1. Introduction
Modern hospital care depends on dense digital interconnections. Electronic health records (EHRs), identity services, laboratory and imaging systems, pharmacy automation, bedside devices, building controls, communications, staffing platforms, supply chains, and payer transactions may share infrastructure or depend on the same external providers. A single failure can therefore become a compound operational event. Reviews of hospital cyber risk describe a broad attack surface, uneven investment, legacy systems, connected devices, and human and organizational vulnerabilities (1,2). The central executive issue is not whether a hospital can prevent every intrusion. It is whether essential care can remain safe when trusted digital functions become unavailable or unreliable.
Empirical evidence makes the clinical stakes visible. An analysis of 374 ransomware attacks on US healthcare delivery organizations from 2016 through 2021 found that nearly half were associated with care disruption, including electronic downtime, cancellation of scheduled care, and ambulance diversion; the attacks exposed protected health information for almost 42 million patients (3). A study of an attack's regional effects found increased emergency department (ED) census, ambulance arrivals, patients leaving without being seen, waiting time, and length of stay at nearby hospitals (4). These observations position a cyberattack as a community capacity shock, not an event confined to the targeted institution.
Technology disruption without malicious intent can produce similar hazards. During the July 2024 CrowdStrike outage, internet-observable loss of service occurred in 759 of 2,232 studied US hospitals, and identifiable disruptions included direct patient-facing and operational services (5). A focus on “cyberattack” alone is therefore too narrow. The same resilience discipline must cover ransomware, cloud or telecommunications failure, failed software updates, unavailable identity infrastructure, compromised data integrity, and loss of key vendors.
NIST Cybersecurity Framework (CSF) 2.0 adds Govern to Identify, Protect, Detect, Respond, and Recover, reinforcing that cybersecurity belongs within enterprise risk management (6). For hospitals, governance must connect these functions to clinical services and patient-safety systems. A technically successful response can still be clinically unsafe if downtime tools are unusable, staff cannot reach current procedures, critical devices depend on unavailable authentication, or recovery releases unreconciled orders and results into production.
This review presents a hospital cyber-resilience operating model organized around executive governance, clinically led preparedness, incident command, safe minimum operations, recovery validation, and learning. We present this article in accordance with the narrative review reporting checklist.
2. Methods
Searches were completed on 12 August 2026. PubMed/MEDLINE-indexed records were identified with combinations of hospital, healthcare, cyberattack, ransomware, cybersecurity, downtime, disruption, patient safety, incident response, resilience, and recovery. Targeted searches of official NIST, HHS, CISA, and FDA websites identified current frameworks, health-sector performance goals, incident-response guidance, contingency-planning material, medical-device cybersecurity guidance, and ransomware resources. Backward citation screening identified additional hospital-specific empirical studies and foundational reviews.
English-language empirical studies, systematic or scoping reviews, government standards, and operational guidance were included when they described hospital cyber risk, care disruption, clinical downtime, incident response, recovery, human factors, or medical-device implications. Priority was given to hospital-specific evidence and final authoritative guidance. General security materials were retained only when they supplied a control directly applicable to hospital resilience. News reports, unsupported vendor marketing, duplicate sources, and purely technical attack analyses without an operational or patient-safety link were excluded. Evidence was synthesized narratively because study designs, exposures, outcomes, and incident reporting were heterogeneous. No meta-analysis or formal risk-of-bias score was performed. Table 1 summarizes the completed search strategy.
