During a month-long ransomware attack on four hospitals in 2021, two neighboring hospital emergency departments experienced increased patient volumes, wait times and stroke patients, among other impacts, according to a study reported this month in JAMA Network Open.
 
“This important study provides empirical data that demonstrates increased emergency department strain and stroke code activations at hospitals adjacent to a hospital attacked by ransomware, potentially creating a risk to patient safety. The diversion of patients and ambulances carrying stroke, heart attack and trauma patients may create a disruption and delay of urgent care throughout an entire region during a ransomware attack, creating what I call the ‘ransomware blast radius.’ This report affirms guidance provided by the AHA that emergency management, cyber incident response and disaster recovery plans be integrated and include ransomware as a hazard that is planned for internally and on a regional basis, under what we refer to as the ‘5R concept’ — Regional Readiness, Response, Resiliency and Recovery.”

Related News Articles

Headline
The Cybersecurity and Infrastructure Security Agency along with international agencies May 14 released guidance for high-risk nonprofit and other resource-…
Headline
Hospitals and health systems nationwide saw a sizable increase in delayed or missing payments in first quarter 2024, according to a report released May 10 by…
Headline
The Federal Bureau of Investigation, Cybersecurity and Infrastructure Security Agency, Department of Health and Human Services, and Multi-State Information…
Headline
The Department of Justice May 7 announced more than two dozen criminal charges against Dimitry Yuryevich Khoroshev, 31, of Voronezh, Russia, for his alleged…
Headline
The AHA and other national hospital groups May 8 sent a letter to UnitedHealth Group, urging the organization to formally accept responsibility for issuing…
Headline
The Cybersecurity and Infrastructure Security Agency May 3 extended the comment period to July 3 for the April 4 proposed rule that would implement cyber…