In a first-person account of a hospital recovering from a ransomware attack, a physician describes the chaos that follows when electronic systems go down: paper charts, written orders, and pilgrimages to radiology. The author notes that cybercriminals exploit clinicians' dependence on electronic medical records, and that attacks can disable not just the EMR but also phone lines, email, and door access. A recent Medicare claims study cited in the piece found a 34–38% relative increase in mortality for patients already admitted during an attack, with emergency department diversions and surgical cancellations also straining nearby hospitals.
The author argues that hospitals are treated as individual businesses despite being designated critical infrastructure. HIPAA's vague 'reasonable and appropriate' safeguards and voluntary HHS performance goals are insufficient. A proposed HIPAA security overhaul, introduced in December 2024, has stalled amid industry pushback over costs projected to exceed $20 billion in the first three years, with final action now targeted for July 2027. Reporting requirements remain partial, and a 2022 law mandating incident and ransom-payment reporting has not yet been implemented.
The piece concludes that the federal government should step in: set clear technological standards, subsidize implementation for small rural hospitals, mandate reporting, and provide federal assistance in ransomware negotiations. The author compares this to hostage negotiations handled by law enforcement, arguing that a health system's best option today—hiring private breach response firms—cannot seize crypto wallets or extradite offenders. Centralizing negotiations would aggregate intelligence and coordinate responses across attacks, the author contends, warning that AI-driven automation will soon make large-scale attacks easier for small criminal groups.