The completed evidence-synthesis exhibits are presented in Supplementary Table S1.
| Item | Completed approach |
|---|---|
| Date of search | 12 August 2026 |
| Sources searched | PubMed/MEDLINE-indexed records; official NIST, HHS, CISA, and FDA websites; backward citation screening |
| Core search concepts | (hospital OR healthcare) AND (ransomware OR cyberattack OR cybersecurity OR technology disruption) AND (patient safety OR downtime OR incident response OR resilience OR recovery) |
| Timeframe | Primarily January 2018–12 August 2026; earlier foundational guidance eligible |
| Inclusion criteria | English-language empirical studies, reviews, standards, and operational guidance with direct hospital continuity or safety relevance |
| Exclusion criteria | Unsupported news or marketing claims; duplicate sources; technical content without a hospital operations link |
| Selection process | Title/abstract or executive-summary screening, record review, then thematic synthesis across governance, preparation, response, recovery, and learning |
| Additional methods | Reference-list screening; bibliographic verification using PubMed, DOI, publisher, or official issuing-organization records |
3. Cyber risk is a care-delivery risk
3.1 The harm pathway
Cyber incidents harm patients through more than disclosure of protected information. The first pathway is loss of availability: clinicians cannot retrieve records, place orders, view images, communicate, or use connected equipment. The second is loss of integrity: data or configurations may be altered, incomplete, duplicated, or stale. Integrity loss can be more dangerous than obvious downtime because staff may trust incorrect information. The third is loss of confidentiality, which can create enduring personal, legal, and trust consequences. The fourth is operational displacement: diverted patients, deferred procedures, delayed payroll or purchasing, and loss of community confidence affect care beyond the compromised network.
Ransomware evidence shows that disruption can persist beyond the visible incident. In a study using Medicare data, hospital admissions, outpatient visits, and ED visits fell sharply in the first week after attacks, with comparable operational effects in rural and urban hospitals; rural patients had substantially longer travel to alternative hospitals (7). A case report from a maternity service described activity reductions lasting weeks after an attack and the need for rapid adaptation to preserve delivery care (8). The consequences depend on local redundancy and regional capacity, so an identical technical event can produce unequal harm.
Cyber-risk quantification should therefore use clinical service impact, not only asset counts or financial loss. A pathology interface used continuously for critical results may warrant more attention than a larger but nonessential application. A rural critical access hospital may have fewer technical assets but less alternative capacity. The relevant unit of analysis is the service-to-dependency chain: clinical service, staff, space, supplies, devices, applications, infrastructure, vendors, and community partners.
3.2 Connected devices and the physical environment
Hospitals operate medical devices with long service lives, specialized operating systems, vendor-controlled maintenance, and limited ability to patch without testing. FDA guidance treats cybersecurity as part of medical-device safety and quality across the product lifecycle (9). Hospital controls should include a device inventory, network segmentation, compensating controls, vendor access management, vulnerability communication, software-bill-of-materials information where available, backup configuration, and clinical plans for degraded operation.
Operational technology also matters. Heating, ventilation, power management, pneumatic tubes, elevators, refrigeration, access control, and nurse-call systems may be digitally connected. Failure can close physical capacity even when the EHR remains available. Facilities engineering and biomedical engineering should therefore participate in enterprise cyber governance and exercises.
4. Governance from the board to the bedside
4.1 Board and executive accountability
The board should treat cyber resilience as an enterprise risk linked to quality, safety, strategy, and capital. It should approve risk appetite at a meaningful level—for example, whether a critical service may depend on one identity provider, whether offline medication workflows have been validated, or how quickly executives must be notified of a material integrity concern. Board dashboards should show critical-service resilience, material dependencies, unremediated high-risk findings, exercise results, recovery performance, third-party exposure, and clinically significant incidents. A heat map of technical vulnerabilities without service context is insufficient.
The chief executive should designate one accountable executive while preserving shared operational ownership. The chief information security officer cannot independently create safe paper medication administration, maintain sterile processing, reroute ambulances, reconcile diagnostic results, or prioritize surgery. Cybersecurity supplies expertise and coordinates controls; service-line executives and clinical leaders own continuity in their domains. NIST's enterprise-risk guidance encourages integration of cybersecurity information into broader risk decisions (10).
A cyber-resilience steering structure should include clinical operations, nursing, medical staff, pharmacy, laboratory, imaging, quality, patient safety, emergency management, information technology, cybersecurity, privacy, legal, compliance, communications, facilities, biomedical engineering, supply chain, human resources, finance, and vendor management. The group should set policy, resolve dependencies, approve service recovery priorities, monitor corrective actions, and commission exercises. During an incident, it should transition to a recognized incident-command structure rather than improvise authority.
4.2 Define decision rights before the crisis
Leaders should preassign authority to isolate networks, disable interfaces, shut down compromised devices, divert ambulances, cancel elective work, use emergency procurement, communicate externally, notify regulators and insurers, and initiate recovery. The clinical authority to declare a workflow unsafe must be as clear as the technical authority to disconnect a system. Legal review and documentation remain important, but consensus-seeking cannot delay action when evidence of harm is credible.
Incident classification should incorporate patient-safety severity, service scope, data integrity, duration, regional effect, and recovery uncertainty. A short interruption to a high-acuity service may outrank a longer administrative outage. Escalation triggers should include inability to verify identity, loss of medication safeguards, unavailability of critical results, mismatch between paper and electronic orders, loss of emergency communications, or credible compromise of clinical data. Table 2 assigns primary authority and required advice for consequential decisions.
| Decision | Primary authority | Required advice | Predefined evidence or trigger |
|---|---|---|---|
| Isolate system or network segment | Incident commander/authorized cybersecurity leader | Clinical owner, IT operations, patient safety | Credible compromise balanced against clinical consequence of isolation |
| Activate clinical downtime | Hospital incident command with clinical operations lead | Service-line leaders, nursing, medical staff, pharmacy, emergency management | Loss or unreliability of a critical dependency beyond defined tolerance |
| Divert or reduce services | Senior clinical/operational executive | ED, EMS liaison, regional partners, communications, legal | Safe minimum capacity breached or imminent |
| Begin restoration | Recovery lead with system and clinical owner | Cybersecurity, vendor, data-integrity and patient-safety teams | Containment evidence, clean restoration path, validation plan, rollback available |
| Release restored system for clinical use | Clinical service owner and technical owner | Pharmacy/lab/imaging/device experts as applicable | Functional, security, interface, identity, and workflow validation completed |
| Notify public/regulators | Designated executive and legal/privacy leads | Communications, patient safety, law enforcement as appropriate | Applicable legal threshold or material public/patient impact |
5. Prepare for safe minimum operations
5.1 Map services to dependencies and tolerances
Traditional application inventories often list owners and servers but omit the clinical consequences of failure. A service-resilience map begins with critical activities: emergency triage, medication administration, blood release, imaging interpretation, operative care, obstetrics, intensive care, respiratory support, laboratory results, patient identification, bed assignment, internal communication, and discharge. Each is mapped to people, facilities, supplies, devices, applications, networks, identity, external vendors, and data flows. Leaders then define maximum tolerable disruption, minimum safe staffing, manual capacity, and the trigger to reduce or stop the service.
Business impact analysis should account for simultaneous dependencies. Printing downtime packets is not a control if printers require the unavailable network. An offline EHR viewer is not resilient if it shares identity infrastructure with production. A generator does not preserve a pharmacy robot whose controller fails authentication. Plans should test these assumptions through technical failure injection and clinical simulation.
HHS Health Care and Public Health Cybersecurity Performance Goals distinguish essential and enhanced practices and emphasize measures such as email security, multifactor authentication, vulnerability management, network segmentation, incident planning, and backup strategies (11). These controls reduce likelihood and blast radius. However, hospitals must translate them into service outcomes: which clinical functions remain available, for how long, and at what volume when each control fails?
5.2 Downtime procedures must be usable under pressure
Downtime binders commonly fail because they are outdated, inaccessible, overly generic, or never practiced. Each critical workflow needs a concise procedure that specifies activation, roles, approved forms, patient identification, orders, medication safeguards, result communication, documentation custody, escalation, and later reconciliation. Forms should be standardized where possible and stocked in sufficient quantities. Current copies must be accessible without the affected network.
