From Health 201FailSystems

how automated healthcare fails, how you'd know, and what to do at each tier — every claim sourced, reviewed continuously


Incident

WannaCry ransomware across the NHS in England

A self-spreading ransomware worm infected 34 English trusts and 603 primary-care and other NHS organisations, and at least 46 more trusts were disrupted. Thousands of appointments were cancelled and five hospitals diverted ambulances.

PathConnectivity & data → Devices → Human handoff

Sources checked when written 26 September 2026

TierInfected trusts were locked out of devices and systems and used pen and paper; five diverted ambulances. Loss of power or phones is not documented. How tiers are assigned.

What happened

The National Audit Office found that at least 80 of 236 trusts in England were affected: 34 infected and locked out of devices (25 of them acute trusts) and 46 not infected but disrupted. Many of the 46 shut down email and other systems as a precaution because central advice did not reach them early enough, and had to use pen and paper. A further 603 primary-care and other NHS organisations were infected, including 595 GP practices. Five acute trusts diverted emergency ambulances to other hospitals. NHS England counted 6,912 cancelled appointments and estimated about 19,000 in total. All infected organisations had unpatched or unsupported Windows systems, and before the attack none of the 88 trusts NHS Digital had assessed had passed its cyber-security assessment. Ghafur et al. (npj Digital Medicine, 2019) analysed hospital episode data. Infected hospitals had about 6% fewer admissions per day during the attack week (4% fewer emergency and 9% fewer elective). The lost activity was valued at £5.9m. No measurable change in A&E deaths was found.[1,2,3]

Documented harm

NHS organisations reported no cases of patient harm (NAO). Ghafur et al. found no significant change in deaths in A&E but fewer admissions at infected hospitals. Harm from delayed care was not measured.

What it teaches

Sources

  1. Investigation: WannaCry cyber attack and the NHS. National Audit Office (UK), 27 October 2017. Primary Official report · link checked 2026-09-26
  2. Lessons learned review of the WannaCry Ransomware Cyber Attack. Department of Health and Social Care / NHS England (William Smart, CIO for Health and Social Care), 1 February 2018. Primary Official report · link checked 2026-09-26
  3. A retrospective impact analysis of the WannaCry cyberattack on the NHS. npj Digital Medicine, 2 October 2019. Primary Peer-reviewed · link checked 2026-09-26

All incidents · Connectivity & data · Devices · Cascades · Human handoff

Information only, not advice. FailSystems is an aggregation and synthesis of published sources. It is not consulting, engineering, legal, regulatory or medical advice, and using it creates no professional relationship. Health systems are complex and no approach fits every organisation: anything you adopt is your own decision, at your own risk, and should be checked against the current official sources and by qualified people who know your setting. Full disclaimer.

Dealing with an incident right now? This site is a reference, not an incident-response service. Activate your organisation's emergency operations plan and incident command, and: