From Health 201FailSystems

how automated healthcare fails, how you'd know, and what to do at each tier — every claim sourced, reviewed continuously


Incident

Ransomware spillover to adjacent San Diego emergency departments

A month-long ransomware attack on a health system with about 25% of regional inpatient discharges drove patients and ambulances to two unaffected academic EDs, raising their census, waits and stroke activations.

PathConnectivity & data → Human handoff

Sources checked when written 26 September 2026

TierThe study reports, citing local media, that the attacked system lost its electronic health records, imaging and telemedicine systems and reverted to paper records for about four weeks. The neighbouring EDs stayed at tier 0 under load. How tiers are assigned.

What happened

Dameff et al. (JAMA Network Open, 2023) compared two urban academic emergency departments that were not attacked, before, during and after a ransomware attack (1–28 May 2021) on a neighbouring health system with about 25% of San Diego County's inpatient discharges. During the attack phase the unaffected EDs saw a 15.1% rise in daily census, 35.2% more ambulance arrivals, a 127.8% rise in patients leaving without being seen, and a 47.6% rise in median waiting-room time. Confirmed strokes rose from 22 to 47, and county-wide EMS diversion hours also rose. The study is the clearest evidence that a cyberattack on one organisation becomes a capacity and time-critical-care problem for its neighbours.[1,2]

Documented harm

Adverse outcomes at the attacked system are not documented in the source reviewed. At adjacent EDs, delays (longer waits and length of stay, more patients leaving without being seen) and higher stroke volumes were documented.

What it teaches

Sources

  1. Ransomware Attack Associated With Disruptions at Adjacent Emergency Departments in the US. JAMA Network Open (Dameff C, Tully J, Chan TC, et al.), 8 May 2023. Primary Peer-reviewed · link checked 2026-09-26
  2. Sentinel Event Alert Issue 67: Preserving patient safety after a cyberattack. The Joint Commission, 15 August 2023. Primary Guidance · link checked 2026-09-26

All incidents · Connectivity & data · Human handoff · Cascades

Information only, not advice. FailSystems is an aggregation and synthesis of published sources. It is not consulting, engineering, legal, regulatory or medical advice, and using it creates no professional relationship. Health systems are complex and no approach fits every organisation: anything you adopt is your own decision, at your own risk, and should be checked against the current official sources and by qualified people who know your setting. Full disclaimer.

Dealing with an incident right now? This site is a reference, not an incident-response service. Activate your organisation's emergency operations plan and incident command, and: