{
  "incidents": [
    {
      "id": "ontario-ai-scribes-audit-2026",
      "title": "Ontario auditor: all 20 approved AI scribes produced inaccurate notes in testing",
      "date": "2026-05",
      "location": "Ontario, Canada",
      "summary": "Ontario's Auditor General found every AI scribe on the province's approved vendor list had fabricated, wrong or missing content in procurement tests, including 12 of 20 recording the wrong drug.",
      "what_happened": "The Auditor General's May 2026 special report on AI in the Ontario government reviewed Supply Ontario's evaluation of AI Scribe systems, which vendors tested on two simulated doctor-patient conversations. All 20 approved vendors showed at least one type of inaccuracy. Nine of 20 fabricated information, including treatment-plan steps such as therapy referrals or blood tests that were never discussed, and statements like 'no masses found'. Twelve of 20 recorded a different drug than the one prescribed. Seventeen of 20 missed key mental-health details in at least one test. Global News reported that vendors were not required to demonstrate their systems live and that at least five were approved without submitting required risk and privacy impact assessments. The province said the tests were an evaluation stage, not operational use.",
      "layers": [
        "models",
        "handoff"
      ],
      "tier_reached": 0,
      "cascade": false,
      "harm": "None documented; findings are from procurement testing, not patient records.",
      "lessons": [
        "Procurement approval is not evidence of accuracy; test on realistic encounters and set thresholds for drug and dose fields.",
        "Omissions were the most common error type, and they are the hardest for a reviewing clinician to see.",
        "Measure accuracy after go-live, not only at procurement."
      ],
      "source_ids": [
        "ontario-ag-2026-ai-report",
        "globalnews-2026-ontario-ai-scribes"
      ],
      "added": "2026-09-26",
      "last_audited": "2026-09-26",
      "audit_status": "verified",
      "kind": "event",
      "failure_type": "wrong-output",
      "tier_basis": "The automation stayed up and kept producing output that was wrong or went unchecked; there was no outage to fall back from."
    },
    {
      "id": "kinney-drugs-ai-burt-refill-2026",
      "title": "Pharmacy AI phone agent garbled drug names and placed wrong and duplicate refills",
      "date": "2026-05",
      "location": "Kinney Drugs, Vermont-based pharmacy chain, USA",
      "summary": "A pharmacy chain's AI voice and text assistant for refills mispronounced medications, ordered wrong dosages and duplicate refills, and gave callers no keypad alternative; after hundreds of complaints the chain pulled it back.",
      "what_happened": "Kinney Drugs deployed 'Burt', an AI assistant built by Synerio, in May 2026 to handle prescription and refill communication. VTDigger reported in July 2026 that customers heard garbled medication names, received wrong dosages and refills they did not need, and in one case accumulated four bottles of a twice-weekly drug; there was no keypad option, so patients had to talk to the AI to get refills. In August 2026 WCAX reported that after hundreds of complaints Kinney returned inbound calls to its touch-tone system and kept the AI only for opt-in outbound refill texts.",
      "layers": [
        "models",
        "handoff"
      ],
      "tier_reached": 1,
      "cascade": false,
      "harm": "Wrong and duplicate refills reported; no injury documented.",
      "lessons": [
        "An agent that acts on medication orders needs unambiguous readback of drug and dose before it acts.",
        "Launch with an always-available non-AI route; here it arrived only as the rollback.",
        "Complaint volume about a medication tool is a safety signal."
      ],
      "source_ids": [
        "vtdigger-2026-kinney-burt",
        "wcax-2026-kinney-pullback"
      ],
      "added": "2026-09-26",
      "last_audited": "2026-09-26",
      "audit_status": "verified",
      "kind": "event",
      "failure_type": "wrong-output",
      "tier_basis": "After complaints, inbound calls went back to the touch-tone system and the AI was kept only for opt-in outbound texts."
    },
    {
      "id": "abbott-libre3-sensor-recall-2025",
      "title": "FreeStyle Libre 3 sensors report falsely low glucose",
      "date": "2025-11-24",
      "location": "United States and worldwide",
      "summary": "Some Libre 3 and 3 Plus continuous glucose sensors read lower than actual glucose; FDA classified the correction Class I after reports of 860 serious injuries and 7 deaths.",
      "what_happened": "Abbott initiated a correction on 24 November 2025 after finding certain FreeStyle Libre 3 and 3 Plus sensors could give glucose readings lower than actual levels, which could lead users to take excess carbohydrate or skip or delay insulin. FDA classified it Class I. As of 7 January 2026, 860 serious injuries and 7 deaths had been reported. Users were told to check serial numbers, stop using affected sensors and use a blood glucose meter for treatment decisions until replacements arrived.",
      "layers": [
        "devices"
      ],
      "tier_reached": 0,
      "cascade": false,
      "harm": "860 serious injuries and 7 deaths reported as of 7 Jan 2026 (FDA).",
      "lessons": [
        "Silent measurement error in a home device reaches patients before it reaches the hospital.",
        "The fallback (fingerstick meter) must already be in the patient's hands and they must know when to use it.",
        "ECRI ranks recall communication failures for home diabetes technology a top-4 hazard for 2026."
      ],
      "source_ids": [
        "fda-abbott-libre3-recall-2025",
        "ecri-top10-hazards-2026"
      ],
      "added": "2026-09-26",
      "last_audited": "2026-09-26",
      "audit_status": "verified",
      "kind": "event",
      "failure_type": "wrong-output",
      "tier_basis": "The automation stayed up and kept producing output that was wrong or went unchecked; there was no outage to fall back from."
    },
    {
      "id": "aws-us-east-1-2025",
      "title": "AWS us-east-1 DynamoDB DNS failure disrupts cloud-hosted clinical systems",
      "date": "2025-10-20",
      "location": "AWS us-east-1 (Northern Virginia); effects in USA and UK",
      "summary": "A race condition in DynamoDB's DNS automation broke a core AWS region for about 15 hours. Some cloud-hosted EHR users slowed or went to paper; others saw nothing.",
      "what_happened": "From 11:48 PM PDT on 19 October to 2:20 PM PDT on 20 October 2025, an empty DNS record for DynamoDB's regional endpoint cascaded into EC2 launch failures, load balancer errors, Lambda and container problems. Tufts Medicine, which moved Epic to AWS in 2022, reported IT slowdowns and minor delays in lab results and said clinical care was not compromised. Baptist Memorial (also Epic on AWS) and Montefiore reported no disruption.\n\nIn England, a trust digital chief told Digital Health News that at least 10 NHS sites using Oracle systems went into downtime and reverted to paper; Central and North West London NHS FT confirmed it was affected. Oracle hosts some services on AWS.",
      "layers": [
        "connectivity",
        "cascades"
      ],
      "tier_reached": 2,
      "cascade": true,
      "harm": "None documented.",
      "lessons": [
        "Hosting on the same cloud does not mean the same exposure; architecture and region choice decide the blast radius.",
        "Your supplier's supplier can put you on paper.",
        "A slowdown that delays lab results is a clinical event even if systems are 'up'."
      ],
      "source_ids": [
        "aws-2025-dynamodb-pes",
        "beckers-2025-aws-tufts",
        "digitalhealth-2025-aws-nhs"
      ],
      "added": "2026-09-26",
      "last_audited": "2026-09-26",
      "audit_status": "verified",
      "kind": "event",
      "failure_type": "unavailable",
      "tier_basis": "At least 10 NHS sites using Oracle services went into downtime and reverted to paper; US Epic-on-AWS sites reported slowdowns or nothing."
    },
    {
      "id": "endoscopy-deskilling-study-2025",
      "title": "Endoscopists detect fewer adenomas without AI after AI is introduced",
      "date": "2025-08",
      "location": "Four endoscopy centres, Poland (ACCEPT trial)",
      "summary": "After AI polyp detection was introduced, the adenoma detection rate of standard non-AI colonoscopy fell from 28.4% to 22.4%.",
      "what_happened": "Four Polish centres in the ACCEPT trial introduced AI polyp detection at the end of 2021 and then randomised colonoscopies to AI or no AI by examination date. Budzyń and colleagues compared 795 non-AI colonoscopies in the three months before AI with 648 non-AI colonoscopies in the three months after (September 2021 to March 2022). The adenoma detection rate fell from 28.4% to 22.4%, an absolute difference of -6.0 percentage points (95% CI -10.5 to -1.6), and exposure to AI was independently associated with lower detection (odds ratio 0.69). The study is observational and retrospective; the authors say continuous AI exposure 'might' reduce unaided performance.",
      "layers": [
        "handoff",
        "models"
      ],
      "tier_reached": null,
      "cascade": false,
      "harm": "No individual harm documented; lower adenoma detection is a recognised quality marker associated with interval cancer risk (not measured in this study).",
      "lessons": [
        "Measure unaided performance after AI rollout, because assisted metrics hide skill loss.",
        "Deskilling can appear within months, faster than most revalidation cycles."
      ],
      "source_ids": [
        "budzyn-2025-lancet-gh-deskilling"
      ],
      "added": "2026-09-26",
      "last_audited": "2026-09-26",
      "audit_status": "verified",
      "kind": "study",
      "failure_type": "human-response"
    },
    {
      "id": "replit-agent-database-deletion-2025",
      "title": "Coding agent deleted a production database during a code freeze, then misreported recovery (non-clinical analogue)",
      "date": "2025-07",
      "location": "Replit / SaaStr, USA (non-clinical)",
      "summary": "Non-clinical analogue. An AI coding agent with write access ran destructive commands against a live database despite an instruction to freeze changes, then said rollback was impossible when it was not.",
      "what_happened": "In July 2025 SaaStr founder Jason Lemkin reported that Replit's AI agent deleted his production database while he had instructed it not to change code without permission. The agent told him rollback would not work; Lemkin later found the rollback did work. OWASP's Top 10 for Agentic Applications cites the case under 'Rogue Agents'. It is included here as a non-clinical analogue for agents with write access to clinical systems.",
      "layers": [
        "models"
      ],
      "tier_reached": null,
      "cascade": false,
      "harm": "Non-clinical; data loss, later recovered.",
      "lessons": [
        "Instructions are not permissions: enforce limits in the system the agent touches.",
        "Keep an independent log of what an agent did; its own report can be wrong.",
        "Separate production from anything an agent can change without approval."
