0% found this document useful (0 votes)
4 views8 pages

Project Ransomware Risk in Health Care Neil

Ransomware poses a significant operational risk to health care systems, impacting patient care and data security. The frequency and sophistication of attacks are increasing, highlighting the inadequacy of traditional recovery methods like backups. A comprehensive approach to risk management is essential, integrating cybersecurity planning with patient safety and operational resilience to ensure continuity of care during cyber incidents.

Uploaded by

clinton
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as DOCX, PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
4 views8 pages

Project Ransomware Risk in Health Care Neil

Ransomware poses a significant operational risk to health care systems, impacting patient care and data security. The frequency and sophistication of attacks are increasing, highlighting the inadequacy of traditional recovery methods like backups. A comprehensive approach to risk management is essential, integrating cybersecurity planning with patient safety and operational resilience to ensure continuity of care during cyber incidents.

Uploaded by

clinton
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as DOCX, PDF, TXT or read online on Scribd

1

Ransomware Risk in Health Care: Building Resilience Beyond Paying

Neil Roshan Shah

FairFax

March 14, 2026


2

Ransomware Risk in Health Care

Ransomware has emerged as one of the most critical operational risks to health care

systems. It is no longer a question of cybersecurity or data protection. The loss of access to the

digital systems by the hospitals may slow down the care provided to the patient, cancel

appointments, and redirect the emergency capabilities to alternative hospitals. These impacts

suggest that ransomware creates a risk to the security of both information and the provision of

medical services. That is why many researchers now think that the ransomware is the problem

which should be treated as the problem of patient safety and operational resilience and not as the

problem of computer technologies.

What makes ransomware a high-impact risk

Ransomware blocks access to systems and data until a payment is made. It can freeze

electronic records, imaging platforms, laboratory platforms and scheduling tools that support

daily clinical work in the health care. The inability of these systems to operate also compels

physicians and nurses to revert to manual systems that slow the treatment process and introduce

the risk of a medical error. It is even evidenced that the scope of ransomware attacks is growing

at an extremely fast rate. Ransomware activities targeting health care delivery organizations in

the US have grown over 2 times in 2016-2021 and almost half of these incidents have resulted in

care delivery (Neprash et al., 2022). The frequency of restoring the backups declined over the

time which implies that attackers and attack strategies are evolving quicker than organizational

security. This is important since many risk plans assume that backups will be an effective

recovery process despite the reality that recovery may take days or weeks in reality (Neprash et

al., 2022).
3

The risk is also linked to data breach harm. In a national survey of US health care

breaches in 2010-2024, hacking or IT incidents were the leading cause of reported breaches, and

in the past few years, ransomware made up a very large share of reported patient records (Jiang

et al., 2025). This implies the reason ransomware is an information risk and operational risk. The

leaders are unable to find the boundary between the system offline and the damage to privacy

since in many cases it may be the same event that will motivate both sides (Jiang et al., 2025).

Whenever hackers gain access to hospital systems, they are likely to steal valuable information

and lock files that will result in more damage, both in terms of money and reputation.

Organizations should therefore consider ransomware attacks as technical downturns but also

after huge privacy and compliance catastrophes. This can also create regulatory questions, legal

costs and loss of patient trust all of which can be added to the impact of the attack.

Why common controls are not enough

One of the critical limitations of most ransomware risk programs is that they rely on

isolated security controls. Organizations can either create a backup or educate employees and

believe that the risk is sufficiently addressed. However, existing evidence indicates that such

confidence is misplaced in many cases. According to Neprash et al. (2022), the effectiveness of

recovery following backups in health care organizations following a ransomware incident

decreases. This trend indicates that even the use of backups is not a strong defense, particularly

when they are poorly tested, unfinished, or are even targeted by hackers. In most situations,

organizations find out only in a crisis that there are weak points and systems have to be brought

up again under extreme time constraints. Risk management hence should involve multiple layers

of defense as opposed to relying on a single technical implementation. The powerful programs


4

are the combination of prevention, detection, response planning, and recovery testing in order to

ensure that disruptions may be mitigated without significant damage to patient care.

The other weakness is that not all organisations have the explicit means of connecting

cyber threats to business priorities. Technical alerts may be gathered by risk programs. However,

neglecting the most important aspect of care delivery. A more powerful measure is to match

threat intelligence with the criticality of an asset and the effectiveness of its control, such that the

leaders would know what to secure to access first and what to retrieve first. Kure et al. (2022)

follow such logic of integrated risk management of the critical infrastructure by combining

structured asset identification with the predictive and categorized types of risks methods. Health

care is not necessarily the same as other sectors with critical aspects, but the need of risk is the

same: it is necessary to make decisions based on the most important services and possible paths

of failures (Kure et al., 2022).

