Cyberattacks are clinical events now
Ransomware cancels surgeries and diverts ambulances. The discipline is moving out of IT compliance and into patient safety, slowly.

Healthcare has spent two decades filing cybersecurity under information technology, with a compliance obligation attached. Protect the data, satisfy HIPAA, notify after a breach.
That filing no longer describes what happens. A serious incident now interrupts care itself: surgeries postponed, ambulances turned around, prescriptions stuck at the counter, diagnoses waiting on a system nobody can log into. The discipline is moving from data protection toward patient safety, and moving slowly.
How it got here
Ransomware crews worked out that hospitals pay, and pay fast, because the alternative is measured in patients rather than downtime.
Meanwhile the industry wired itself together. Laboratories, imaging providers, claims clearinghouses, e-prescribing platforms, and a small number of record vendors now sit between most providers and most payers. One compromised company can stop work at thousands of others.
The 2024 attack on Change Healthcare showed precisely that. Claims processing, eligibility checks, and prior authorization stalled across much of the country for weeks. Prescriptions stopped moving through the company's pharmacy switch. Revenue cycles seized. In some markets patients paid cash because nobody could confirm they had insurance. One vendor outage became a national clinical operations failure.
Why hospitals are harder to defend than banks
A hospital never closes, so there is no good hour to patch anything. Connected devices age in place. An infusion pump or imaging system bought a decade ago is still in service, still on the network, still running roughly what it shipped with. Access is spread across thousands of clinicians, contractors, and trainees who rotate through on a schedule.
Then there is money. Rural hospitals, small independents, and federally qualified health centers run on margins with no security budget hidden inside them. The organizations least able to absorb an incident are the ones least able to prevent one.
What the serious work looks like
Downtime planning has moved out of the IT binder and into clinical operations. Paper workflows written before they are needed. Manual order sets. Communication trees that function when email does not. Drills that include the clinicians who would actually be running them at two in the morning.
Alongside that, segmentation and identity hardening, on the premise that one stolen credential should not reach everything. And harder questions for the vendors sitting inside critical workflows, which is a change for an industry that has mostly bought on function and price.
Regulators move slower. The Department of Health and Human Services has signaled that minimum cybersecurity practices could become a condition of Medicare participation. Several states have floated their own rules. Whether the federal version arrives prescriptive, and whether money comes with it for providers who cannot fund the work, is unsettled.
All of which lands somewhere specific. An incident that stops care belongs in patient safety review and root cause analysis. It belongs on the board risk dashboard beside the other events that can close a service line. It belongs in the chief medical officer's portfolio, not only the chief information security officer's.
That is an awkward move for a sector that has filed security under back office for thirty years. It is also the accurate one.