Clinical teams should design and test the procedures. Downtime changes workload and redistributes risk: pharmacists may receive handwritten orders, nurses may double-document, laboratory staff may telephone critical results, and registration staff may create temporary identifiers. Plans should calculate the manual throughput of these bottlenecks and identify when demand must be reduced. Human-factors research in healthcare cybersecurity finds that policy, culture, training, and technology must work together; framing staff as the weakest link obscures poorly designed systems and incentives (12).
Exercises should include nights, weekends, multiple campuses, and third parties. Scenarios should test loss of EHR and identity services, corrupted rather than absent data, inaccessible cloud communication, medical-device compromise, regional diversion, and a recovery that must be rolled back. High-fidelity simulation can reveal patient-safety hazards that a tabletop discussion misses. Observers should time key tasks, track errors and workarounds, and record decisions. Corrective actions need owners, due dates, and verification.
5.3 Build recoverability, not merely backups
Backups have value only if they are protected from the same compromise, complete enough for the service, and restorable within the required time. Hospitals should maintain offline or logically isolated copies, strong access control, immutability where appropriate, and frequent restoration testing. Recovery exercises should include applications, interfaces, identity, configurations, device connectivity, and data reconciliation. NIST contingency-planning guidance distinguishes recovery planning, testing, and maintenance as continuing activities (13).
Architecture should limit blast radius through segmentation, least privilege, privileged-access management, application allowlisting where appropriate, secure remote access, and separation of backup administration. CISA's ransomware guidance emphasizes preparation, protective controls, incident response, and reporting rather than reliance on ransom payment (14). Vendor remote access and service accounts merit particular attention because they can bridge multiple systems or organizations.
The care-delivery impact cascade
6. Respond as a clinical incident
6.1 Establish a unified operating picture
When detection occurs, technical teams need freedom to investigate and contain, while clinical teams need actionable statements about what can be trusted. Incident command should maintain a shared picture: affected services; known versus suspected compromise; availability and integrity status; patient-safety events; current manual capacity; diversions or cancellations; vendor and regional status; communications; and decisions pending. Uncertainty should be explicit. “System available” is not the same as “data trustworthy.”
NIST SP 800-61 Revision 3 integrates incident response across CSF 2.0 and emphasizes preparation, detection, response, recovery, and improvement throughout risk management (15). In hospitals, operational briefings should occur at a cadence appropriate to clinical risk. Liaison roles should connect the command center with unit leaders, emergency medical services, public health, blood suppliers, laboratories, pharmacies, and neighboring facilities.
Internal communication should use redundant channels and plain language. Staff need to know which systems are unavailable, which are untrusted, what workflow to use, where to obtain forms, how to escalate urgent needs, and when the next update will occur. Messages should distinguish confirmed facts from precautions. Public communication should support safe patient decisions without creating unnecessary avoidance of essential care.
6.2 Protect safety during prolonged downtime
As downtime continues, fatigue, supply depletion, backlogs, and handoff failures intensify. Incident command should monitor clinical leading indicators: time to critical medications and diagnostics, unidentified patients, unreconciled orders, unreviewed results, ambulance offload, staffing, blood and medication inventory, device availability, and error reports. A just-culture approach encourages rapid reporting of workarounds and near misses, which may be the earliest evidence that minimum safe operations are failing.
Regional coordination is essential. The adjacent-ED study demonstrates how attack effects propagate through a community (4). Hospitals should share service status and capacity through existing emergency-preparedness networks, coordinate diversion thresholds, and avoid unilateral communications that displace demand without warning. Rural plans require special attention to transportation time, limited alternate capacity, and shared vendors.
7. Recover safely: the dangerous transition back
7.1 Restoration requires technical and clinical validation
Recovery sequencing should follow patient consequence, dependencies, and confidence—not executive visibility or revenue alone. Identity, networking, and core infrastructure may need to precede applications, but clinical teams should determine which services can safely resume at each stage. A system should pass security, functional, interface, performance, and workflow checks in a clean environment. Users should verify that roles, order sets, formularies, reference ranges, device links, printers, queues, and alerts function as intended. A rollback path must remain available.
Partial recovery can create false confidence. If the EHR is available but laboratory interfaces remain delayed, a result may appear absent rather than pending. If one facility is restored while central scheduling is not, patients may receive conflicting instructions. If device clocks or queues are misaligned, data can be attached to the wrong encounter. Release criteria should therefore be service based and communicated precisely.
7.2 Reconcile the record and the work
During downtime, organizations create paper orders, temporary identifiers, handwritten medication records, local spreadsheets, printed worklists, telephone results, and deferred documentation. Reconciliation is a safety-critical project. Teams should establish a source-of-truth hierarchy, prioritize high-risk medications and unresolved diagnostics, match temporary and permanent identities, enter legally and clinically required documentation, avoid duplicate execution of orders, and close loops on critical results.
Backlogs need triage. Entering every historical action into production may overwhelm staff and increase error. Clinical, health-information-management, legal, and compliance leaders should define what must be transcribed, scanned, abstracted, or retained separately. Reconciliation progress should be measured, and unresolved high-risk items should remain visible to incident command. Table 3 summarizes a minimum clinical downtime control bundle.
Recovery also affects people. Staff may have worked extended shifts under high cognitive load and may then face a second surge of data entry, rescheduling, claims repair, and patient communication. Fatigue controls, relief staffing, psychological support, and realistic productivity expectations are part of safe recovery.
| Domain | Minimum controls | Failure signal |
|---|---|---|
| Patient identity | Approved temporary identifier; wristband process; duplicate-record prevention; photo/biographic checks | Mismatched orders/results, duplicate identifiers, unidentified transfers |
| Medications | Paper order standard; allergy and interaction verification; pharmacy communication; controlled-substance log | Unverified home medications, illegible orders, delayed high-risk drugs |
| Diagnostics | Manual requisition; specimen labeling; critical-result read-back; image/result routing log | Orphaned specimens, unacknowledged critical results, wrong-patient association |
| Documentation | Time-stamped forms; custody; minimum dataset; secure storage; reconciliation owner | Missing notes, untraceable forms, conflicting versions |
| Communication | Redundant phones/radios/runners; unit contact tree; update cadence | Staff using unapproved apps; missed escalation; inconsistent instructions |
| Capacity | Manual throughput limit; service reduction/diversion trigger; regional notification | Queues exceed safe staffing or monitoring capability |
7.3 Learn without normalizing the event
After-action review should examine technical root causes and operational performance: what happened, when it was detected, which decisions were delayed, how patients were affected, which manual processes worked, which dependencies were unknown, and whether communications were trusted. The review should include frontline staff and external partners. Findings should enter the same corrective-action governance used for serious safety events, with accountable owners and effectiveness checks.
Hospitals should share deidentified lessons through sector information-sharing and analysis organizations where appropriate. Underreporting impedes collective learning; the literature remains constrained by incomplete incident data and heterogeneous definitions (1). Legal privilege and security sensitivity must be managed, but neither should become a reason to suppress actionable learning.
8. Measurement for boards and operators
Common metrics such as phishing-click rate, patch counts, or blocked threats describe pieces of the control environment but do not establish resilience. Executives need measures tied to service continuity and recovery. Examples include the percentage of critical services with current dependency maps; proportion with tested downtime procedures; time to activate incident command; time to achieve safe manual operations; restoration success from protected backups; time to validate a priority service; unreconciled high-risk orders or results; exercise defects closed on time; and number of critical vendors without tested continuity or material-change notification.
Outcome measures should include patient-safety events, care delays, diversions, cancellations, excess length of stay, workforce injury or fatigue, privacy impact, and financial loss. Interpretation needs context: a longer restoration time may be appropriate if teams identified an integrity concern and refused an unsafe release. Conversely, a rapid technical restoration followed by medication or result errors is failure. Table 4 pairs board-level resilience measures with the operating measures needed to interpret them.
| Domain | Board-level measure | Operator-level measure |
|---|---|---|
| Governance | Critical risks above appetite; material exceptions overdue | Owners assigned; corrective actions completed and effectiveness tested |
| Preparation | Critical services with validated downtime and recovery plans | Exercise frequency, participation, defect severity, closure time |
| Protection/detection | Coverage of essential HHS performance goals; material third-party gaps | MFA/segmentation/backup coverage, detection and escalation time |
| Response | Time to unified incident command; time to safe minimum operations | Unit activation, communication reach, patient-safety indicators |
| Recovery | Priority services restored and clinically validated within tolerance | Restore success, interface validation, rollback readiness, reconciliation backlog |
| Learning | Serious-event actions closed; regional lessons shared | Repeat defects, near-miss reporting, procedure and training updates |
9. Implementation priorities
In the first 90 days, executives should confirm incident authority, identify the ten to twenty services whose interruption presents the greatest patient risk, map their principal dependencies, and test whether offline procedures are accessible. The organization should validate contact methods that do not depend on production identity or email, review backup isolation and restoration evidence, and establish triggers for clinical downtime and diversion. The 2023 Health Industry Cybersecurity Practices provide sector-specific threat and mitigation context (16), while CISA's cross-sector performance goals offer a complementary baseline (17). Privacy and security response processes should remain aligned with current HHS Office for Civil Rights guidance (18), and clinical continuity planning should incorporate the Joint Commission's patient-safety recommendations for cyberattack preparation and recovery (19).
Within six months, each priority service should complete a multidisciplinary exercise that includes data-integrity uncertainty and a recovery transition. Vendor contracts and remote access should be risk ranked. Identity, segmentation, privileged access, endpoint visibility, vulnerability management, and protected backups should be aligned to HHS and NIST outcomes. Gaps that cannot be remediated promptly should have explicit compensating controls and executive acceptance. A review of hospital bring-your-own-device security found that people, policy, and technology must be addressed together (20); an earlier healthcare cybersecurity review similarly emphasized defined responsibilities, maintenance, procedures, and training (21). Lessons after WannaCry underscored the importance of culture and resilience (22), while analysis of the National Health Service illustrates the organizational scope of the challenge (23).
Within twelve months, the hospital should conduct an enterprise exercise with regional partners, validate restoration of representative critical systems from protected backups, measure record reconciliation, and report results to the board. Capital planning should address unsupported devices, single points of failure, and manual-capacity constraints revealed by testing. The annual cycle should use new incidents, technology changes, construction, acquisitions, and service-line changes to update dependency maps and priorities. Federal oversight reviews identify persistent gaps in the adoption and evaluation of ransomware practices across critical infrastructure sectors (24). Hospitals can translate the NIST security-control catalog (25) and zero-trust architecture principles (26) into locally prioritized safeguards, while recognizing that control implementation must be tested against clinical continuity.
Implementation should include a regional continuity compact. Hospitals, emergency medical services, public health agencies, blood suppliers, laboratories, pharmacies, and referral partners need pre-event contacts, alternative communication methods, transfer principles, and a shared understanding of what information can be exchanged during disruption. Exercises should test simultaneous demand rather than assume that an unaffected neighbor can absorb unlimited diversion. The compact should also address how delayed results, duplicate registrations, paper records, and patient-location uncertainty will be reconciled across organizations after restoration. These arrangements turn community dependence from an undocumented assumption into a managed capability.
