From Health 201FailSystems

how automated healthcare fails, how you'd know, and what to do at each tier — every claim sourced, reviewed continuously


Incident

CrowdStrike Falcon content update crashes Windows hosts, including hospital systems

A faulty Rapid Response Content update to CrowdStrike's Falcon sensor crashed about 8.5 million Windows devices worldwide. Outside-in measurement found disrupted services at 759 of 2,232 US hospitals studied.

PathDevices → Connectivity & data → Human handoff

Sources checked when written 26 September 2026

TierAt Mass General Brigham, on-site staff went to downtime procedures and handwritten notes, according to Healthcare Brew; a scan of US hospitals found patient-facing services offline at many sites. How tiers are assigned.

What happened

CrowdStrike's root cause analysis says a new IPC Template Type defined 21 input fields, but the sensor code that called it supplied only 20. Testing and early deployments used wildcard matching for the 21st field, so the mismatch stayed latent. On 19 July 2024 a new Channel File 291 used a non-wildcard criterion for the 21st field. That triggered an out-of-bounds memory read, and Windows hosts that received it crashed. CrowdStrike's remediations include bounds checks, more testing, staged deployment through rings, and customer control over content rollout. Microsoft estimated 8.5 million Windows devices were affected, under 1% of the total, and noted that the damage was outsized because enterprises running critical services use CrowdStrike. CISA confirmed it was not a cyberattack but warned of phishing that took advantage of the outage. Tully et al. (JAMA Network Open, 2025) scanned hospital IP space and Epic FHIR endpoints from outside. Of 2,232 US hospitals, 759 (34.0%) had detectable disruptions. Of 1,098 disrupted services, 239 (21.8%) were patient-facing. Most services came back within 6 hours, but 43 were down for more than 48 hours. The authors note that network measurement is only a surrogate for clinical impact.[1,2,3,4,5,6,7]

Documented harm

None documented at the patient level. Tully et al. could not confirm patient outcomes. 239 patient-facing services were disrupted at US hospitals.

What it teaches

Sources

  1. External Technical Root Cause Analysis - Channel File 291. CrowdStrike, 6 August 2024. Supporting Official report · link checked 2026-09-26
  2. Testimony of Adam Meyers, CrowdStrike, before the House Homeland Security Subcommittee on Cybersecurity and Infrastructure Protection: 'An Outage Strikes'. U.S. House Committee on Homeland Security, 24 September 2024. Primary Testimony / filing · link checked 2026-09-26
  3. Microsoft global outage forces hospitals to cancel appointments. STAT (Palmer K, Trang B, Ross C), 19 July 2024. Secondary Journalism · link checked 2026-09-26
  4. Patient Care Technology Disruptions Associated With the CrowdStrike Outage. JAMA Network Open (Tully JL, ... Dameff CJ), 1 July 2025. Primary Peer-reviewed · link checked 2026-09-26
  5. Helping our customers through the CrowdStrike outage. Microsoft (David Weston), 20 July 2024. Supporting Official report · link checked 2026-09-26
  6. Widespread IT Outage Due to CrowdStrike Update. CISA, 19 July 2024. Primary Guidance · link checked 2026-09-26
  7. A look at how Mass General Brigham recovered from the CrowdStrike outage. Healthcare Brew (Cassie McGrath), 11 September 2024. Secondary Journalism · link checked 2026-09-27

All incidents · Devices · Connectivity & data · Cascades · Human handoff

Information only, not advice. FailSystems is an aggregation and synthesis of published sources. It is not consulting, engineering, legal, regulatory or medical advice, and using it creates no professional relationship. Health systems are complex and no approach fits every organisation: anything you adopt is your own decision, at your own risk, and should be checked against the current official sources and by qualified people who know your setting. Full disclaimer.

Dealing with an incident right now? This site is a reference, not an incident-response service. Activate your organisation's emergency operations plan and incident command, and: