One cyber incident can slow or stop patient care for days or weeks. In U.S. healthcare, the biggest continuity threats are ransomware, EHR outages, device failures, vendor attacks, cloud failures, and stolen credentials.
I’d sum it up like this: if you want care to keep moving during a cyber event, you need to plan for system loss that lasts four weeks or more, not just a short outage. The article points to one hard fact: in 2023, 58% of the 77.3 million people affected by healthcare data breaches were tied to attacks on business associates, and business associate breaches were up 287% from 2022.
Here’s the short version of what matters most:
- Ransomware can lock EHRs, lab, imaging, and pharmacy systems
- EHR and app outages can force staff into paper workflows
- Connected device issues can disrupt bedside care
- Third-party attacks can hit many hospitals at once
- Cloud failures can take down several services at the same time
- Identity compromise often opens the door to larger attacks
What should you do first?
- Keep a current list of systems, devices, vendors, and cloud links
- Test downtime plans with clinical teams
- Keep offline or immutable backups
- Use MFA, least-privilege access, and tighter vendor access rules
- Practice restores and set recovery order for patient care systems first
Cyberattacks on Hospitals Are Attacks on Communities: Why Ransomware Is a Patient Safety Crisis
sbb-itb-535baee
Quick Comparison
| Risk | What it can hit | What happens to care | Main step to cut downtime |
|---|---|---|---|
| Ransomware | EHR, PACS, lab, pharmacy, scheduling | Delays, diversions, paper workflows | Offline backups and restore testing |
| EHR/app outages | Records, orders, scheduling, radiology | Manual work and slower treatment | Downtime playbooks and drills |
| Device/IoMT issues | Monitors, imaging, diagnostic tools | Bedside disruption | Device inventory and network separation |
| Third-party attacks | Billing, apps, vendor services | Multi-hospital disruption | Third-party vendor risk management and contract terms |
| Cloud/data failures | Shared platforms, storage, communications | Multi-system outage | Dependency mapping and backup planning |
| Stolen credentials | User accounts, remote access, admin paths | System access for attackers | MFA and access reviews |
If I had to put it in one line: cyber risk in healthcare is a patient care problem first, and a tech problem second.
Why Cyber Risk Is a Continuity Risk in U.S. Healthcare
Healthcare is highly exposed to cyber disruption. Care doesn't stop just because systems go down. When a core system fails, care slows right away. That's why the next six risks matter for continuity, not just security.
That exposure gets worse because healthcare depends on critical third-party providers too. This includes business associates, device vendors, and supply-chain partners that support care and day-to-day operations. One attack on a single provider can ripple across connected organizations. As John Riggi of the AHA warns:
"The loss of critical dependent third-party technology and services may be even more wide-ranging and disruptive to patient care than when hospitals are attacked directly." [1]
The numbers make the point plain. In 2023, 58% of the 77.3 million individuals affected by healthcare data breaches were impacted because of an attack on a business associate [1]. Breaches involving healthcare business associates increased by 287% in 2023 compared to 2022 [1], and healthcare suffered more third-party data breaches than any other sector [1].
And those aren't just breach statistics sitting in a report. They turn into service disruption on the ground. The damage can spread far beyond the original target, hitting hospitals, clinics, and emergency departments across a region for weeks. Riggi puts it this way:
"The resulting 'ransomware blast radius' may be felt by every hospital, clinic and emergency department in the entire region as ambulances and patients are diverted to other surrounding hospitals, sometimes for weeks on end." [1]
So cyber risk in healthcare isn't just an IT issue. It's a patient safety and operational continuity issue. The focus can't be only on restoring systems after the fact. It also has to stay on keeping care running when disruption starts. The six risks below show how that disruption begins and how it spreads.
1. Ransomware Attacks on Core Clinical Systems
Ransomware is one of the most direct threats to healthcare continuity. When attackers encrypt EHRs, PACS, pharmacy, lab, and scheduling systems, clinical workflows slow down or stop. Staff may have to switch to paper, and patient care can slip fast. When these systems go down, care slows right away.