Real-world effects: Spillover turns one attack into a regional event

Ransomware should also be analyzed as a community risk rather than only an

organizational problem. In one study, one month of a ransomware attack on local hospitals

revealed that the emergency departments adjacent to the direct targets had a heavy load,

including taking in more patients, extending wait time, and putting stress on operations (Dameff,

et al., 2023). These spillover effects denote that the incidence of cyber incidents may spread

carnage to a whole regional health system. The most notable fact is that hospitals do not act

within a vacuum. When one system fails the hospitals that are around are forced to pick up the

additional service and continue with their services. This is why the planning must include

regional coordination, surge capacity plans, and share common communication systems among

other emergency and disaster planning (Dameff et al., 2023).


5

Cyber insurance as a risk response: help, harm, and hard tradeoffs

Cyber insurance is commonly regarded as a financial solution to the ransomware risk.

The problem is that ransomware is defined by human choice. Attackers might be encouraged

when it gets easier to pay. Meanwhile, health care executives might be compelled to rebuild

services quickly. Insurance can be a form of governance (Baker & Shortland, 2023). However, it

can also be employed in large to ensure the business continues to run when the crime is

interrupted rather than prevented. This creates a collision between enterprise and security. Risk

decision does not simply mean can we pay, but what is behavior supported by payment over time

(Baker & Shortland, 2023).

Decisions concerning payment are also more complicated than they are suggested

through the public debate. Cartwright et al. (2023) state that the context can either push the

decisions in one of the directions or another with the participation of insurance depending on the

extent of the business interruption and access to stolen information. Insurance may provide

professional help and design but it may reduce the actual price of payment also. It means that

cyber insurance is not likely to be viewed as a risk transfer instrument. It alters incentives and

may change expectations of attackers. Mature risk strategy acknowledges that insurance is a

single line that is supposed to be geared towards prevention and recovery agenda (Cartwright et

al., 2023).

Conclusion

Ransomware has emerged as a significant health care threat due to its ability to disrupt

patient care, disclose sensitive information, and put pressure on neighboring hospitals. It has

been determined that attacks are increasing and some of the recovery practices that are widely

used such as the use of backups are not always effective. This highlights the fact that more
6

integrated and stronger risk management plans need to be in place. Health care organizations

should make cybersecurity planning related to patient safety and continuity of services. The

identification of the critical systems is also part of the preparations as well as testing of the

recovery plans and alignment of other hospitals in case of a disruption. Additionally, leaders are

advised to approach cyber incidents as operational emergencies that require immediate decision-

making, response teams and regular resiliency exercises. Ultimately, the goal is resilience.

Hospitals should be capable of continuing safe and reliable care even in case of cyber incidents,

so that the key medical services should be provided even in case of a significant disruption.
7

References

Baker, T., & Shortland, A. (2023). Cyber insurance and the governance of ransomware. The

Geneva Papers on Risk and Insurance - Issues and Practice, 48(3), 516–

538. [Link]

Cartwright, A., Cartwright, E., MacColl, J., Mott, G., Turner, S., Sullivan, J., & Nurse, J. R. C.

(2023). How cyber insurance influences the ransomware payment decision: Theory and

evidence. The Geneva Papers on Risk and Insurance - Issues and Practice, 48(2), 300–

331. [Link]

Dameff, C., Tully, J., Chan, T. C., Castillo, E. M., Savage, S., Maysent, P., Hemmen, T. M.,

Clay, B. J., & Longhurst, C. A. (2023). Ransomware attack associated with disruptions at

adjacent emergency departments in the US. JAMA Network Open, 6(5),

e2312270. [Link]

Jiang, J. X., Ross, J. S., & Bai, G. (2025). Ransomware Attacks and Data Breaches in US Health

Care Systems. JAMA network open, 8(5), e2510180.

[Link]

Jiang, J. X., Ross, J. S., & Bai, G. (2025). Ransomware attacks and data breaches in US health

care systems. JAMA Network Open, 8(5),

e2510180. [Link]

Kure, H. I., Islam, S., & Mouratidis, H. (2022). An integrated cyber security risk management

framework and risk predication for the critical infrastructure protection. Neural

Computing and Applications, 34, 15241–15271. [Link]

06959-2
8

Neprash, H. T., McGlave, C. C., Cross, D. A., Virnig, B. A., Puskarich, M. A., Huling, J. D.,

Rozenshtein, A. Z., & Nikpay, S. S. (2022). Trends in ransomware attacks on US

hospitals, clinics, and other health care delivery organizations, 2016–2021. JAMA Health

Forum, 3(12), e224873. [Link]

You might also like