Restoration is not release
10. Strengths and limitations
This review connects empirical evidence of disruption with current government frameworks and translates them into clinical governance, downtime, and recovery practices. It treats malicious and nonmalicious technology failures within one resilience model and addresses regional spillover, data integrity, connected devices, human factors, and the transition back to electronic operations.
The published evidence is incomplete and subject to reporting bias. Organizations may withhold incident details, and observational studies cannot always separate cyber effects from concurrent operational conditions. Event definitions, duration, and outcomes vary. This narrative search was purposive rather than systematic and did not include classified, proprietary, or insurance claims information. Most operational recommendations are based on convergent guidance and incident lessons rather than controlled trials. Regulatory obligations and threat conditions change; hospitals must verify current requirements and adapt controls to local clinical services, architecture, workforce, and community capacity.
11. Conclusions
Hospital cybersecurity is inseparable from patient safety and continuity. A resilient organization maps clinical services to digital and physical dependencies, assigns decision rights before crisis, protects recovery capabilities, rehearses usable manual work, coordinates incident command across technical and clinical teams, and validates restoration from the bedside outward. Boards should demand evidence that essential care can continue and that recovery will not introduce a second wave of harm. Prevention remains essential, but the defining executive capability is prepared adaptation: sustaining safe minimum operations, communicating honestly under uncertainty, recovering with integrity, and learning across the organization and region.
None.
Reporting Checklist: The author has completed the narrative review reporting checklist.
Funding: None.
Conflicts of Interest: The author has completed the ICMJE uniform disclosure form. The author is President and Chief Executive Officer of The Healthcare Executive. No other conflicts of interest are declared.
Ethical Statement: The authors are accountable for all aspects of the work in ensuring that questions related to the accuracy or integrity of any part of the work are appropriately investigated and resolved. This narrative review did not involve human participants or animals; institutional review board approval and informed consent were not applicable.
Data Sharing Statement: No original datasets were generated or analyzed for this narrative review. The completed search strategy is reported in the manuscript and supplementary material.
References
- Argaw ST, Bempong NE, Eshaya-Chauvin B, et al. The state of research on cyberattacks against hospitals and available best practice recommendations: a scoping review. BMC Med Inform Decis Mak. 2019;19:10. doi:10.1186/s12911-018-0724-5.
- Argaw ST, Troncoso-Pastoriza JR, Lacey D, et al. Cybersecurity of hospitals: discussing the challenges and working towards mitigating the risks. BMC Med Inform Decis Mak. 2020;20:146. doi:10.1186/s12911-020-01161-7.
- Neprash HT, McGlave CC, Cross DA, et al. Trends in ransomware attacks on US hospitals, clinics, and other health care delivery organizations, 2016-2021. JAMA Health Forum. 2022;3:e224873. doi:10.1001/jamahealthforum.2022.4873.
- Dameff C, Tully J, Chan TC, et al. Ransomware attack associated with disruptions at adjacent emergency departments in the US. JAMA Netw Open. 2023;6:e2312270. doi:10.1001/jamanetworkopen.2023.12270.
- Tully JL, Rao S, Straw I, et al. Patient care technology disruptions associated with the CrowdStrike outage. JAMA Netw Open. 2025;8:e2530226. doi:10.1001/jamanetworkopen.2025.30226.
- Pascoe C, Quinn S, Scarfone K. The NIST Cybersecurity Framework (CSF) 2.0. Gaithersburg (MD): National Institute of Standards and Technology; 2024. NIST CSWP 29. doi:10.6028/NIST.CSWP.29.
- Neprash HT, McGlave CC, Rydberg K, et al. What happens to rural hospitals during a ransomware attack? Evidence from Medicare data. J Rural Health. 2024;40:728-737. doi:10.1111/jrh.12834.
- Gabbay-Benziv R, Ben-Natan M, Roguin A, et al. When the lights go down in the delivery room: lessons from a ransomware attack. Int J Gynaecol Obstet. 2023;162:562-568. doi:10.1002/ijgo.14687.
- US Food and Drug Administration. Cybersecurity in Medical Devices: Quality System Considerations and Content of Premarket Submissions—Guidance for Industry and Food and Drug Administration Staff. Silver Spring (MD): FDA; 2023.
- Quinn S, Pillitteri V, Barrett M, et al. NIST Cybersecurity Framework 2.0: Enterprise Risk Management Quick-Start Guide. Gaithersburg (MD): National Institute of Standards and Technology; 2024. NIST SP 1303. doi:10.6028/NIST.SP.1303.
- US Department of Health and Human Services. Healthcare and Public Health Sector Cybersecurity Performance Goals. Washington (DC): HHS; 2024.
- Nifakos S, Chandramouli K, Nikolaou CK, et al. Influence of human factors on cyber security within healthcare organisations: a systematic review. Sensors (Basel). 2021;21:5119. doi:10.3390/s21155119.
- Swanson M, Bowen P, Phillips AW, et al. Contingency Planning Guide for Federal Information Systems. Gaithersburg (MD): National Institute of Standards and Technology; 2010. NIST SP 800-34 Rev. 1. doi:10.6028/NIST.SP.800-34r1.
- Cybersecurity and Infrastructure Security Agency. #StopRansomware Guide. Washington (DC): CISA; 2023.
- Nelson A, Rekhi S, Scarfone K, et al. Incident Response Recommendations and Considerations for Cybersecurity Risk Management: A CSF 2.0 Community Profile. Gaithersburg (MD): National Institute of Standards and Technology; 2025. NIST SP 800-61 Rev. 3. doi:10.6028/NIST.SP.800-61r3.
- US Department of Health and Human Services, Health Sector Coordinating Council. Health Industry Cybersecurity Practices: Managing Threats and Protecting Patients, 2023 Edition. Washington (DC): HHS; 2023.
- Cybersecurity and Infrastructure Security Agency. Cybersecurity Performance Goals. Washington (DC): CISA; 2023.
- Office for Civil Rights, US Department of Health and Human Services. Security Rule Guidance Material. Washington (DC): HHS; updated 2024.
- Joint Commission. Sentinel Event Alert 67: Preserving patient safety after a cyberattack. Jt Comm J Qual Patient Saf. 2023;49:724-729. doi:10.1016/j.jcjq.2023.07.006.
- Wani TA, Mendoza A, Gray K. Hospital bring-your-own-device security challenges and solutions: systematic review of gray literature. JMIR Mhealth Uhealth. 2020;8:e18175. doi:10.2196/18175.
- Kruse CS, Frederick B, Jacobson T, et al. Cybersecurity in healthcare: a systematic review of modern threats and trends. Technol Health Care. 2017;25:1-10. doi:10.3233/THC-161263.
- Martin G, Ghafur S, Kinross J, et al. WannaCry—a year on. BMJ. 2018;361:k2381. doi:10.1136/bmj.k2381.
- Ghafur S, Grass E, Jennings NR, et al. The challenges of cybersecurity in health care: the UK National Health Service as a case study. Lancet Digit Health. 2019;1:e10-e12. doi:10.1016/S2589-7500(19)30005-6.
- US Government Accountability Office. Critical Infrastructure Protection: Agencies Need to Enhance Oversight of Ransomware Practices and Assess Federal Support. Washington (DC): GAO; 2024. GAO-24-106221.
- National Institute of Standards and Technology. Security and Privacy Controls for Information Systems and Organizations. Gaithersburg (MD): NIST; 2020. NIST SP 800-53 Rev. 5. doi:10.6028/NIST.SP.800-53r5.
- National Institute of Standards and Technology. Zero Trust Architecture. Gaithersburg (MD): NIST; 2020. NIST SP 800-207. doi:10.6028/NIST.SP.800-207.

