
Rural Trust7029 minunchanged

If District Hospital goes offline

HospitalArrivals a dayWaitChange
City General28247 min+5 min
University Hospital33757 min+6 min
District Hospital· offline112—systems down
Rural Trust7029 minunchanged

If Rural Trust goes offline

HospitalArrivals a dayWaitChange
City General27646 min+4 min
University Hospital31051 minunchanged
District Hospital14941 min+3 min
Rural Trust· offline56—systems down

A model, not measured facilities. The multipliers come from published findings —35% more ambulance arrivals at hospitals that were not attacked, a 20% fall in the attacked hospital's own volume, and a disruption averaging 15.8 days. How sharply waiting time rises with load is a declared assumption rather than a measurement.

The number worth carrying away is the one in the last column. When University Hospitalgoes down in this model, 2 hospitals that were not attacked have longer waits, and the worst-affected — City General — sees its wait rise by 17 minutes for 15.8 days on average. That cost appears on nobody's incident report. It is not in the attacked organisation's loss estimate, not in its insurance claim, and not in the sector figures that describe breaches as an expense borne by the breached.

Why is an outage here different?

Every organisation says it cannot afford downtime. Most are describing revenue. A hospital is describing a queue of people whose conditions continue to develop while the queue does not move, which is a different kind of clock and the reason extortion finds this sector so productive.

The mechanism of harm is worth being precise about, because it is not what the phrase "hospital hacked" suggests. Nobody adjusts a ventilator. What happens is that the record system goes down, and with it the ability to know what a patient is allergic to, what they were prescribed last week, what their last scan showed and what their bloods said this morning. Clinicians continue working, more slowly and with less information, and the accumulated effect of many small delays across many patients is measurable in outcomes.

That is what the mortality finding describes. The increase of roughly a third among patients already admitted when an attack begins is not a story about anybody being targeted; it is what happens when an entire institution loses several days of precision at once. The same research puts the estimate at a few dozen preventable deaths across five years in one country's Medicare population alone — a small number against national mortality and an enormous one against the way this subject is usually costed.

There is also a reason the disruption lasts. Bringing systems back is not the end of it: every appointment cancelled during the outage still needs to happen, every procedure postponed joins a waiting list that was already long, and the backlog is worked through at the same rate as everything else. An average disruption of about sixteen days to care delivery understates the recovery, which continues quietly for months.

Why did the paper fallback stop working?

Ask anyone outside the sector what a hospital does when its computers fail and the answer is that it goes back to paper. Hospitals do exactly that, and it works far less well than it used to, for a reason that has nothing to do with forms.

Paper is an output medium, not a source. Writing an observation on a chart is easy; knowing what to write requires the history, the allergies, the current medication list, the imaging and the results, and those now exist in one place. A clinician with a blank chart and an unfamiliar patient cannot safely prescribe, and the careful ones do not. The fallback fails on the information, not on the stationery.

The organisations that cope best have understood this and hold a small amount of clinical information somewhere the outage cannot reach — a nightly extract of active patients, their medication and their key alerts, printed or on a machine that is not part of the estate. It is unfashionable, it is manifestly a stopgap, and it is the difference between a slow week and a diverted ambulance.

Rehearsal matters more than the document. A downtime procedure that exists in a folder and has never been used will be discovered, during the incident, to depend on a directory that is also down or a phone list nobody maintained. The wards that manage are the ones that practised badly a few times in advance, which costs an afternoon and is refused for exactly the reason it is needed.

When the sector lost its paper option

411 entries in this archive concern healthcare security, of which 66 mention ransomware and 32 mention medical devices.

102014392015532016902017472018572019582020492021

The rise tracks dependency rather than adversaries. These are the years in which electronic records went from a project to the only place the information lives, and a sector that could once run on paper for a day gradually lost that option without anybody deciding to give it up. The ratio in those figures is worth noting too: the coverage concentrates on the attack that stops a hospital working rather than on the equipment inside it, and for once the coverage is pointing at the right thing. The earliest ransomware piece here, The fbi is investigating ransomware based attack at methodist hospital, predates the incidents that made the pattern famous.

A figure that moved the wrong way

Healthcare has recorded the highest average breach cost of any industry for thirteen consecutive years, and in the most recent measurement that average was about $6.64m. The interesting part is the direction: it fell by roughly a tenth while the global average across all sectors rose by 12%.

There are at least three readings and the honest position is that the data does not choose between them. The sector may genuinely be improving, which would be consistent with a decade of regulatory attention and considerable investment. The mix of counted incidents may have shifted toward smaller organisations, which pulls an average down without anything improving. Or the costs may be moving to places the measurement does not reach, which is the reading this page finds most plausible given everything above.

Breach cost studies count what the breached organisation spends: response, notification, legal work, lost business, regulatory penalties. They do not count the waiting time at the hospital down the road, the ambulance that travelled further, or the procedure postponed by six weeks. Those are real costs borne by real people, and they are invisible to an instrument that asks organisations what they spent.

None of which makes the figure useless. It makes it a measure of one party's expenses rather than of the harm, and the gap between those two things is unusually wide in this sector. Anyone using breach cost to argue for investment in a hospital is arguing with the smaller number.

The medical device question

Connected medical equipment attracts more coverage than any other part of this subject, and the reason is narrative rather than evidential. A compromised infusion pump is a vivid and frightening image. It is also, so far, an unusual event, while the encrypted record system that slowed an entire hospital for a fortnight is common and hard to photograph.

The genuine device problem is duller and larger. A hospital runs thousands of connected things — scanners, monitors, pumps, analysers — bought over two decades, certified in the configuration they shipped with, and frequently running operating systems whose support ended years ago. They cannot be patched without revisiting the certification, they cannot be replaced without a capital programme, and they sit on the same network as everything else because that is how they were installed.

Which makes the answer the same as in any plant: change the surroundings rather than the device. Put the equipment where only what needs to reach it can, accept that it will remain vulnerable, and monitor for it behaving unlike itself. Regulators have moved in this direction too, with expectations that manufacturers ship equipment that can be updated and disclose what is inside it, which helps for machines bought from now on and does nothing for the scanner installed in 2014. The archive's earliest device piece, FDAnews Announces — Software and Cybersecurity Risk Management for Medical Devices Workshop, April 14-15, 2015, was already making the point about equipment lifespan.

What actually reduces the harm

The measured harm is delay, so the measures that address it are the ones that let clinical work continue while the systems are gone. That reorders the usual priority list considerably.

A rehearsed downtime procedure comes first, with the emphasis on rehearsed. Second is offline availability of the minimum clinical information — active patients, medications, allergies, key results — refreshed nightly and held where an attack on the estate cannot reach it. Third is a restore that somebody has performed and timed, because the difference between a two-day and a two-week outage is the largest single factor in how much harm accumulates.

After those, the ordinary work applies with ordinary priority: phishing-resistant authentication on remote access and administrative accounts, segmentation between the record systems and everything else, and the removal of anything reachable from the internet that does not need to be. None of that is specific to medicine, which is rather the point — the sector's distinguishing feature is the consequence of failure, not the mechanism of it.

The regional dimension deserves its own line, because no single organisation owns it. Neighbouring hospitals discover their mutual dependency during the incident, when the diversion begins, and the arrangements that help — an agreed way to share capacity information, a plan for who absorbs what — have to exist beforehand. That is a job for whoever holds the region rather than for any hospital's security team, and it is the part of this problem most consistently left unowned.

Who pays when the harm lands next door?

Nobody, in any formal sense, and that is the structural problem underneath everything on this page. The hospital that was attacked bears its own recovery cost and will report it. The hospital that absorbed its ambulances bears longer waits, a stretched rota and worse outcomes for its own patients, and there is no instrument anywhere that records this as a cost of the attack.

This is a familiar shape in other fields. An externality is a cost created by one party and paid by another, and the standard remedies are regulation, liability or insurance. None of the three currently reaches this case. Health regulators assess organisations individually against their own obligations; liability requires somebody to have been negligent toward a party they owed a duty to, which the neighbouring hospital is not; and insurance covers the policyholder.

The practical consequence is that the party best placed to reduce the regional harm has the least reason to spend on it. A hospital investing in faster recovery is buying a benefit that partly accrues to institutions down the road, which is exactly the condition under which economists expect underinvestment — and exactly what the sector's spending patterns look like.

Where this has been addressed at all, it has been through regional coordination rather than through anybody's security budget: shared arrangements for capacity information, agreed diversion protocols, and in a few places a regional body that funds resilience across facilities rather than leaving each to argue for it alone. Those arrangements are unglamorous, cheap relative to the harm, and consistently nobody's responsibility until after an incident makes them somebody's.

The ransom decision, when the currency is time

Across the economy the share of victims paying has fallen sharply, and refusal is now the majority position. That shift rests on an argument that holds up well in most organisations: paying funds the next attack, the decryption tool is often slow or incomplete, and a tested restore gets you back regardless.

Each of those points survives contact with a hospital, and each one becomes harder to say out loud. A restore measured in days is a perfectly good answer for a manufacturer and a different proposition for an emergency department, because the cost of those days is not revenue. The people making the decision know the mortality research, and they know that the interval they are choosing is the variable it measures.

What tends to resolve it in practice is that paying does not shorten the interval as much as the decision-maker hopes. Decryption of a large estate takes days on its own, much of it proceeding in parallel with the restore that was happening anyway, and the clinical systems come back in an order determined by dependencies rather than by payment. Organisations that have been through both routes generally report that the money bought less time than expected, which is worth knowing in advance because nobody is in a state to evaluate it during.

The decision that actually matters is therefore made long before: how quickly can this organisation restore, and has anybody measured it. A hospital with a rehearsed answer has removed most of the leverage; one without it will make the payment decision under duress, with a clock it cannot see, and in a situation where the argument for paying is genuinely stronger than the standard advice acknowledges.

The supplier no patient has heard of

A hospital's dependencies extend well past its own walls, and the ones that matter are frequently invisible to everybody using the service. Claims clearing, pharmacy eligibility checks, transcription, imaging archives, laboratory interfaces and appointment systems are often operated by third parties, sometimes by a single third party across a large share of a country's providers.

The 2024 attack on a payments clearing house demonstrated what that concentration means. The company was unknown to the public, sat between patients and their prescriptions, and its outage stopped pharmacies dispensing and providers being paid across an entire national system — eventually reported as affecting around 193 million people. No individual hospital had made a bad decision. Each had contracted with a normal supplier for a normal service, and the aggregate was a single point of failure nobody had chosen.

Concentration of this kind is hard to address from inside one organisation, because the alternatives are frequently the same supplier under a different name, or do not exist. The realistic move is to know which dependencies would stop clinical work and to have a manual path for each — a way to dispense without eligibility checking, a way to receive results without the interface — rather than to pretend the dependency can be removed.

It also argues for asking a question that procurement rarely covers: what happens to us if this supplier is down for two weeks. Contracts reliably specify uptime and penalties, which compensate for a loss rather than preventing it, and a penalty clause has never yet dispensed a prescription. The useful contract term is not the service level but the obligation to tell you promptly when the service has gone, and to keep telling you while it is away.

Common questions

Why is healthcare attacked so often?

Two properties combine badly. The data is unusually valuable because a medical record cannot be reissued like a card number, and the operational pressure to keep running is unusually high because the alternative is turning away patients. Extortion works best where the victim cannot wait, and few organisations can wait less than a hospital.

Do ransomware attacks on hospitals harm patients?

The evidence now says yes and quantifies it. Research published in early 2026 found in-hospital mortality among patients already admitted when an attack begins rises by roughly 34 to 38 per cent. A separate study of 374 attacks found 44.4% disrupted care delivery, with disruption lasting an average of 15.8 days.

What happens to hospitals near one that is attacked?

They absorb the load and their own patients wait longer. Emergency arrivals at hospitals that were not attacked rise by around 35% while a neighbour is offline, with documented increases in stroke activations and cardiac arrests among the diverted population. The harm reaches organisations that did nothing wrong and had no say.

How much does a healthcare breach cost?

Around $6.64m on average, the highest of any industry for the thirteenth consecutive year. The figure fell about 10.5% year on year while the global average across all sectors rose 12%, which is worth noting rather than celebrating: it may reflect genuine improvement, or a change in the mix of incidents being counted.

Why can't hospitals just switch to paper?

Many still try and it works far less well than it used to. Paper fallback assumes the information to write on it is available, and history, allergies, current medication and imaging now live only in systems that are down. Prescribing safely for an unfamiliar patient without their record is the constraint, not the absence of forms.

Are medical devices the main problem?

They receive attention out of proportion to observed harm. Attacks that manipulate a device are rare and dramatic; attacks that encrypt the systems the ward depends on are common and quietly damaging. Device security matters and it is not where the deaths documented so far have come from.

Why is medical equipment so old?

Because it is certified. A device approved for clinical use is approved in a configuration, replacement is a capital purchase competing with clinical priorities, and a scanner bought for fifteen years of service will spend most of them running software nobody updates. The constraint is the same one industrial plants face, with a regulator attached.

Does HIPAA make hospitals secure?

It makes them accountable for confidentiality, which is a narrower thing. The regime was built around disclosure of records and fits awkwardly around an attack whose harm is that the ward cannot function. An organisation can be substantially compliant and still lose a week of operations.

What should a hospital prioritise?

The ability to keep treating without the systems. That means a downtime procedure that has been rehearsed rather than written, offline access to the minimum clinical information needed to prescribe safely, and a restore that somebody has timed. It is unglamorous and it addresses the harm that has actually been measured.

Are smaller hospitals more exposed than large ones?

Generally yes, and for the same reason as in every other sector: a rural or community facility has the same regulatory obligations and a fraction of the staff. It is also more likely to be the only emergency department within a long drive, which makes its downtime harder for neighbours to absorb.

Is patient data more valuable than card data?

It is more durable, which matters more than headline price. A stolen card is cancelled within days; a medical history, a national identifier and an insurance number remain accurate for decades and support fraud that is not detected by a bank. Comparisons of per-record prices tend to miss that the value is measured in years.

Should a hospital pay a ransom?

The general advice against paying holds here too, and it is harder to say, because the cost of the extra days is measured in patients rather than revenue. What tends to settle it in practice is that payment shortens the interval less than expected: decrypting a large estate takes days by itself, largely in parallel with the restore that was happening anyway. The decision that matters is made long beforehand, in whether anybody has measured how quickly the organisation can recover.

Who is accountable for the harm at a neighbouring hospital?

In any formal sense, nobody. Regulators assess organisations individually, liability requires a duty owed to the party harmed, and insurance covers the policyholder. The result is that the party best placed to reduce the regional damage has the least reason to fund it, which is a textbook condition for underinvestment and matches what the sector actually spends.

How long do these disruptions last?

Far longer than the outage. The average disruption to care delivery in the largest study of this ran to about 15.8 days, and the backlog of postponed procedures continues well beyond that. Restoring the systems is the first half of the recovery, not the end of it.

Healthcare in the archive

411 entries, peaking in 2017 with 90.