The risk also goes far beyond a single hospital. Attackers now often use a hub-and-spoke strategy by going after one shared third-party technology provider that supports many hospitals at the same time. As John Riggi of the AHA explains:
"Why hack or attack 1,000 hospitals when they can target the one common business associate and get all the data or disrupt all the hospitals that depend on that single mission-critical third-party provider?" [1]
This hub-and-spoke model can disrupt many providers in one hit. And that’s the point: the main problem isn’t just encryption itself. It’s the length of time clinical teams may need to work without their normal systems.
Recovery often takes weeks, which means downtime procedures need to support the loss of life- and mission-critical functions for four weeks or longer [1]
That’s why clinical teams need:
- Documented downtime procedures
- Regular drills
- Offline backups that are ready to use the moment systems go dark , following proven steps to prevent ransomware attacks
2. EHR and Core Application Outages
This risk goes well beyond ransomware. Even if no one locks the system, an EHR outage can bring clinical work to a halt. These disruptions to clinical applications represent some of the most significant threats to patient safety today. When the EHR goes down, medication management, orders, scheduling, lab, and radiology workflows can stall. Staff then have to switch to manual backup processes, and care delays can show up fast.
One outage at a central hub can push patients across an entire region for days or even weeks. The February 2024 Change Healthcare outage showed how a mission-critical hub can disrupt hospitals nationwide for weeks.[1]
The danger is highest for high-acuity patients. When EDs divert ambulances, nearby hospitals have to take the overflow, which can put more strain on care teams and slow treatment.
To reduce the damage, map dependencies across systems, build downtime plans for each application, and restore life-critical functions first. That same dependency issue gets even worse when connected medical device security risks cause failures.
3. Networked Medical Device and IoMT Vulnerabilities
Beyond EHR and core app outages, connected devices can disrupt bedside care too. Networked medical devices and IoMT systems can interrupt care when they fail, act unpredictably, or lose network access.
Patching these devices is often slow and messy. In many cases, healthcare providers have to patch third-party devices by hand, which can leave critical systems exposed. A growing Secure by Design push, backed by CISA, is meant to reduce flaws before products ever reach end users. But that change is still in progress.[1]
To cut risk, healthcare organizations need a current inventory of:
- Networked devices
- Connected technologies
- Vendors with internal access
They also need downtime procedures for life-critical technology that can keep operations going for four weeks or longer without major harm to care.[1] That means running regular drills at both the department and enterprise level, with device vendors involved, not sitting on the sidelines. Centralized risk management also helps track device exposure, access, and remediation. This approach is essential to effectively manage third-party risk across the enterprise.
A lot of these device issues start with vendors. So this problem ties straight into the third-party and supply-chain security challenges that come next.
4. Third-Party and Supply Chain Cyber Risks
Third-party outages turn into continuity problems fast because hospitals don't control the recovery timeline. Billing, cloud, device, and application vendors sit inside day-to-day care and business workflows. If one of them goes down, the hospitals that rely on it are stuck waiting.
The scale of this risk is already clear. In early 2024, the ALPHV BlackCat ransomware attack on Change Healthcare disrupted mission-critical billing and clinical functions across every hospital in the United States. [1] If an internal system fails, the hospital can work the problem itself. If a vendor gets hit, the hospital has to wait - and that can mean losing access to critical systems for long stretches while the vendor handles its own restoration process.
That delay can spread far beyond one facility. A single vendor outage can create a regional blast radius, with diverted patients and ambulances putting heavy strain on nearby hospitals and emergency departments for weeks. [1]
That's why vendor risk management belongs in continuity planning, not just in procurement paperwork.
To manage this exposure, hospitals need a current vendor inventory that also includes subcontractors. BAAs should spell out cybersecurity and cyber insurance requirements based on each vendor's risk level. Censinet RiskOps™ - an AHA cybersecurity partner - can help healthcare organizations manage vendor exposures and align with voluntary HHS Cybersecurity Performance Goals. [1]
5. Cloud and Data Infrastructure Failures
Hospitals depend on cloud platforms for EHR access, imaging, scheduling, communications, and billing. And when the cloud goes down, it’s not just one tool that stops working. Several clinical workflows can stall at the same time.
The main risk here is centralized dependency. If multiple hospitals rely on the same cloud or data provider, that provider turns into a single point of failure. One outage can knock connected clinical and business systems offline all at once, leaving care teams without the systems they use across the board.
