From Health 201FailSystems

how automated healthcare fails, how you'd know, and what to do at each tier — every claim sourced, reviewed continuously


Incident

Princeton Community Hospital Petya ransomware

Ransomware made the EHR inaccessible; the hospital moved to paper within an hour and restored computers after 36 hours.

Sources checked when written 26 September 2026

TierEHR and email down; paper and pen for medication and lab orders for about 36 hours. How tiers are assigned.

What happened

As recounted by the Joint Commission, staff arrived to find Petya ransomware notices. The EHR was inaccessible and email was down. Within an hour, the hospital activated its incident response plan and moved to paper and pen for medication and lab orders. It stayed open but diverted emergency cases. Surgeries and diagnostics continued, except for a few patients whose allergy information could not be accessed. IT had computers running again 36 hours after the attack using cloud backup and disaster-recovery software, but had to replace hard drives (TJC SEA 67, citing Healthcare IT News, Aug. 2017).[1,2,3]

Documented harm

none documented

What it teaches

Sources

  1. Sentinel Event Alert Issue 67: Preserving patient safety after a cyberattack. The Joint Commission, 15 August 2023. Primary Guidance · link checked 2026-09-26
  2. Princeton hospital to replace 12-hundred computer hard drives after cyber attack. WV MetroNews (Carrie Hodousek), 30 June 2017. Secondary Journalism · link checked 2026-09-27
  3. Cyber attack prompts Princeton Community Hospital to rebuild network. Bluefield Daily Telegraph (Blake Stowers), 29 June 2017. Secondary Journalism · link checked 2026-09-27

All incidents · Connectivity & data · Human handoff

Information only, not advice. FailSystems is an aggregation and synthesis of published sources. It is not consulting, engineering, legal, regulatory or medical advice, and using it creates no professional relationship. Health systems are complex and no approach fits every organisation: anything you adopt is your own decision, at your own risk, and should be checked against the current official sources and by qualified people who know your setting. Full disclaimer.

Dealing with an incident right now? This site is a reference, not an incident-response service. Activate your organisation's emergency operations plan and incident command, and: