Crime Science Weekly | EP.18 | When Ransomware Hits a Hospital: What Breaks, and Does It Cost Lives?

June 19, 2026

When Ransomware Hits a Hospital: What Breaks, and Does It Cost Lives?

Ransomware is a type of malicious software that prevents users from accessing their electronic systems and demands a ransom to restore access.

When this happens to an ordinary business, the result is an interruption to trade. When it happens to a hospital, the study published in JAMA Health Forum in 2022 summarises what has been reported: computers and electronic health records disabled or encrypted, clinicians forced to document care using pen and paper, appointments and surgeries delayed or cancelled, and emergency departments forced to divert ambulances.

"This is not simply a data breach. It is a question of whether the hospital can still function."

The researchers note that these operational disruptions may harm patients, especially those experiencing emergencies and for whom timely treatment is crucial.

Note the word may. Whether patients are in fact harmed is a harder question than it looks, and this article separates what the evidence establishes from what it does not.

Source: https://pmc.ncbi.nlm.nih.gov/articles/PMC9856685/

 

How Often It Happens and What Breaks

The same study assembled 374 ransomware attacks on health care delivery organisations in the United States between 2016 and 2021, which exposed the protected health information of nearly 42 million patients.

Almost half of those attacks, 166 or 44.4 per cent, disrupted the delivery of health care itself.

The most common failure was electronic system downtime, occurring in 156 attacks or 41.7 per cent. Next came delays and cancellations of scheduled care, in 38 attacks or 10.2 per cent, and ambulance diversion, in 16 attacks or 4.3 per cent.

On duration, 32 attacks or 8.6 per cent were associated with a disruption exceeding two weeks. The mean disruption duration was 15.8 days.

That average has to be read carefully, because the researchers state that duration was known for only 99 of the 374 attacks. Anyone quoting an average of 15.8 days without that denominator is overstating it.

Source: https://pmc.ncbi.nlm.nih.gov/articles/PMC9856685/

The Hospitals That Were Not Attacked Also Absorb the Damage

The part most often overlooked is that the consequences do not stop at the hospital that was attacked.

A study published in JAMA Network Open in 2023 examined the emergency departments of two hospitals that were not themselves attacked, but which sat near a health care organisation hit by ransomware on 1 May 2021, comparing the period before the attack with the period during it.

The significant increases were as follows. Mean daily emergency department census rose from 218.4 to 251.4 patients. Arrivals by ambulance rose from 1,741 to 2,354. Admissions rose from 1,614 to 1,722.

More troubling were the figures for patients leaving without being seen, which rose from 158 to 360, and patients leaving against medical advice, which rose from 107 to 161.

Waiting also lengthened. Median waiting room time rose from 21 minutes to 31 minutes, and total emergency department length of stay for admitted patients rose from 614 minutes to 822 minutes.

Across greater San Diego County, median total daily ambulance diversion time rose by 74.1 per cent, from 27 cumulative hours to 47 cumulative hours.

Source: https://pmc.ncbi.nlm.nih.gov/articles/PMC10167570/

 

What the Evidence Cannot Yet Show

At this point many readers will have concluded that ransomware kills patients. Neither of these two studies says so.

The 2022 study states its own limitation plainly: the researchers could not say whether or how ransomware disruptions affect patients seeking care, and further study is needed to quantify an empirical association between ransomware attacks and patient outcomes.

The 2023 study, which measured congestion in neighbouring emergency departments, contains an important negative finding that should always be reported alongside the rest. Although the number of stroke code activations rose, the researchers state that the increased stroke alerts were not correlated with longer times to stroke imaging, to administration of clot-dissolving medication, or to the start of the endovascular procedure.

Put simply, the emergency departments did become more crowded, but stroke patients were still treated within times no different from before.

The researchers list several further limitations: the study was observational and descriptive with no defined sample size, precluding true hypothesis testing; the incidence of stroke was relatively low; and confounding effects including variations in infectious disease burden, trauma burden or seasonality may be responsible for changes in emergency department metrics independent of the cybersecurity incident.

Source: https://pmc.ncbi.nlm.nih.gov/articles/PMC10167570/

 

What Governments Recommend

The United States Cybersecurity and Infrastructure Security Agency, together with the Federal Bureau of Investigation and the Department of Health and Human Services, issued a joint advisory specifically for the healthcare sector.

The central recommendation concerns backups. It states that it is critical to maintain offline, encrypted backups of data and to test those backups regularly, because many ransomware variants attempt to find and delete any accessible backups. It offers the 3-2-1 rule as a guideline: three copies of all critical data, on at least two different types of media, with at least one stored offline.

The next recommendations speak directly to hospital work. Plan for the possibility of critical information systems being inaccessible for an extended period of time. Print and properly store hard copies of digital information that would be required for critical patient healthcare. Periodically train staff to handle the re-routing of incoming and existing patients expediently if information systems abruptly become unavailable.

Equally important is the recommendation to coordinate the potential for surge support with other healthcare facilities in the greater local area, which matches precisely what the research found actually happened in San Diego.

On paying the ransom, the advisory is explicit that the three agencies do not recommend paying, because payment does not guarantee files will be recovered and may embolden adversaries to target additional organisations.

Source: https://www.cisa.gov/news-events/cybersecurity-advisories/aa20-302a

 

Lessons for Thailand

First, this is not a problem for the IT department alone, because what fails is the ability to treat patients, not merely a set of files. The response plan therefore has to belong to the whole hospital, and be rehearsed by clinical staff rather than by technical staff only.

Second, the figures argue for planning over a long horizon, since 8.6 per cent of attacks were associated with disruption lasting more than two weeks. A plan built to cover one or two days is too short.

Third, preparedness has to be thought about at the level of an area rather than a single hospital, because when one hospital goes down the load moves immediately to its neighbours, and those neighbours were never attacked at all. Joint provincial-level exercises have evidence behind them.

Fourth, communication matters. When an incident occurs, the public needs to be told which services remain open, which are postponed, and where to go instead, because clear information reduces the number of people arriving in the wrong place, which is the source of the congestion the research measured.

Finally, the risk should be described honestly. The available evidence shows clearly that care is disrupted, that queues lengthen, and that a number of patients walk out without being seen. It has not shown that these attacks kill people. Overstating the evidence may buy a stronger headline in the short term, at the cost of credibility once somebody opens the study and reads it.

References

Cybersecurity and Infrastructure Security Agency, Federal Bureau of Investigation, & Department of Health and Human Services. (2020, October 28). Ransomware activity targeting the healthcare and public health sector (Alert AA20-302A). https://www.cisa.gov/news-events/cybersecurity-advisories/aa20-302a

Dameff, C., Tully, J., Chan, T. C., Castillo, E. M., Savage, S., Maysent, P., Hemmen, T. M., Clay, B. J., & Longhurst, C. A. (2023). Ransomware attack associated with disruptions at adjacent emergency departments in the US. JAMA Network Open, 6(5), Article e2312270. https://pmc.ncbi.nlm.nih.gov/articles/PMC10167570/

Neprash, H. T., McGlave, C. C., Cross, D. A., Virnig, B. A., Puskarich, M. A., Huling, J. D., Rozenshtein, A. Z., & Nikpay, S. S. (2022). Trends in ransomware attacks on US hospitals, clinics, and other health care delivery organizations, 2016-2021. JAMA Health Forum, 3(12), Article e224873. https://pmc.ncbi.nlm.nih.gov/articles/PMC9856685/

Good knowledge should not stay in the library. It should be used to build a safer world.

Follow us at www.crimesci.com

Contact info@crimesci.com

#HubofKnowledge #CenterforCrimeScience #CrimeScienceWeekly

#วิทยาการอาชญากรรม #แรนซัมแวร์ #ความปลอดภัยผู้ป่วย #Ransomware