      ],
      "source_ids": [
        "theregister-2025-replit-database",
        "owasp-2025-agentic-top10"
      ],
      "added": "2026-09-26",
      "last_audited": "2026-09-26",
      "audit_status": "verified",
      "kind": "analogue",
      "failure_type": "wrong-output"
    },
    {
      "id": "iberian-blackout-2025",
      "title": "Iberian Peninsula blackout",
      "date": "2025-04-28",
      "location": "Continental Spain and Portugal",
      "summary": "A grid collapse cut power to continental Spain and Portugal for about ten hours. Hospitals largely held on generators; care outside them did not.",
      "what_happened": "At 12:33 CEST cascading generator disconnections blacked out continental Spain and Portugal. Major Spanish hospitals kept ICUs, wards and active surgery running on generators, with no generator failures reported by those consulted, but suspended outpatient clinics and non-urgent surgery; scanners needed restart procedures and some lab analyzers and prescribing/records systems failed. In Portugal, a perspective by clinicians and officials reports hospitals on limited generator capacity, triaged equipment, inaccessible digital records and cold-chain failures.\n\nEMS lost communications and faced fuel shortages. Home device users were at acute risk; at least one death from ventilator failure is reported. A Nature Communications study estimated about 167 excess deaths in Spain over the following two days (95% credible interval 28 to 300), with no comparable signal in Portugal.",
      "layers": [
        "power",
        "connectivity",
        "devices",
        "cascades"
      ],
      "tier_reached": 3,
      "cascade": true,
      "harm": "Estimated +167 excess deaths in Spain (95% CrI +28 to +300), mainly women 85+; at least one home-ventilator death; eight directly attributed fatalities. In-hospital harm not documented in the sources reviewed.",
      "lessons": [
        "Hospitals that pass on generators still lose labs, imaging restarts, records and phones.",
        "The highest-risk patients during a blackout may be at home, not in the hospital.",
        "Plan for EMS and telecoms failing at the same moment as power."
      ],
      "source_ids": [
        "entsoe-2026-iberian-final-report",
        "eldiario-2025-hospitales-apagon",
        "goiana-da-silva-2025-fph-iberian",
        "castro-delgado-2025-pdm-blackout-ems",
        "konstantinoudis-2026-natcomms-iberian-mortality"
      ],
      "added": "2026-09-26",
      "last_audited": "2026-09-26",
      "audit_status": "verified",
      "kind": "event",
      "failure_type": "unavailable",
      "tier_basis": "Grid power lost nationally; in Portugal hospitals had limited generator capacity and triaged equipment, and EMS lost communications."
    },
    {
      "id": "ai-sepsis-alert-fluid-overload-2025",
      "title": "Sepsis alert nearly led to fluid loading of a dialysis patient",
      "date": "2025-03",
      "location": "St. Rose Dominican Hospital (Dignity Health), Henderson, NV, USA",
      "summary": "An automated sepsis alert triggered a protocol for large-volume IV fluids in a dialysis patient; the nurse objected, was told to follow the protocol, and a physician intervened.",
      "what_happened": "The Associated Press reported in March 2025 that emergency nurse Adam Hart's hospital computer system flagged a newly arrived patient for sepsis, and hospital protocol called for an immediate large dose of IV fluids. Hart recognised that the patient was on dialysis with kidney failure, for whom fluid loading is dangerous. His supervising nurse told him to follow the protocol, and a physician intervened. Nurses in the same AP report described frequent false alerts.\n\nScientific American (February 2026) named the hospital as St. Rose Dominican in Henderson, Nevada, and described the alert as coming from an AI system; the AP account says only that the computer system flagged the patient. The two accounts differ on what followed: AP says the patient received a slow infusion of IV fluids, while Scientific American says the physician ordered dopamine instead of fluids.",
      "layers": [
        "models",
        "handoff"
      ],
      "tier_reached": 0,
      "cascade": false,
      "harm": "None; averted by the nurse and physician.",
      "lessons": [
        "A protocol that starts automatically from a model flag turns advice into an order.",
        "The model could not see a contraindication visible at the bedside; override authority must be explicit.",
        "Near misses like this belong in the incident system so the protocol can be fixed."
      ],
      "source_ids": [
        "euronews-ap-2025-nurses-ai-sepsis",
        "sciam-2026-ai-nurses-schellmann"
      ],
      "added": "2026-09-26",
      "last_audited": "2026-09-26",
      "audit_status": "verified",
      "kind": "event",
      "failure_type": "wrong-output",
      "tier_basis": "The automation stayed up and kept producing output that was wrong or went unchecked; there was no outage to fall back from."
    },
    {
      "id": "bd-alaris-apr-backlog-2025",
      "title": "Alaris infusion interoperability backlog can load outdated pump orders",
      "date": "2025-02-18",
      "location": "United States",
      "summary": "A Class I software correction found that backlogged EHR-to-pump automated programming requests could load stale rate, dose or volume parameters.",
      "what_happened": "FDA announced that with BD Alaris Systems Manager (v12.5.2 and earlier) and Care Coordination Engine Infusion Adapter (v1.7.2), delayed responses could cause automated programming requests to back up, so an outdated request could later load on the pump with different rate, dose or volume parameters; if accepted, the patient could receive the wrong dose. It was classified as the most serious recall type. No injuries or deaths were reported. Clinicians were told to verify all parameters before starting and to update the adapter software. The same pump platform had a Class I software recall in 2020 for five issues including a low-battery alarm failure.",
      "layers": [
        "devices",
        "connectivity",
        "handoff"
      ],
      "tier_reached": 1,
      "cascade": false,
      "harm": "None reported (FDA).",
      "lessons": [
        "Integration queues turn latency into stale commands; a late order is a wrong order.",
        "Auto-programming does not remove the need for a human check at the pump; it moves the check.",
        "Watch interface engine queue depth as a patient safety signal, not an IT metric."
      ],
      "source_ids": [
        "fda-bd-alaris-apr-correction-2025",
        "fda-bd-alaris-2020-recall"
      ],
      "added": "2026-09-26",
      "last_audited": "2026-09-26",
      "audit_status": "verified",
      "kind": "event",
      "failure_type": "wrong-output",
      "tier_basis": "Clinicians were told to verify every pump parameter against the order before starting: automation demoted to advice."
    },
    {
      "id": "contec-cms8000-backdoor-2025",
      "title": "Contec CMS8000 patient monitors: hidden remote-access function disclosed by CISA and FDA",
      "date": "2025-01-30",
      "location": "United States (FDA/CISA advisories); devices sold in US and EU",
      "summary": "CISA and FDA reported that a low-cost patient monitor's firmware contained hidden functionality that could allow remote access and sent patient data to an external address; independent researchers later judged it an insecure design rather than an intentional backdoor.",
      "what_happened": "On 30 January 2025 CISA and FDA reported that Contec CMS8000 monitors (and relabeled Epsimed MN-120) contained hidden functionality connecting to hard-coded IP addresses, could be remotely controlled, and exfiltrated patient data once networked; the firmware could enable network interfaces even when disabled. CVEs included CVE-2025-0626 (hidden functionality) and CVE-2024-12248 (out-of-bounds write, CVSS v3.1 9.8). With no patch, FDA told users to unplug ethernet and disable wireless, or stop using the monitor if they depended on remote monitoring. A July 2025 patch removed networking entirely. FDA reported no known incidents, injuries or deaths.\n\nTwo security firms analysed the firmware afterwards. Claroty's Team82 (2 February 2025) concluded the function was most likely not a hidden backdoor but an insecure design: the hard-coded address appears in the vendor's and resellers' manuals as the central management system, and an update needs a physical button press. Cylera (4 February 2025) called it not an intentional backdoor but an unfortunate use of a public IPv4 address range in an internal setting. CISA's updated advisory (25 February 2025) added a vulnerability credited to Claroty and still says the function could serve as a backdoor; FDA's communication still describes a backdoor.",
      "layers": [
        "devices",
        "connectivity"
      ],
      "tier_reached": null,
      "cascade": false,
      "harm": "None documented (FDA, as of July 2025 update).",
      "lessons": [
        "Firmware can do things the settings screen says it does not; verify network behavior with traffic capture, not configuration.",
        "The only mitigation for a compromised device may be to remove its connectivity, so plan for local-only operation.",
        "Procurement must require an SBOM and a vulnerability disclosure process for every networked monitor, however cheap."
      ],
      "source_ids": [
        "fda-contec-cms8000-2025",
        "cisa-icsma-25-030-01",
        "claroty-team82-contec-2025",
        "cylera-contec-2025"
      ],
      "added": "2026-09-26",
      "last_audited": "2026-09-26",
      "audit_status": "verified",
      "kind": "event",
      "failure_type": "vulnerability"
    },
    {
      "id": "whisper-confabulation-2024",
      "title": "Whisper-based medical transcription invents text, and the audio is deleted",
      "date": "2024-10",
      "location": "United States (Nabla tool used by 40 health systems)",
      "summary": "Researchers and an AP investigation found OpenAI's Whisper speech-to-text model inserting fabricated sentences, and a Whisper-based clinical scribe used by over 30,000 clinicians erased the source audio, removing the way to check.",
      "what_happened": "A peer-reviewed FAccT 2024 study found about 1% of Whisper transcriptions contained whole phrases or sentences absent from the audio, 38% of which included explicit harms such as violent content, false associations or implied false authority; rates were higher for speakers with aphasia and long pauses. In October 2024 the Associated Press reported that over 30,000 clinicians and 40 health systems had adopted a Whisper-based tool from Nabla, used for about 7 million visits, despite OpenAI's warning against use in high-risk domains. Nabla's tool erased the original audio for data-safety reasons, so transcripts could not be compared with the recording; the company said providers must edit and approve notes.",
      "layers": [
        "models",
        "handoff"
      ],
      "tier_reached": null,
      "cascade": false,
      "harm": "No specific patient harm documented in the cited sources; risk is erroneous content in medical records.",
      "lessons": [
        "Keep the source audio; deleting it removes the only ground truth.",
        "General-purpose speech models need clinical validation before they write to the chart.",
        "Clinician sign-off is the last control, so it needs time and tooling to work."
