Home · Wiki · Incidents & Campaigns
type: incident · created: 2026-10-02 · updated: 2026-10-02 · tags: [incident, healthcare, ransomware] · confidence: medium · severity: medium · affected_sectors: [healthcare] · au_impact: true

MedPage Today published an opinion on 30 September by a clinician whose midsize hospital spent three weeks on paper charts and written orders after a ransomware attack: Epic was restored, but only one in four computers was working and the Picture Archiving and Communication System was still down at the time of writing. The account anchors the sector's operational stakes in data — it cites a study of Medicare claims data finding a 34–38% relative increase in mortality for patients already admitted to a hospital during an attack, plus emergency department diversions and surgical cancellations shifting burden to surrounding hospitals. Its argument is governance: double extortion places a ransom decision on staff who are simultaneously treating patients, while HIPAA requires only "reasonable and appropriate" safeguards and prescribes no architecture — so hospitals, which regulators call critical infrastructure but fund and secure as individual businesses, should delegate cyber defence and ransom negotiations to standardised domain expertise, as they do in clinical care, with deterrence requiring federal resources. The mortality study and outage account are the author's citations; the conclusion is argument, not finding.

Attribute Detail
Sector Healthcare
Date 2026-10-02
Source MedPage Today
Reliability Tier 3