Cloud outages can also last longer than a normal downtime window. That’s why the most important controls are pretty direct: keep a dynamic inventory of every cloud and data dependency, including subcontractors; back up critical data and set restoration priorities for core systems; and build downtime procedures that can hold up for a month. [1]
6. Social Engineering, Insider Misuse, and Identity Compromise
As more care runs through shared vendors, cloud services, and remote access, identity turns into a continuity control.
A lot of healthcare attacks begin the same way: someone steals credentials or tricks a user. Phishing, insider misuse, and stolen logins can give attackers trusted entry into clinical and business systems. Once they have valid credentials, they can move from system to system, interrupt workflows, and slip past basic security checks.
In healthcare, this gets more dangerous when those credentials open the door to shared platforms used by many organizations. One compromised account doesn’t just put one hospital at risk. It can create a continuity problem across multiple hospitals at the same time.
At scale, compromised credentials can get past perimeter controls, stall core workflows, and push teams into manual downtime operations.
To cut this risk, focus on a few practical controls:
- Keep access inventories current
- Apply least-privilege access
- Require MFA for staff and vendors
- Set stricter BAA terms
- Build downtime plans for outages that last four weeks or longer
BAAs should spell out cybersecurity, access, and breach-response requirements so care teams can keep operating during a prolonged outage.
Safeguards That Reduce Downtime Across All Six Risks
These controls won’t stop every attack. But they can shrink the blast radius and help clinical teams get back on their feet faster across all six risks.
Each safeguard below is meant to limit how far an outage spreads and shorten recovery time, no matter which of the six risks sets the incident off.
Asset Inventory and Dependency Mapping
You can’t protect systems you can’t see. A solid inventory should include EHRs, imaging systems, lab platforms, medical devices, cloud services, and every vendor connection tied to clinical workflows. Then map the dependencies between them so shared points of failure show up before they interrupt care.
Set downtime and recovery targets for each critical system, then match backups and manual workflows to those targets.[5] That’s what turns a plain asset list into a working continuity tool.
Identity, Access, and Privileged Account Controls
Using phishing-resistant MFA for high-value accounts, like hardware keys or number-matching prompts, cuts the risk of credential-based initial access.[3] Least-privilege access and privileged access management (PAM) also help contain damage if someone gets in.
It also helps to review legacy protocols on a regular basis. Disabling SMBv1, restricting RDP, and tightening internal access paths can block the lateral movement routes ransomware often uses.[3][7]
Segmentation, Backups, and Recovery Readiness
Network segmentation helps keep incidents contained. If IoMT and medical device networks are separated from administrative IT, an encryption event in one area is less likely to spread to life-sustaining equipment.[3][8] Backup networks and storage should also be separated from production, with admin access protected by MFA.[2][6][7]
For backup design, U.S. healthcare guidance keeps pointing to the 3-2-1 rule: three copies of data, on at least two media types, with at least one copy stored offline or in an immutable format.[2][4][5][6][7] That applies to EHR, PACS, LIS, Active Directory, and other critical systems.
Backups only matter if they work when you need them. Test restore procedures in an isolated environment and confirm they meet your documented recovery targets.[7]
Downtime Procedures and Clinical Continuity Planning
Downtime procedures need to be tested in outage scenarios that feel real, not just good on paper. Manual medication and scheduling steps should be simple enough to use under pressure. They also need clear data reconciliation steps for when systems come back online.[3][4][8]
Incident Drills, Medical Device Security, and Vendor Coordination
Run tabletop drills that cover EHR downtime, device behavior, and vendor response.[8] These exercises tend to be much more useful when biomedical engineering is in the room with IT and clinical leaders. Medical devices don’t always behave the way people expect during a network incident, and teams that haven’t practiced often find that out at the worst time.
Third-party risk and vendor dependency reviews matter here too. If a third party can touch a critical system, their recovery speed becomes part of your recovery timeline.
The table below shows how each risk affects continuity and which controls matter most.
Risk Types and Continuity Impact at a Glance
Top 6 Cyber Risks Threatening Healthcare Continuity
Not every cyber risk hits healthcare in the same way. Some cause a local problem. Others can stall clinical operations across an entire region for weeks.
The table below gives you a fast way to connect each risk to the systems it can hit, the kind of outage it tends to cause, and the controls that do the most to cut downtime.
Comparison Table: Risk Type, Affected Systems, Outage Pattern, and Top Controls
| Risk Type | Affected Systems | Continuity Impact | Typical Outage Pattern | Top Controls |
|---|---|---|---|---|
| Ransomware | Core clinical systems, Emergency Departments, internal networks | Regional ambulance diversion; care delays that threaten life | Cascading disruption - "blast radius" lasting weeks | Enterprise-level backups, restoration prioritization, incident command integration |
| EHR & Core App Outages | Patient records, clinical documentation, scheduling | Manual-only operations and delayed care | Sudden, total loss of digital access | Clinical continuity plans, downtime procedures, staff training and drills |
| Medical Device / IoMT | Networked devices, imaging, diagnostic equipment | Gaps in life-critical specialty care | Localized disruption | Asset inventory, network segmentation, patching, vendor coordination |
| Third-Party & Supply Chain | Business associates, mission-critical vendors | Multiple dependent organizations affected at once | Cascading hub-and-spoke failure; extended loss of services | Third-party risk management program, BAA cyber requirements, fourth-party mapping, vendor drills |
| Cloud & Data Infrastructure | Shared cloud platforms and data services | Simultaneous service failure across multiple dependent organizations | System-wide outage | Redundancy, offline backups, restoration priority planning |
| Identity / Social Engineering | Privileged accounts, identity systems, access paths | Unauthorized access, data extraction, malware pathway | Variable; often precedes ransomware | Identity controls, staff education, access reviews |
A ransomware event and a third-party attack can both set off the same kind of cascading outage. The difference is scale. When a vendor goes down, every provider tied to that vendor can feel the impact at the same time. Organizations like Emory Healthcare have streamlined these complex vendor risks to ensure stability.
Across all six risks, continuity plans should keep life- and mission-critical functions running for four weeks or longer.
Conclusion
These six risks all lead to the same place: care gets disrupted. Ransomware can knock out regional services. A compromised vendor can affect hundreds of hospitals at the same time. As John Riggi of the AHA said:
"The bottom line is that when hospitals are attacked, lives are threatened." [1]
That’s why this is an enterprise issue, not just an IT issue. Cyber risk belongs in the boardroom, in emergency preparedness planning, and in every vendor contract your organization signs.
The right response starts before an incident happens. Organizations that recover faster map dependencies, test downtime procedures, and prepare to keep care running for four weeks or longer. Resilience takes steady operational discipline, with a direct link to continuity and patient safety.
Tools like Censinet RiskOps™ can help healthcare risk teams with third-party and enterprise risk assessments, cybersecurity benchmarking, and collaborative risk management.
FAQs
Why plan for four weeks of downtime?
Healthcare organizations should plan for four weeks of downtime. Cyber incidents - especially ransomware attacks and third-party vendor failures - can knock out clinical and operational systems for weeks, not just days.
Planning for that stretch helps keep essential, life-critical functions running when core systems are down. It also cuts the risk that comes with long outages, like delayed diagnoses, treatment errors, and diverted care.
Which cyber risk is most likely to disrupt patient care first?
Ransomware is the top cyber risk to healthcare continuity because it can lock up critical systems like EHRs and medical devices. When that happens, teams may have to shut systems down at once and switch to manual workarounds.
That kind of outage isn't just an IT problem. If clinicians lose access to patient records and core tools, diagnosis and treatment can slow down, and delays like that can put lives at risk. Censinet helps healthcare organizations assess and manage these risks.
What should a hospital fix first to reduce downtime?
First, carry out a structured risk assessment to spot and rank threats that could directly disrupt patient care, like ransomware, critical medical device failures, or network outages. Use that assessment to identify mission-critical services and set recovery time objectives.
Then shift to prevention with continuous vulnerability scanning, network segmentation, and automated patch management. Censinet RiskOps helps simplify enterprise and third-party risk assessments.
Related Blog Posts
- 5 Challenges in Healthcare Cyber Risk Management
- One in Three Hospitals Confirm Cyber Incidents Directly Impacted Patient Care in Benchmark Findings
- Cybersecurity Benchmark Study Links Cyber Incidents to Direct Patient Safety Concerns
- How Healthcare Organizations Lost Access to Patient Records for 15 Hours - And What Happens Next