      ],
      "source_ids": [
        "koenecke-2024-careless-whisper",
        "ap-2024-whisper-hospitals"
      ],
      "added": "2026-09-26",
      "last_audited": "2026-09-26",
      "audit_status": "verified",
      "kind": "study",
      "failure_type": "wrong-output"
    },
    {
      "id": "crowdstrike-2024",
      "title": "CrowdStrike Falcon content update crashes Windows hosts, including hospital systems",
      "date": "2024-07-19",
      "location": "Global; US hospitals including Mass General Brigham, Dana-Farber, Memorial Sloan Kettering, Duke",
      "summary": "A faulty Rapid Response Content update to CrowdStrike's Falcon sensor crashed about 8.5 million Windows devices worldwide. Outside-in measurement found disrupted services at 759 of 2,232 US hospitals studied.",
      "what_happened": "CrowdStrike's root cause analysis says a new IPC Template Type defined 21 input fields, but the sensor code that called it supplied only 20. Testing and early deployments used wildcard matching for the 21st field, so the mismatch stayed latent. On 19 July 2024 a new Channel File 291 used a non-wildcard criterion for the 21st field. That triggered an out-of-bounds memory read, and Windows hosts that received it crashed. CrowdStrike's remediations include bounds checks, more testing, staged deployment through rings, and customer control over content rollout. Microsoft estimated 8.5 million Windows devices were affected, under 1% of the total, and noted that the damage was outsized because enterprises running critical services use CrowdStrike. CISA confirmed it was not a cyberattack but warned of phishing that took advantage of the outage.\n\nTully et al. (JAMA Network Open, 2025) scanned hospital IP space and Epic FHIR endpoints from outside. Of 2,232 US hospitals, 759 (34.0%) had detectable disruptions. Of 1,098 disrupted services, 239 (21.8%) were patient-facing. Most services came back within 6 hours, but 43 were down for more than 48 hours. The authors note that network measurement is only a surrogate for clinical impact.",
      "layers": [
        "devices",
        "connectivity",
        "cascades",
        "handoff"
      ],
      "tier_reached": 2,
      "cascade": true,
      "harm": "None documented at the patient level. Tully et al. could not confirm patient outcomes. 239 patient-facing services were disrupted at US hospitals.",
      "lessons": [
        "A security agent with kernel access and vendor-controlled auto-update is a single point of failure across every workstation and device that runs it.",
        "Recovery time is set by hands-on per-machine remediation (disk encryption keys, physical access), not by how fast the vendor rolls back.",
        "Demand staged, customer-controlled update rings for any agent on clinical endpoints.",
        "Redundancy inside a hospital does not help when primary and backup run the same agent and receive the same update.",
        "Security tooling with kernel-level access is itself a common-mode dependency.",
        "Customer control over staged rollout is a contract term worth asking for.",
        "Outside-in monitoring can measure a cascade across hundreds of hospitals within hours.",
        "A single vendor update can push many hospitals down a tier at the same moment, so a peer hospital cannot be assumed to be at tier 0.",
        "External measurement can detect the drop faster than internal reports.",
        "Plan recovery for hands-on work on each device."
      ],
      "source_ids": [
        "crowdstrike-rca-channel-file-291",
        "house-homeland-meyers-testimony-2024",
        "statnews-2024-crowdstrike-hospitals",
        "tully-2025-jama-netw-open-crowdstrike",
        "microsoft-2024-crowdstrike-8-5m-devices",
        "cisa-2024-crowdstrike-alert",
        "healthcarebrew-2024-mgb-crowdstrike"
      ],
      "added": "2026-09-26",
      "layer_path": [
        "devices",
        "connectivity",
        "handoff"
      ],
      "last_audited": "2026-09-26",
      "audit_status": "verified",
      "kind": "event",
      "failure_type": "unavailable",
      "tier_basis": "At Mass General Brigham, on-site staff went to downtime procedures and handwritten notes, according to Healthcare Brew; a scan of US hospitals found patient-facing services offline at many sites."
    },
    {
      "id": "synnovis-2024",
      "title": "Synnovis pathology ransomware, South-East London",
      "date": "2024-06-03",
      "location": "London, United Kingdom",
      "summary": "Ransomware hit Synnovis, the pathology provider for several south-east London NHS trusts and GP practices. Blood testing and matching collapsed, more than 11,000 appointments and procedures were postponed, O-type blood ran short nationally, and one death was later partly attributed to a delayed result.",
      "what_happened": "Synnovis says the 3 June 2024 attack affected almost all of its IT systems and interrupted many pathology services. Stolen data were published on 20 June, and full restoration took until late autumn 2024. Because the affected hospitals could not match patients' blood at the usual frequency, NHS Blood and Transplant appealed on 10 June for O-positive and O-negative donors. NHS England reported 10,152 acute outpatient appointments and 1,710 elective procedures postponed at King's College Hospital and Guy's and St Thomas'. The UK government now uses Synnovis as its case study for designating 'critical suppliers' under the Cyber Security and Resilience Bill, citing more than 11,000 disrupted appointments and operations and estimated losses of £32.7m.\n\nIn June 2025 King's College Hospital said a patient safety investigation into one patient's unexpected death had found several contributing factors, including a long wait for a blood test result caused by the attack. The Register reported that South East London ICB recorded 170 patients harmed, mostly low harm. In 2026 The Record reported that South London and Maudsley was still working with pathology systems that had not been fully restored, and had logged 122 incidents of incorrect, unavailable or delayed results.",
      "layers": [
        "connectivity",
        "cascades",
        "handoff"
      ],
      "tier_reached": 2,
      "cascade": true,
      "harm": "One death in which the delayed blood result was a contributing factor (KCH, June 2025). About 170 patients harmed, mostly low harm, per South East London ICB as reported by The Register. More than 10,000 appointments and 1,710 procedures postponed.",
      "lessons": [
        "Outsourced diagnostics are a clinical dependency: plan for weeks, not hours, without them.",
        "Loss of electronic crossmatch pushes blood banks to universal-donor units and drains regional stocks.",
        "Harm from delayed results surfaces months later; run structured harm reviews during and after the outage.",
        "One pathology supplier shared by several trusts and GP practices was a regional single point of failure.",
        "Loss of blood matching spread to national blood stocks through extra O-type demand.",
        "Recovery of downstream organisations can lag the supplier's recovery by more than a year.",
        "Regulators are moving to put critical suppliers under direct cyber rules.",
        "The failure of one supplier's lab system can drop several hospitals to tier 2 at once.",
        "Manual fallbacks such as universal-donor blood draw down national stocks, so the cascade reaches beyond the region.",
        "Recovery is prioritised and staged, and can take months."
      ],
      "source_ids": [
        "nhs-england-synnovis-incident",
        "bloomberg-2025-synnovis-harm",
        "therecord-2025-synnovis-death",
        "synnovis-cyber-update",
        "nhsbt-2024-o-type-appeal",
        "theregister-2025-qilin-nhs-death",
        "therecord-2026-synnovis-ongoing",
        "govuk-2026-csr-bill-critical-suppliers"
      ],
      "added": "2026-09-26",
      "layer_path": [
        "connectivity",
        "handoff"
      ],
      "last_audited": "2026-09-26",
      "audit_status": "verified",
      "kind": "event",
      "failure_type": "unavailable",
      "tier_basis": "Pathology IT was down for months; hospitals ran reduced blood matching and postponed work. Power and phones were not affected in the sources."
    },
    {
      "id": "ascension-2024",
      "title": "Ascension ransomware and multi-week EHR downtime",
      "date": "2024-05-08",
      "location": "United States (Ascension, 140 hospitals in multiple states)",
      "summary": "A ransomware attack took Ascension's electronic records offline for about five weeks. Clinicians told KFF Health News of medication errors and delayed lab results, and one said he had no training for the attack; Ascension said its care teams were trained for such disruptions.",
      "what_happened": "Ascension detected the attack on 8 May 2024 and took systems offline; hospitals diverted ambulances and pharmacies were disrupted. EHR access was restored across the network by 14 June and Ascension declared full restoration on 20 June; data recorded during downtime was not immediately visible in the restored record.\n\nClinicians in three states told KFF Health News of delayed or lost lab results, medication errors, and the loss of barcode checks. Specific reports included a patient who died after staff said they waited four hours for lab results that never came, and a patient given a narcotic meant for someone else who then needed a ventilator. Ascension did not confirm or dispute these accounts and said staff were trained for such disruptions.",
      "layers": [
        "connectivity",
        "handoff",
        "cascades"
      ],
      "tier_reached": 2,
      "cascade": true,
      "harm": "Clinician-reported adverse events, including a death and a wrong-patient narcotic, reported by KFF Health News/NPR; not confirmed by Ascension or any regulator.",
      "lessons": [
        "Paper workarounds built for hours do not hold for five weeks: order routing between departments breaks down.",
        "Losing barcode medication administration removes a key independent check; plan manual double-checks for high-risk drugs.",
        "Back-entering downtime data is its own risk period; the record stays incomplete after 'restoration'.",
        "The paper fallback is only as good as the last time staff practised it.",
        "Barcode and EHR safety checks disappear at tier 3; plan manual double-checks to replace them."
      ],
      "source_ids": [
        "kff-2024-ascension-lapses",
        "healthcaredive-2024-ascension-tracker"
      ],
      "added": "2026-09-26",
      "last_audited": "2026-09-26",
      "audit_status": "verified",
      "kind": "event",
      "failure_type": "unavailable",
      "tier_basis": "EHR and other clinical systems offline for about five weeks and care ran on paper, with barcode checks lost; loss of power or phones is not documented."
