Explore our Topics:

Cyberattack fallout: Understanding the clinical downtime blast radius

Experts are working to understand the human and financial costs that pile up in the wake of cyberattacks that disrupt clinical care.
By admin
Sep 18, 2026, 10:48 AM

On February 19, a cyberattack disrupted operations at University of Mississippi Medical Center (UMMC). Cut off from critical IT systems, the hospital was forced to close clinics and cancel surgeries. It took more than a week to return to restore those systems and resume regular operations.

Disruption to patient care is a common consequence in an industry beset by cyberattacks. A 2025 report from Proofpoint and Ponemon Institute found that patient care was disrupted at 72% of health care organizations hit with cyberattacks. In 2026, health care remains a top target for ransomware gangs and other threat actors. 

When a health care provider’s ability to provide clinical care is hampered or completely broken, the impact spreads beyond that provider’s four walls. These events have a “spillover effect that we call the cyber blast radius,” according to Jeff Tully, MD, a practicing anesthesiologist and co-director of the UC San Diego Center for Healthcare Cybersecurity.

As the cyber threats that health care faces continue to grow and evolve, understanding this blast radius, the harm of clinical downtime and finding ways to maintain clinical continuity is more critical than ever.

Cyberattacks hit like a natural disaster, but the preparation is more difficult 

Both cyberattacks and natural disasters can cause clinical downtime at hospitals and health systems. Systems go down. Patients have to be diverted to other hospitals. Care is delayed or cancelled.

When a cyberattack hits critical IT systems, doctors and nurses may not be able to access electronic health records, imaging systems, bedside monitoring or any other number of vital pieces of technology that rely on a functioning, uncompromised network. And the damage doesn’t end there. Operational technology, like HVAC systems, can be impacted.

John Riggi, the American Hospital Association’s (AHA) national advisor for cybersecurity and risk, shared an example of a hospital in Florida that couldn’t set its temperature and humidity to the correct levels in the operating rooms following a ransomware attack, leading to cancelled and delayed surgeries.

That risk can ripple outward, sending waves that crash over entire health systems and regions. Imagine a rural hospital serving a community miles away from any other facility providing critical care.

“You’ve lost the availability of your nearest Level 1 Trauma Center. That immediately creates delay when those patients have to be transferred a further distance. And any delay, especially in urgent cases like stroke, heart attack or trauma, creates elevated risk of a negative outcome,” Riggi said.

Some natural disasters come with advance warning. Cyberattacks never do, and intruders are always probing and seeking vulnerabilities.

“A hurricane can be devastating, but we know it’s coming. We have a forecast, we have time to prepare, unlike a cyberattack,” Riggi said.

That means hospitals are under pressure to always be ready to respond to a cyberattack. The concepts of clinical continuity and cyber resilience are not new, nor are the resource constraints that complicate putting those concepts into practice.

The AHA and Joint Commission offer a Cyber Resilience Readiness Program designed to help organizations sustain clinical continuity for 30 days or longer following an outage related to a cybersecurity incident.

“We arrived at the 30-day number based on analysis of hundreds of ransomware attacks against hospitals, against third-party providers,” Riggi shared. “We have found that the 30-day number is a very good estimate for how long it would take a victim organization to restore at least core systems.”

Getting the data on downtime is complicated

Researchers want to understand what happens when patient care is disrupted by cyberattacks and technology failures. Tully is engaged in this work with the group at the UC San Diego Center for Healthcare Cybersecurity. He shared that getting the necessary data is a considerable challenge.

“It requires fairly large sample sizes. It requires institutions that are affected with a serious internal disaster and have associated regulatory and legal liability to share that data freely, which is not always the case,” he said.

Even if affected organizations are compelled to share data by regulatory agencies or willing to do so to advance this type of research, a cyberattack could make that impossible.

“Many of the same systems that we use to track care quality in the hospital and look at things like infections or outcomes from strokes; those are digital systems themselves that may not be available in the setting of that incident,” Tully added.

To further complicate matters, a cyberattack blast radius can span multiple organizations and spread across state lines. And these events happen very quickly. Tully and his colleagues want to study this exact kind of large-scale impact.

“[We want to] model some of those impacts and try to see if we can do a better job of what we call sector risk assessment to find those third-party dependencies that are going to be increasingly important for us to ensure we are as resilient as possible,” he said.

Clinical continuity is even more critical as health care faces AI, third-party risk and geopolitical cyber risks

Through his work with the AHA, Riggi called out cyberattacks fueled and generated by AI, supply chain cyberattacks and geopolitical tension as the biggest cyber risks to health care this year.

Anxiety regarding the capabilities of ever more powerful frontier AI models in the hands of threat actors is mounting, and health care organizations are adopting more AI tools that expand the attack surface.

“Frontier models may or may not be used to drastically increase the rate of discovery of vulnerabilities and their associated exploits, but also these tools are being used right now in health care and are themselves vulnerable to disruption,” Tully said.

Operational disruption could stem from an autonomous cyberattack or from an internal AI tool that has been compromised.

Hospitals and health systems don’t have to be the targets of AI-fueled cyberattacks or garden variety ones to become victims. Targeting their vendors can be an extremely effective way to widen the blast radius of an attack. The effects of the cyberattack on health care technology company Change Healthcare in 2024 were felt across the country.

While clinical downtime can stem from a ransomware attack, it is more a side effect than a primary goal. Other types of threat actors target health care with the sole aim of widespread disruption. As geopolitical tensions continue to ramp up on the world stage so does the risk of nation state groups targeting critical infrastructure sectors, including health care.

“Geopolitical risk is the foundation for the vast majority of cyber risk we face,” Riggi said.

The answers to clinical continuity questions aren’t easy, but the experts are trying to find them

The big questions health care leaders have to ask themselves about maintaining clinical continuity are simple, according to Riggi. “What will work? What won’t work? What’s the plan to carry on safe and quality care for 30 days or longer?”

Answering those questions is the tough part, but industry stakeholders are trying to get there. “I don’t think there’s a hospital or health system out there that does not recognize cyber as a significant threat,” Riggi said.

Initiatives like the Cyber Resilience Readiness Program offer hospitals support for assessing risk, preparing for cyberattacks and maintaining clinical continuity. The Advanced Research Projects Agency for Health (ARPA-H) has the DIGIHEALS initiative, which awarded funding for digital security tools to strengthen health care cybersecurity. The team at UC San Diego Center for Healthcare Cybersecurity is working on Project CRASHCART, a “mobile backup computing system” designed to help hospitals restore essential operations in the event of a cyberattack.

The cost of clinical downtime hits not only the bottom line but patient safety, and it is incumbent on policymakers, providers and vendors to find ways to ensure care can be delivered even when critical technology goes down.


Carrie Pallardy, a Chicago-based freelance writer and editor, began her career covering healthcare more than a decade ago. Her work has taken into many different industries, but covering healthcare delivery remains a constant focus. She can be reached at [email protected] or on LinkedIn.


Show Your Support

Subscribe

Newsletter Logo

Subscribe to our topic-centric newsletters to get the latest insights delivered to your inbox weekly.

Enter your information below

By submitting this form, you are agreeing to DHI’s Privacy Policy and Terms of Use.