    },
    {
      "id": "change-healthcare-2024",
      "title": "Change Healthcare ransomware and national claims/pharmacy clearinghouse outage",
      "date": "2024-02-21",
      "location": "United States (national)",
      "summary": "Attackers used stolen credentials on a Change Healthcare Citrix remote-access portal that had no multi-factor authentication, then deployed ransomware nine days later. Disconnecting the clearinghouse stalled pharmacy claims, medical claims and payments across the US.",
      "what_happened": "According to UnitedHealth Group CEO Andrew Witty's Senate testimony, attackers used compromised credentials on 12 February 2024 to reach a Change Healthcare Citrix portal that had no multi-factor authentication. They moved laterally, took data, and deployed ALPHV/BlackCat ransomware on 21 February. UnitedHealth cut connectivity to Change's data centres to stop the spread, and rebuilt the environment over the following weeks. Change handles information, claims and payments between physicians, pharmacists, health plans and governments. Witty testified that pharmacists had to submit claims manually, that by 7 March 99% of pre-incident pharmacies could process claims, and that by late April more than $6.5 billion had been advanced to providers as accelerated payments and loans.\n\nAn American Hospital Association survey of nearly 1,000 hospitals (9–12 March 2024) found 94% reported financial impact and 74% reported direct impact on patient care. Nearly 40% said patients had trouble getting care because utilization requirements such as prior authorization were delayed, and about two-thirds reported difficulty switching to another clearinghouse. HHS later cited the attack in its January 2025 proposal to strengthen the HIPAA Security Rule.",
      "layers": [
        "connectivity",
        "cascades",
        "handoff"
      ],
      "tier_reached": 1,
      "cascade": true,
      "harm": "Direct patient-care impact reported by 74% of surveyed hospitals, including delayed access where prior authorization could not be processed (AHA survey). No individual clinical harm is quantified in the sources reviewed.",
      "lessons": [
        "A single third-party clearinghouse can be a national single point of failure even when no hospital is breached.",
        "Remote-access portals without MFA remain a primary entry point.",
        "Contract for, and test, a second clearinghouse or manual submission path before you need it.",
        "Plan cash-flow continuity as part of clinical continuity: payment outages hit care delivery within days.",
        "One clearinghouse was a single point of failure for a large share of US claims, pharmacy and prior-authorization traffic.",
        "Switching supplier during a crisis was hard for most hospitals; alternates must be enrolled beforehand.",
        "A missing MFA control on one remote-access portal was the latent condition that let the cascade start.",
        "Disconnecting to contain the attack was defensible, and it was also what stopped the downstream services."
      ],
      "source_ids": [
        "witty-2024-senate-finance-testimony",
        "aha-2024-change-survey",
        "aha-change-underscores-preparedness",
        "healthcaredive-2025-change-190m",
        "hhs-hipaa-security-nprm-2025"
      ],
      "added": "2026-09-26",
      "layer_path": [
        "connectivity",
        "handoff"
      ],
      "last_audited": "2026-09-26",
      "audit_status": "verified",
      "kind": "event",
      "failure_type": "unavailable",
      "tier_basis": "Providers' own clinical systems stayed up; claims, pharmacy benefit checks and prior authorisation were done manually or delayed."
    },
    {
      "id": "unitedhealth-nh-predict-denials-2023",
      "title": "Post-acute care denials rose as UnitedHealthcare automated prior authorization; lawsuit targets nH Predict",
      "date": "2023-11",
      "location": "United States (Medicare Advantage)",
      "summary": "A class action alleges UnitedHealth used naviHealth's nH Predict model to cut off post-acute care; a Senate investigation found UnitedHealthcare's post-acute denial rate nearly tripled while it automated prior authorization.",
      "what_happened": "In November 2023 families of two deceased Medicare Advantage members filed a proposed class action in Minnesota alleging that UnitedHealth used nH Predict to override physicians and end post-acute coverage, that the model had a 90% error rate, and that the insurer relied on only about 0.2% of members appealing. naviHealth said the tool is a guide, not used to make coverage determinations. These are allegations. In February 2025 Judge John Tunheim dismissed five of seven counts but let contract and good-faith claims proceed, calling the appeals process futile. Separately, the Senate Permanent Subcommittee on Investigations reported in October 2024 that UnitedHealthcare's post-acute prior-authorization denial rate rose from 8.7% in 2019 to 22.7% in 2022 while its overall denial rate stayed about 7.5%, during a period of automation initiatives. One internal model test noted an increase in adverse determinations. CMS stated in February 2024 that a length-of-stay prediction alone cannot be the basis to terminate post-acute care.",
      "layers": [
        "models",
        "handoff"
      ],
      "tier_reached": 0,
      "cascade": false,
      "harm": "Complaint alleges patients were discharged from care facilities or paid out of pocket; not adjudicated.",
      "lessons": [
        "A prediction presented as guidance can function as the decision if workflow and targets push staff to follow it.",
        "Low appeal rates hide high error rates; track reversal on appeal.",
        "Regulators now require individual assessment, so a model-only denial is a compliance failure as well as a safety one."
      ],
      "source_ids": [
        "cbs-2023-unitedhealth-nh-predict-lawsuit",
        "courthousenews-2025-uhg-ai-lawsuit-ruling",
        "psi-2024-ma-post-acute-report",
        "cms-2024-ma-faq-algorithms"
      ],
      "added": "2026-09-26",
      "last_audited": "2026-09-26",
      "audit_status": "verified",
      "kind": "event",
      "failure_type": "wrong-output",
      "tier_basis": "The automation stayed up and kept producing output that was wrong or went unchecked; there was no outage to fall back from."
    },
    {
      "id": "mammography-automation-bias-experiment-2023",
      "title": "Wrong AI suggestions pull radiologists' mammogram ratings off",
      "date": "2023-05",
      "location": "Germany (multi-institution reader experiment)",
      "summary": "In a controlled experiment, 27 radiologists' accuracy on mammograms fell sharply when a purported AI suggested an incorrect BI-RADS category.",
      "what_happened": "Dratsch and colleagues had 27 radiologists read 50 mammograms with a purported AI suggesting a BI-RADS category; in 12 of 40 test cases the suggestion was deliberately wrong. Correct ratings fell from 79.7% to 19.8% for inexperienced readers, 81.3% to 24.8% for moderately experienced readers, and 82.3% to 45.5% for very experienced readers when the suggestion was incorrect. Inexperienced readers were most likely to follow incorrect higher-category suggestions. This is an experiment, not a clinical event, and is listed as the clearest measurement of automation bias in a clinical task.",
      "layers": [
        "handoff",
        "models"
      ],
      "tier_reached": null,
      "cascade": false,
      "harm": "None (experimental setting).",
      "lessons": [
        "Expertise reduces automation bias but does not remove it.",
        "An AI that is usually right trains readers to follow it when it is wrong."
      ],
      "source_ids": [
        "dratsch-2023-radiology-mammography-automation-bias"
      ],
      "added": "2026-09-26",
      "last_audited": "2026-09-26",
      "audit_status": "verified",
      "kind": "experiment",
      "failure_type": "human-response"
    },
    {
      "id": "gstt-heatwave-datacentre-2022",
      "title": "Guy's and St Thomas': heatwave cooling failure takes down both data centres",
      "date": "2022-07-19",
      "location": "London, UK",
      "summary": "Air conditioning tripped at both trust data centres on the UK's record-heat day. Clinical IT went down and the trust ran on paper for weeks.",
      "what_happened": "On 19 July 2022 (London peaked at 40.3°C) condenser high-pressure trips shut down cooling at the Guy's data centre, which reached 50.3°C; the St Thomas' data centre suffered disk and controller failures. The two sites were each other's backup, a design the trust's review said could not cover a shared environmental cause. Cooling concerns had been raised in 2018 and a £195k replacement request from March 2022 was still unapproved. The remote environment monitoring for St Thomas' was hosted on the storage network that failed, and email alerts stopped.\n\nThe trust declared a critical incident and moved to a 'Paper Hospital'. Core clinical systems took about six weeks to recover, slowed by 371 interlinked systems. Activity fell to 64% of normal referrals and 68% of diagnostic tests. The same heat caused a cooling failure in a Google Cloud London zone that day.",
      "layers": [
        "power",
        "connectivity",
        "cascades"
      ],
      "tier_reached": 2,
      "cascade": true,
      "harm": "As of January 2023: one moderate harm (a patient could not be transplanted when organs became available), 20 low harms, no deaths or severe harm identified; the harm review remained open.",
      "lessons": [
        "Two data centres a few miles apart are one failure domain for weather.",
        "Monitoring that runs on the system it watches goes dark when you need it.",
        "Deferred cooling replacement is a clinical risk, not just an estates line item."
      ],
      "source_ids": [
        "gstt-2023-it-incident-review",
        "google-cloud-2022-europe-west2"
      ],
      "added": "2026-09-26",
      "last_audited": "2026-09-26",
      "audit_status": "verified",
      "kind": "event",
      "failure_type": "unavailable",
      "tier_basis": "Data-centre cooling failed and the trust ran a 'Paper Hospital' for about six weeks; clinical areas kept power."
    },
    {
      "id": "philips-respironics-2021",
      "title": "Philips Respironics ventilator, BiPAP and CPAP recall over degrading sound-abatement foam",
      "date": "2021-06-30",
      "location": "Worldwide (about 15 million devices); US",
      "summary": "Philips recalled about 15 million breathing devices because PE-PUR foam could degrade into particles and chemicals the patient could inhale; remediation ran years and ended in a consent decree.",
      "what_happened": "On 30 June 2021 Philips Respironics recalled certain ventilators, BiPAP and CPAP machines (Class I) because the polyester-based polyurethane foam used to reduce noise could break down, releasing particles or invisible chemicals into the air path. FDA issued a section 518(a) order in March 2022 over the adequacy of recall notifications. By 31 January 2024 FDA had received more than 116,000 MDRs, including 561 death reports, associated with foam breakdown; FDA notes MDRs cannot by themselves establish cause.\n\nOn 9 April 2024 a federal court entered a consent decree restricting new device production at three Philips facilities until compliance, requiring a recall remediation plan and independent review of testing of the replacement silicone foam. Separately, in July 2024 a Class I software correction for Trilogy Evo ventilators addressed issues including an inaccurate display of delivered oxygen.",
      "layers": [
        "devices"
      ],
      "tier_reached": 0,
      "cascade": false,
      "harm": "561 death reports and over 116,000 MDRs associated with foam breakdown as of Jan 2024; causation not established by MDRs alone.",
      "lessons": [
        "A hazard can sit inside a working device for years with no alarm or visible symptom.",
        "Recall execution (replacement supply, notification, patient tracing) is a failure point of its own.",
        "Home-use life-support devices need a registry the hospital or DME supplier can query when a recall lands."
      ],
      "source_ids": [
        "fda-philips-activities",
        "fda-philips-mdrs",
        "fda-philips-consent-decree-2024",
        "fda-philips-trilogy-evo-correction-2024"
      ],
      "added": "2026-09-26",
      "last_audited": "2026-09-26",
      "audit_status": "verified",
      "kind": "event",
      "failure_type": "latent-hazard",
      "tier_basis": "No loss of automation is documented."
    },
    {
      "id": "epic-sepsis-model-2021",
      "title": "Epic Sepsis Model missed two-thirds of sepsis cases in external validation",
      "date": "2021-06",
      "location": "Michigan Medicine, Ann Arbor, MI, USA (model deployed at hundreds of US hospitals)",
      "summary": "An independent validation of Epic's proprietary sepsis score found it far less accurate than the vendor reported: it missed 67% of sepsis cases while alerting on 18% of all hospitalizations.",
      "what_happened": "Wong and colleagues applied the Epic Sepsis Model retrospectively to 38,455 hospitalizations of 27,697 patients at Michigan Medicine. The hospitalization-level AUC was 0.63, against the developer's reported 0.76 to 0.83. At the alert threshold of 6 the model had 33% sensitivity and 12% positive predictive value; it did not identify 1,709 of the 2,552 patients with sepsis, and it flagged only 183 septic patients (7%) whom clinicians had not already treated with timely antibiotics. Alerts fired on 6,971 hospitalizations. A 2026 multicenter validation of the redesigned version 2 found better discrimination (encounter-level AUROC 0.82 to 0.92) but still low PPV (0.13 to 0.26), high alert burden and wide variation between the four health systems.",
      "layers": [
        "models",
        "handoff"
      ],
      "tier_reached": null,
      "cascade": false,
      "harm": "No individual patient harm documented in the study; the documented effect is missed detection and alert burden at scale.",
      "lessons": [
        "Vendor-reported accuracy is not local accuracy; validate before go-live.",
        "Counting alerts fired says nothing about the cases the model missed.",
        "A better model version still needs local validation because performance varies by site.",
        "Every alert a model fires is work assigned to a person; count it before deployment.",
        "An alert with low precision teaches clinicians to ignore the alerts that are right."
      ],
      "source_ids": [
        "wong-2021-jama-im-epic-sepsis",
        "wong-2026-jama-netw-open-esm-v2"
      ],
      "added": "2026-09-26",
      "last_audited": "2026-09-26",
      "audit_status": "verified",
      "kind": "study",
      "failure_type": "wrong-output"
    },
    {
      "id": "san-diego-ransomware-spillover-2021",
      "title": "Ransomware spillover to adjacent San Diego emergency departments",
      "date": "2021-05-01",
      "location": "San Diego County, California, United States",
      "summary": "A month-long ransomware attack on a health system with about 25% of regional inpatient discharges drove patients and ambulances to two unaffected academic EDs, raising their census, waits and stroke activations.",
      "what_happened": "Dameff et al. (JAMA Network Open, 2023) compared two urban academic emergency departments that were not attacked, before, during and after a ransomware attack (1–28 May 2021) on a neighbouring health system with about 25% of San Diego County's inpatient discharges. During the attack phase the unaffected EDs saw a 15.1% rise in daily census, 35.2% more ambulance arrivals, a 127.8% rise in patients leaving without being seen, and a 47.6% rise in median waiting-room time. Confirmed strokes rose from 22 to 47, and county-wide EMS diversion hours also rose.\n\nThe study is the clearest evidence that a cyberattack on one organisation becomes a capacity and time-critical-care problem for its neighbours.",
      "layers": [
        "connectivity",
        "handoff",
        "cascades"
      ],
      "layer_path": [
        "connectivity",
        "handoff"
      ],
      "tier_reached": 2,
      "cascade": true,
      "harm": "Adverse outcomes at the attacked system are not documented in the source reviewed. At adjacent EDs, delays (longer waits and length of stay, more patients leaving without being seen) and higher stroke volumes were documented.",
      "lessons": [
        "Neighbouring hospitals absorb the load of an attacked system without any warning.",
        "Stroke and other time-critical pathways are where spillover shows first.",
        "Regional plans need to treat one member's cyber outage as a regional surge event.",
        "A multi-week tier 2 outage at one hospital raises the load on neighbouring hospitals, so exercise regionally.",
        "Plan for weeks, not hours.",
        "Time-critical pathways such as stroke need downtime versions at receiving hospitals too."
      ],
      "source_ids": [
        "dameff-2023-jama-netw-open-adjacent-eds",
        "tjc-sea-67-cyberattack"
      ],
      "added": "2026-09-26",
      "last_audited": "2026-09-26",
      "audit_status": "verified",
      "kind": "event",
      "failure_type": "unavailable",
      "tier_basis": "The study reports, citing local media, that the attacked system lost its electronic health records, imaging and telemedicine systems and reverted to paper records for about four weeks. The neighbouring EDs stayed at tier 0 under load."
    },
    {
      "id": "texas-winter-storm-2021",
      "title": "Texas winter storm: record load shed, hospitals lose water and heat",
      "date": "2021-02-14",
      "location": "Texas, USA",
      "summary": "Freezing weather knocked out generation and forced the largest controlled load shed in US history. Power loss spread to water systems and hospitals, and to patients at home on powered medical equipment.",
      "what_happened": "FERC and NERC reported that during the week of 14 February 2021, ERCOT averaged 34,000 MW of generation outages for more than two days, nearly half its all-time winter peak load. The controlled firm load shed of 23,418 MW was the largest in US history. The joint inquiry's recommendations include gas–electric coordination and mapping critical interdependent natural gas and electric infrastructure. Power loss stopped water treatment. In Austin, St David's South Austin Medical Center lost water pressure and heat because its boiler depended on water, and began moving patients. Its CEO said no single hospital could take a large number of transfers. Galveston and Houston hospitals also reported water problems, and about 800 people sheltered in Southeast Texas emergency departments seeking oxygen refills and power for home medical equipment.\n\nThe Texas Department of State Health Services confirmed 246 storm-related deaths. Twenty-five of them (10.2%) were from exacerbation of pre-existing illness, linked to disruption of dialysis or oxygen, frozen medical devices and medication, and loss of power to life-sustaining equipment.",
      "layers": [
        "power",
        "cascades",
        "devices",
        "handoff"
      ],
      "tier_reached": 3,
      "cascade": true,
      "harm": "246 deaths confirmed as storm-related by Texas DSHS, including 25 from exacerbation of pre-existing illness tied to dialysis or oxygen disruption and loss of power to life-sustaining equipment. The hospital-level harm is not separately quantified.",
      "lessons": [
        "A hospital with working generators can still lose heat because the boiler depends on city water.",
        "Grid load-shed lists that leave fuel supply unprotected turn a power problem into a fuel problem.",
        "Regional events remove the transfer destinations your plan assumed.",
        "Hospital generators protect electricity, not the water, gas and heating that depend on the grid.",
        "In a region-wide event the transfer plan fails because every neighbour is degraded at once.",
        "Patients on home devices become ED patients when the grid fails.",
        "Infrastructure interdependencies (gas → power → water) have to be mapped explicitly."
      ],
      "source_ids": [
        "ferc-nerc-2021-cold-weather",
        "texastribune-2021-austin-hospitals",
        "dshs-2021-winter-storm-deaths",
        "ferc-nerc-2022-feb2021-outages-tracking",
        "circleofblue-2021-austin-hospitals-water",
        "abc-2021-texas-hospitals-water"
      ],
      "added": "2026-09-26",
      "layer_path": [
        "power",
        "devices",
        "handoff"
      ],
      "last_audited": "2026-09-26",
      "audit_status": "verified",
      "kind": "event",
      "failure_type": "unavailable",
      "tier_basis": "A hospital lost water pressure and heat and began moving patients; power was shed across the grid."
    },
    {
      "id": "pulse-oximetry-bias-2020",
      "title": "Pulse oximeters overestimate oxygen saturation in patients with darker skin",
      "date": "2020-12-17",
      "location": "United States (University of Michigan and 178-hospital cohort; Johns Hopkins COVID-19 cohort)",
      "summary": "Paired SpO2/SaO2 data showed occult hypoxemia missed by pulse oximetry about three times as often in Black as in White patients, delaying treatment decisions.",
      "what_happened": "Sjoding and colleagues compared pulse oximetry with arterial blood gas measurements. Occult hypoxemia (SaO2 below 88% while SpO2 read 92-96%) occurred in 11.7% of measurements in Black patients vs 3.6% in White patients at Michigan, and 17.0% vs 6.2% in a multicenter cohort. A 2022 Johns Hopkins COVID-19 study found SpO2 overestimated SaO2 by 1.1-1.7 points in Asian, Black and Hispanic patients relative to White patients, and Black patients had a 29% lower hazard of being recognized as eligible for oxygen-threshold therapies.\n\nFDA issued a safety communication in February 2021, held advisory panels in November 2022 and February 2024, and issued draft guidance on 7 January 2025 revising performance testing across skin pigmentation. As of this review FDA's product page still lists the January 2025 guidance as draft.",
      "layers": [
        "devices",
        "models"
      ],
      "tier_reached": null,
      "cascade": false,
      "harm": "Documented delayed or missed recognition of treatment eligibility (Fawzy 2022); individual patient outcomes not attributed.",
      "lessons": [
        "A device that keeps reporting a plausible wrong number triggers no downtime procedure at all.",
        "Validation populations define who the device is accurate for; ask for the data by skin tone.",
        "Thresholds built on a biased sensor (triage, therapy eligibility, early-warning scores) inherit the bias."
      ],
      "source_ids": [
        "sjoding-2020-nejm-pulse-oximetry",
        "fawzy-2022-jama-im-pulse-oximetry-covid",
        "fda-pulse-oximeters-actions",
        "fda-2025-pulse-oximeter-draft-guidance"
      ],
      "added": "2026-09-26",
      "last_audited": "2026-09-26",
      "audit_status": "verified",
      "kind": "study",
      "failure_type": "wrong-output"
    },
    {
      "id": "va-unknown-queue-2020",
      "title": "VA Oracle Cerner EHR 'unknown queue' silently dropped clinical orders",
      "date": "2020-10",
      "location": "Mann-Grandstaff VA Medical Center, Spokane, Washington, United States",
      "summary": "After go-live, the new EHR routed more than 11,000 clinical orders to a hidden queue instead of the intended service, without telling the ordering clinician; VHA identified 149 adverse events.",
      "what_happened": "The new EHR let providers pick service locations that the system could not match; unmatched orders went to an 'unknown queue' rather than to specialty care, lab or imaging, and the provider received no alert. From go-live in October 2020 to June 2021 more than 11,000 orders were not delivered. The first trouble ticket about lost orders was placed on 28 October 2020, four days after go-live; the OIG found no evidence that the vendor gave VA actionable information about the queue beforehand.\n\nVHA's clinical review of 1,286 event assessments classified 149 adverse events (2 major, 52 moderate, 95 minor). Mitigation relied on staff manually monitoring and re-entering queued orders; 206 orders were still in the queue across VHA sites on 16 May 2022.",
      "layers": [
        "connectivity",
        "handoff"
      ],
      "tier_reached": 0,
      "cascade": false,
      "harm": "149 adverse events classified by VHA: 2 major harm, 52 moderate, 95 minor.",
      "lessons": [
        "The dangerous failure is the one that looks like success: every order appeared placed.",
        "Every interface and routing layer needs a dead-letter queue that someone owns and watches daily.",
        "Ask vendors to disclose every place data can be parked or dropped before go-live."
      ],
      "source_ids": [
        "va-oig-2022-unknown-queue"
      ],
      "added": "2026-09-26",
      "last_audited": "2026-09-26",
      "audit_status": "verified",
      "kind": "event",
      "failure_type": "wrong-output",
      "tier_basis": "The automation stayed up and kept producing output that was wrong or went unchecked; there was no outage to fall back from."
    },
    {
      "id": "uhs-2020",
      "title": "Universal Health Services enterprise-wide IT shutdown",
      "date": "2020-09-27",
      "location": "United States (UHS acute and behavioral hospitals)",
      "summary": "A security incident led UHS to suspend user access to IT applications across its US operations; facilities ran on offline documentation for up to several weeks.",
      "what_happened": "Early on 27 September 2020 UHS experienced an IT security incident and suspended user access to its IT applications for US operations. Facilities used established back-up processes, including offline documentation. Applications were restored on a rolling basis during October 2020.\n\nUHS's 10-K reports that ambulance traffic and elective procedures were diverted to competitors, that coding and billing were delayed into December, and that the incident had an estimated $67 million pre-tax impact in 2020. The company states care was delivered safely and found no evidence of patient data being accessed.",
      "layers": [
        "connectivity",
        "cascades"
      ],
      "tier_reached": 2,
      "cascade": true,
      "harm": "None documented; company states care continued safely. No independent harm review found.",
      "lessons": [
        "Shutting everything off is a containment choice with a clinical cost: prepare paper for every unit before you need it.",
        "Revenue-cycle recovery lags clinical recovery by months."
      ],
      "source_ids": [
        "uhs-2020-8k",
        "uhs-2020-10k"
      ],
      "added": "2026-09-26",
      "last_audited": "2026-09-26",
      "audit_status": "verified",
      "kind": "event",
      "failure_type": "unavailable",
      "tier_basis": "User access to IT applications was suspended for weeks and facilities used offline documentation."
    },
    {
      "id": "michigan-sepsis-model-covid-shift-2020",
      "title": "Sepsis model switched off after COVID-19 changed the patient mix",
      "date": "2020-04",
      "location": "University of Michigan Hospital, Ann Arbor, MI, USA; alert surge measured across 24 US hospitals",
      "summary": "Weeks after its first COVID-19 admissions, the University of Michigan paused Epic sepsis alerts because dataset shift produced spurious alerting; its clinical AI committee decommissioned the model.",
      "what_happened": "Finlayson and colleagues report that the University of Michigan Hospital deactivated the Epic sepsis-alerting model in April 2020 because changes in patient characteristics during the pandemic altered the relationship between fever and bacterial sepsis, producing spurious alerts; the hospital's clinical AI governing committee decommissioned its use. A companion study of 24 US hospitals found the share of patients generating sepsis alerts per day rose from 9% to 21% in the three weeks after each hospital's first COVID-19 case, while census fell. Michigan paused alerts 3 to 4 weeks after its first COVID-19 hospitalization, following nursing reports of overalerting.",
      "layers": [
        "models",
        "handoff"
      ],
      "tier_reached": 1,
      "cascade": false,
      "harm": "None documented.",
      "lessons": [
        "A model can become wrong overnight when the population changes, with no error message.",
        "Frontline staff noticed first; nursing reports of overalerting were the trigger.",
        "Having a governance body with authority to switch the model off turned a silent failure into a controlled tier-1 fallback."
      ],
      "source_ids": [
        "finlayson-2021-nejm-dataset-shift",
        "wong-2021-jama-netw-open-sepsis-covid-alerts"
      ],
      "added": "2026-09-26",
      "last_audited": "2026-09-26",
      "audit_status": "verified",
      "kind": "event",
      "failure_type": "wrong-output",
      "tier_basis": "The hospital deactivated the sepsis model after its alerts became spurious."
    },
    {
      "id": "care-management-algorithm-bias-2019",
      "title": "Care-management algorithm under-referred Black patients because it predicted cost, not illness",
      "date": "2019-10",
      "location": "United States (commercial algorithm; the authors say it affects millions of patients)",
      "summary": "A widely used commercial risk algorithm assigned Black patients the same scores as healthier White patients, because it was trained to predict health-care spending, which is lower for Black patients at the same level of need.",
      "what_happened": "Obermeyer and colleagues analysed a commercial algorithm that health systems use to select patients for high-risk care-management programmes. At any given risk score, Black patients had more uncontrolled chronic illness than White patients. The cause was the training label: the model predicted future cost, and unequal access to care means less is spent on Black patients with the same needs. Correcting the disparity would have raised the share of Black patients receiving additional help from 17.7% to 46.5%. The paper does not name the vendor.",
      "layers": [
        "models"
      ],
      "tier_reached": null,
      "cascade": false,
      "harm": "Systematic under-referral of Black patients to extra care; individual patient harm not quantified.",
      "lessons": [
        "Check what the model is actually trained to predict; a convenient proxy can encode inequity.",
        "Aggregate accuracy can look good while one group is badly served; report by subgroup.",
        "Section 1557 now requires covered entities to look for and mitigate this risk in decision-support tools."
      ],
      "source_ids": [
        "obermeyer-2019-science-racial-bias",
        "hhs-45cfr92-210"
      ],
      "added": "2026-09-26",
      "last_audited": "2026-09-26",
      "audit_status": "verified",
      "kind": "study",
      "failure_type": "wrong-output"
    },
    {
      "id": "uber-tempe-2018",
      "title": "Uber automated test vehicle kills pedestrian while safety operator is distracted (non-clinical analogue)",
      "date": "2018-03-18",
      "location": "Tempe, Arizona, USA",
      "summary": "Non-clinical analogue. The human operator meant to back up an automated driving system was looking at her phone; the NTSB cited automation complacency.",
      "what_happened": "NON-CLINICAL ANALOGUE. An Uber automated test vehicle travelling at 45 mph struck a pedestrian; the automated driving system detected her 5.6 seconds before impact. The NTSB (report HAR-19-03) found the probable cause was the operator's failure to monitor the driving environment and the automated system because she was visually distracted throughout the trip by her personal phone. Contributing factors included Uber's inadequate safety procedures, ineffective oversight of vehicle operators, and a lack of adequate mechanisms for addressing operators' automation complacency.",
      "layers": [
        "handoff"
      ],
      "tier_reached": null,
      "cascade": false,
      "harm": "Non-clinical: death of the pedestrian.",
      "lessons": [
        "A human asked to watch a mostly reliable system will stop watching unless the organisation designs against it.",
        "Automation complacency is an organisational finding, not only an individual one."
      ],
      "source_ids": [
        "ntsb-har-19-03-uber-tempe"
      ],
      "added": "2026-09-26",
      "last_audited": "2026-09-26",
      "audit_status": "verified",
      "kind": "analogue",
      "failure_type": "human-response"
    },
    {
      "id": "hollywood-hills-irma-2017",
      "title": "Hurricane Irma: nursing home loses air conditioning while power stays on",
      "date": "2017-09-10",
      "location": "Hollywood, Florida, USA",
      "summary": "Irma knocked out the transformer feeding a nursing home's air conditioning. 14 residents died; 12 deaths were ruled homicides.",
      "what_happened": "The Rehabilitation Center at Hollywood Hills kept electrical power after Irma, but the transformer supplying its air conditioning failed. Staff used portable fans and cooling units; by the third day residents were in distress, and eight died on 13 September 2017. Four more died in the following weeks; the medical examiner ruled 12 deaths homicides and staff faced manslaughter charges. A cohort study across 54,095 Florida nursing home residents found power loss after Irma raised the odds of death within 7 days by 25%.",
      "layers": [
        "power",
        "cascades"
      ],
      "tier_reached": 3,
      "cascade": false,
      "harm": "14 deaths; 12 ruled homicides from environmental heat exposure.",
      "lessons": [
        "Cooling is a life-safety load; 'we still have power' is not the same as 'we still have cooling'.",
        "Heat harm to frail patients builds over days, so escalation triggers must be set in advance."
      ],
      "source_ids": [
        "npr-2019-hollywood-hills",
        "skarha-2021-jamahf-irma-nursing-homes"
      ],
      "added": "2026-09-26",
      "last_audited": "2026-09-26",
      "audit_status": "verified",
      "kind": "event",
      "failure_type": "unavailable",
      "tier_basis": "The building kept power, but the transformer supplying its air conditioning failed. Loss of HVAC where temperature control is needed is a tier 3 trigger."
    },
    {
      "id": "wannacry-nhs-2017",
      "title": "WannaCry ransomware across the NHS in England",
      "date": "2017-05-12",
      "location": "England, United Kingdom",
      "summary": "A self-spreading ransomware worm infected 34 English trusts and 603 primary-care and other NHS organisations, and at least 46 more trusts were disrupted. Thousands of appointments were cancelled and five hospitals diverted ambulances.",
      "what_happened": "The National Audit Office found that at least 80 of 236 trusts in England were affected: 34 infected and locked out of devices (25 of them acute trusts) and 46 not infected but disrupted. Many of the 46 shut down email and other systems as a precaution because central advice did not reach them early enough, and had to use pen and paper. A further 603 primary-care and other NHS organisations were infected, including 595 GP practices. Five acute trusts diverted emergency ambulances to other hospitals. NHS England counted 6,912 cancelled appointments and estimated about 19,000 in total. All infected organisations had unpatched or unsupported Windows systems, and before the attack none of the 88 trusts NHS Digital had assessed had passed its cyber-security assessment.\n\nGhafur et al. (npj Digital Medicine, 2019) analysed hospital episode data. Infected hospitals had about 6% fewer admissions per day during the attack week (4% fewer emergency and 9% fewer elective). The lost activity was valued at £5.9m. No measurable change in A&E deaths was found.",
      "layers": [
        "connectivity",
        "devices",
        "cascades",
        "handoff"
      ],
      "tier_reached": 2,
      "cascade": true,
      "harm": "NHS organisations reported no cases of patient harm (NAO). Ghafur et al. found no significant change in deaths in A&E but fewer admissions at infected hospitals. Harm from delayed care was not measured.",
      "lessons": [
        "Precautionary disconnection disrupts as much as infection: the 46 'not infected but disrupted' trusts were a planned response, not collateral damage.",
        "Unsupported operating systems inside diagnostic devices turn an IT outage into a diagnostic outage.",
        "Central alerts without a way to verify local patching leave the system exposed.",
        "Precautionary shutdowns at uninfected trusts caused more disruption than the infection itself in many places.",
        "Unpatched systems were a known, fixable latent condition across the network.",
        "Neither the Department nor NHS England knew how many organisations were disrupted because they shared data or systems with infected trusts.",
        "Diverting ambulances pushed the load onto neighbouring hospitals."
      ],
      "source_ids": [
        "nao-2017-wannacry",
        "nhs-2018-wannacry-lessons-learned",
        "ghafur-2019-npj-wannacry"
      ],
      "added": "2026-09-26",
      "layer_path": [
        "connectivity",
        "devices",
        "handoff"
      ],
      "last_audited": "2026-09-26",
      "audit_status": "verified",
      "kind": "event",
      "failure_type": "unavailable",
      "tier_basis": "Infected trusts were locked out of devices and systems and used pen and paper; five diverted ambulances. Loss of power or phones is not documented."
    },
    {
      "id": "princeton-community-petya-2017",
      "title": "Princeton Community Hospital Petya ransomware",
      "date": "2017",
      "location": "Princeton, WV, USA",
      "summary": "Ransomware made the EHR inaccessible; the hospital moved to paper within an hour and restored computers after 36 hours.",
      "what_happened": "As recounted by the Joint Commission, staff arrived to find Petya ransomware notices. The EHR was inaccessible and email was down. Within an hour, the hospital activated its incident response plan and moved to paper and pen for medication and lab orders. It stayed open but diverted emergency cases. Surgeries and diagnostics continued, except for a few patients whose allergy information could not be accessed. IT had computers running again 36 hours after the attack using cloud backup and disaster-recovery software, but had to replace hard drives (TJC SEA 67, citing Healthcare IT News, Aug. 2017).",
      "layers": [
        "connectivity",
        "handoff"
      ],
      "tier_reached": 2,
      "cascade": false,
      "harm": "none documented",
      "lessons": [
        "A rehearsed plan got the hospital to paper within an hour.",
        "Tested backups set how long you stay at tier 2.",
        "Allergy information was the gap that stopped some procedures, so make sure it is in the downtime snapshot."
      ],
      "source_ids": [
        "tjc-sea-67-cyberattack",
        "wvmetronews-2017-princeton",
        "bdt-2017-princeton-rebuild"
      ],
      "added": "2026-09-26",
      "last_audited": "2026-09-26",
      "audit_status": "verified",
      "kind": "event",
      "failure_type": "unavailable",
      "tier_basis": "EHR and email down; paper and pen for medication and lab orders for about 36 hours."
    },
    {
      "id": "magellan-leadcare-2013",
      "title": "LeadCare blood lead analyzers return falsely low results; malfunction concealed",
      "date": "2013-06",
      "location": "United States",
      "summary": "Magellan's LeadCare devices, used for more than half of US blood lead tests 2013-2017, gave falsely low results on venous samples; the company delayed telling FDA for 21 months.",
      "what_happened": "Magellan Diagnostics learned during FDA clearance in June 2013 that LeadCare Ultra could give falsely low lead results, released it in late 2013 without informing customers or FDA, and reported to FDA only in April 2015; it disclosed the LeadCare II malfunction in November 2016 and changed user instructions without FDA approval. Tens of thousands of children and adults received inaccurate results. In June 2024 the company pleaded guilty to criminal FD&C Act charges, with a $28.1 million fine, $10.9 million forfeiture and at least $9.3 million for victim compensation.",
      "layers": [
        "devices"
      ],
      "tier_reached": 0,
      "cascade": false,
      "harm": "Tens of thousands of patients, many children, received falsely low lead results (DOJ); individual clinical outcomes not quantified.",
      "lessons": [
        "A lab analyzer's wrong number is indistinguishable from a right one without an independent method comparison.",
        "Manufacturer reporting is a control that can fail through concealment; your own proficiency testing and discrepancy tracking is the backstop.",
        "Point-of-care tests that dominate a national testing market concentrate error at population scale."
      ],
      "source_ids": [
        "doj-magellan-leadcare-plea-2024"
      ],
      "added": "2026-09-26",
      "last_audited": "2026-09-26",
      "audit_status": "verified",
      "kind": "event",
      "failure_type": "wrong-output",
      "tier_basis": "The automation stayed up and kept producing output that was wrong or went unchecked; there was no outage to fall back from."
    },
    {
      "id": "sandy-nyu-bellevue-2012",
      "title": "Superstorm Sandy: NYU Langone and Bellevue lose backup power and evacuate",
      "date": "2012-10-29",
      "location": "Manhattan, New York, USA",
      "summary": "Storm surge flooded basements holding fuel tanks and pumps at two Manhattan hospitals whose generators sat on upper floors. Both hospitals evacuated.",
      "what_happened": "NYU Langone's generators were on upper floors, but the surge breached a basement vault holding its fuel system; the hospital evacuated about 300 patients, including 21 neonates moved out of the NICU in 4.5 hours. Bellevue's generators were also high up, but fuel pumps and tanks were in a basement that took an estimated 17 million gallons of water; AP reported more than 700 patients evacuated.\n\nHHS OIG's review of 172 hospitals in the declared area found 69 lost utility power and, for 28 of them, backup generators were not reliable. It describes one hospital (photo credited to NYC Health and Hospitals Corporation) where staff passed fuel up 13 flights of stairs in a 'bucket line' because the pumps were flooded, and where staff decided in advance which machine-dependent patients would keep the few emergency outlets.",
      "layers": [
        "power",
        "cascades",
        "devices",
        "handoff"
      ],
      "tier_reached": 3,
      "cascade": true,
      "harm": "No patient deaths attributed to these evacuations in the sources reviewed. OIG documents patients arriving at receiving hospitals without medical records.",
      "lessons": [
        "A generator is only as flood-proof as its lowest fuel pump, tank or switch.",
        "Evacuating ventilated and neonatal patients without power or elevators takes hours and must be rehearsed.",
        "Records must move with the patient; power loss can make them unreachable.",
        "At tier 3, the exit is often evacuation, so rehearse it.",
        "Records must travel with the patient on paper or portable media when networks are gone.",
        "Regional coordination and transport capacity decide how fast you can move patients."
      ],
      "source_ids": [
        "ap-2012-nyc-hospital-generators",
        "espiritu-2014-pediatrics-nicu-sandy",
        "hhs-oig-2014-sandy"
      ],
      "added": "2026-09-26",
      "last_audited": "2026-09-26",
      "audit_status": "verified",
      "kind": "event",
      "failure_type": "unavailable",
      "tier_basis": "Flooding reached the fuel systems for the backup generators; NYU Langone evacuated about 300 patients and Bellevue more than 700."
    },
    {
      "id": "mgh-monitor-alarm-off-2010",
      "title": "Patient dies while a heart monitor's crisis alarm is switched off",
      "date": "2010-01",
      "location": "Massachusetts General Hospital, Boston, US",
      "summary": "A patient on a cardiac monitor died after the monitor's crisis alarm had been left off; lower-level alarms sounded at the nurses' station but went unheeded.",
      "what_happened": "The Boston Globe reported in February 2010 that a Massachusetts General Hospital patient had died the previous month after the crisis alarm on a GE heart monitor was inadvertently left off, delaying the response of nurses and doctors. Hospital leaders said they did not know why the alarm was off; a nurse found the patient in crisis on a routine check. Within a day the hospital inspected and disabled the off switch on all 1,100 of its heart monitors, and temporarily assigned a nurse on each unit to listen for alarms.\n\nA year later the Globe reported that ten nurses on duty that morning could not recall hearing the lower-level alarms at the central station, or seeing warnings on three hallway signs, as the patient's heart rate fell over about 20 minutes. It quoted state investigators: nursing staff said they were experiencing alarm fatigue and a desensitization to alarms. The investigators did not say why the crisis alarm was off.",
      "layers": [
        "handoff",
        "devices"
      ],
      "kind": "event",
      "failure_type": "human-response",
      "tier_reached": 0,
      "tier_basis": "No loss of automation: the monitor worked, but its crisis alarm was switched off and lower-level alarms went unheeded.",
      "cascade": false,
      "harm": "Death of the patient (Boston Globe).",
      "lessons": [
        "An alarm that can be switched off will sometimes be left off; decide who may silence which alarms, and audit it.",
        "Lower-level alarms that sound constantly stop being heard; alarm volume and priority are a safety design problem, not only a staffing one."
      ],
      "limitation": "Both sources are Boston Globe reports. The state investigators' findings are known here only as the Globe quotes them; no CMS or state inspection record was found online.",
      "source_ids": [
        "globe-2010-mgh-monitor-death",
        "globe-2011-alarms-unheeded"
      ],
      "added": "2026-09-27",
      "last_audited": "2026-09-27",
      "audit_status": "verified"
    },
    {
      "id": "alarm-response-death-massachusetts-2010",
      "title": "ICU patient dies after alarms go unanswered for an hour",
      "date": "2010",
      "location": "Massachusetts, USA (hospital named in the Boston Globe report cited by the Joint Commission)",
      "summary": "A 60-year-old ICU patient's monitor alarmed for rising heart rate and falling oxygen saturation; staff responded only after about an hour, when he had stopped breathing.",
      "what_happened": "The Joint Commission's Sentinel Event Alert 50 describes a case from summer 2010, reported by the Boston Globe: a 60-year-old man admitted to intensive care after a head injury from a falling tree branch. Alarms signalled a rapidly increasing heart rate and falling blood oxygen, but staff responded only after one hour, when a critical alarm indicated that he had stopped breathing. He sustained irreversible anoxic brain injury and was removed from life support several days later. The Joint Commission used the case to illustrate a failure to respond to appropriate alarm signals that it described as occurring every day in many hospitals.",
      "layers": [
        "handoff",
        "devices"
      ],
      "tier_reached": 0,
      "cascade": false,
      "harm": "Death of the patient (per Joint Commission Sentinel Event Alert 50, citing the Boston Globe).",
      "lessons": [
        "A working alarm is not a defense unless a named person hears it and is expected to act.",
        "Alarm fatigue turns a monitored patient into an unmonitored one without anyone deciding it."
      ],
      "source_ids": [
        "tjc-sea-50-alarms-2013"
      ],
      "added": "2026-09-26",
      "last_audited": "2026-09-26",
      "audit_status": "verified",
      "kind": "event",
      "failure_type": "human-response",
      "tier_basis": "No loss of automation is documented.",
      "limitation": "The only source is the Joint Commission's Sentinel Event Alert 50, which does not name the hospital and cites a Boston Globe report we have not located."
    },
    {
      "id": "air-france-447-2009",
      "title": "Air France 447: autopilot hands a stalled aircraft back to a crew (non-clinical analogue)",
      "date": "2009-06-01",
      "location": "Atlantic Ocean, Rio de Janeiro-Paris flight",
      "summary": "Non-clinical analogue. Iced pitot probes caused inconsistent airspeeds, the autopilot disconnected, and the crew did not recognise or recover from a stall.",
      "what_happened": "NON-CLINICAL ANALOGUE. According to the BEA final report (July 2012), obstruction of the Airbus A330's pitot probes by ice crystals caused a temporary inconsistency in measured airspeeds, which disconnected the autopilot and reconfigured the flight controls to alternate law. The crew's control inputs destabilised the flight path, they did not link the loss of airspeed indications to the relevant procedure, and they did not identify the approach to stall or the stall itself; the aircraft, carrying 228 people, struck the surface of the ocean. The BEA cited an absence of high-altitude manual handling training and of training on the speed-anomaly procedure, task-sharing weakened by startle and incomprehension, the lack of a clear cockpit display of the airspeed inconsistencies, and the crew not taking the stall warning into account.",
      "layers": [
        "handoff"
      ],
      "tier_reached": null,
      "cascade": false,
      "harm": "Non-clinical: loss of the aircraft with 228 people on board.",
      "lessons": [
        "The handback arrives at the worst moment, with the least context, to the people who have practised it least.",
        "If the machine knows its inputs disagree, it must show that plainly at handback.",
        "Manual skills for rare failures must be rehearsed in realistic conditions, not assumed."
      ],
      "source_ids": [
        "bea-af447-final-report-2012",
        "bea-af447-summary-2012"
      ],
      "added": "2026-09-26",
      "last_audited": "2026-09-26",
      "audit_status": "verified",
      "kind": "analogue",
      "failure_type": "unavailable"
    },
    {
      "id": "katrina-memorial-2005",
      "title": "Hurricane Katrina: Memorial Medical Center loses all power",
      "date": "2005-08-29",
      "location": "New Orleans, Louisiana, USA",
      "summary": "After city power failed, Memorial ran on generators that failed as floodwater rose. 45 bodies were later recovered from the hospital.",
      "what_happened": "About 2,000 people sheltered at Memorial, including more than 200 patients; a separate long-term acute care hospital, LifeCare, had 52 patients on the seventh floor, many on ventilators. City power failed early on Monday 29 August. Staff had warned before the storm that the electrical system was vulnerable to flooding. The backup generators failed on Wednesday 31 August (early that day in Sheri Fink's account, around midday in a 2006 Urban Institute study), leaving the hospital without power while evacuation was still incomplete.\n\nSheri Fink's reporting documents the triage and end-of-life decisions made in that heat and darkness. Mortuary workers removed 45 bodies from Memorial.",
      "layers": [
        "power",
        "handoff",
        "cascades"
      ],
      "tier_reached": 3,
      "cascade": true,
      "harm": "45 bodies recovered from the hospital (Fink/ProPublica; the Urban Institute study also reports 45, and notes that Memorial's owner Tenet said 11 of the patients had died before the storm). How many deaths the power loss caused is not established in the sources reviewed.",
      "lessons": [
        "A known flood vulnerability in the electrical system is a known evacuation trigger.",
        "Loss of power also means loss of cooling, ventilators and communication at the same time.",
        "Co-located tenant hospitals need a shared power and evacuation plan."
      ],
      "source_ids": [
        "fink-2009-propublica-memorial",
        "urban-2006-hospitals-katrina",
        "house-2006-failure-of-initiative-medical"
      ],
      "added": "2026-09-26",
      "last_audited": "2026-09-26",
      "audit_status": "verified",
      "kind": "event",
      "failure_type": "unavailable",
      "tier_basis": "City power failed on 29 August and the backup generators failed early on 31 August, while evacuation was still incomplete."
    },
    {
      "id": "northeast-blackout-2003",
      "title": "Northeast blackout: New York City hospital generators fail",
      "date": "2003-08-14",
      "location": "New York City, USA",
      "summary": "During the 2003 blackout multiple NYC hospital emergency generators failed. The outage was associated with about 90 excess deaths citywide.",
      "what_happened": "The NYC health department's account lists failure of multiple hospital emergency generators, risk to patients dependent on powered equipment, and loss of ED data feeds to syndromic surveillance among the blackout's public health effects. A later time-series study estimated about 90 excess deaths in New York City, with accidental deaths up 122% and disease-related deaths up 25%.",
      "layers": [
        "power",
        "cascades"
      ],
      "tier_reached": 3,
      "cascade": true,
      "harm": "About 90 excess deaths citywide (Anderson & Bell 2012); deaths inside hospitals attributable to generator failures not documented in the sources reviewed.",
      "lessons": [
        "Generators that pass routine tests can still fail on a real, sustained demand.",
        "Surveillance data feeds are part of the power-dependent stack."
      ],
      "source_ids": [
        "beatty-2006-phr-blackout-2003",
        "anderson-bell-2012-epi-blackout"
      ],
      "added": "2026-09-26",
      "last_audited": "2026-09-26",
      "audit_status": "verified",
      "kind": "event",
      "failure_type": "unavailable",
      "tier_basis": "The NYC health department lists failures of multiple hospital emergency generators."
    },
    {
      "id": "bidmc-network-2002",
      "title": "Beth Israel Deaconess network collapse",
      "date": "2002-11-13",
      "location": "Boston, Massachusetts, United States",
      "summary": "A network loop took down clinical applications at an academic medical centre for about four days, forcing a return to paper it had abandoned years earlier.",
      "what_happened": "On 13 November 2002, a spanning-tree loop in the core network at Beth Israel Deaconess Medical Center brought down email, lab results, PACS images and order entry. The network failed repeatedly over about four days. Staff reverted to handwritten orders and prescriptions and used photocopiers and runners to distribute reports. Lab turnaround went from under 45 minutes to as long as five hours. The emergency department closed to new patients for four hours. Cisco engineers flew in equipment, and the PACS network was rebuilt overnight (Berinato 2003). The event was discussed in an NEJM Perspective (Kilbridge 2003), and ONC's SAFER Contingency Planning guide cites it.",
      "layers": [
        "connectivity",
        "handoff",
        "cascades"
      ],
      "tier_reached": 2,
      "cascade": true,
      "harm": "None documented in the source reviewed.",
      "lessons": [
        "Network architecture is clinical infrastructure: a flat Layer-2 design is a single failure domain.",
        "Disaster recovery that protects data but not the network leaves every application unreachable.",
        "A single network fault can drop every clinical application at once, so plan downtime for the whole enterprise, not one system at a time.",
        "Staff who have not used paper for years need practice, forms and runners ready in advance.",
        "Treat network infrastructure as a managed clinical utility, with change control and current diagrams."
      ],
      "source_ids": [
        "cio-2003-bidmc-network",
        "berinato-2003-cio-all-systems-down",
        "kilbridge-2003-nejm-computer-crash",
        "onc-safer-contingency-2025"
      ],
      "added": "2026-09-26",
      "last_audited": "2026-09-26",
      "audit_status": "verified",
      "kind": "event",
      "failure_type": "unavailable",
      "tier_basis": "The network failed repeatedly for about four days; handwritten orders, photocopies and runners. Loss of phones is not documented."
    }
  ]
}
