From Health 201FailSystems

how automated healthcare fails, how you'd know, and what to do at each tier — every claim sourced, reviewed continuously


Layer 2 of 5

Connectivity & data

The networks, interfaces, vendors and records that carry clinical data, and what happens when data is missing, late or wrong.

Reviewed 26 September 2026Sources checked when written 26 September 2026 Involved in 15 of 39 incidents70 sources (65 primary or secondary)

What this layer is

This layer is everything between a clinician's question and the data that answers it: local networks and internet circuits, the EHR and its interfaces to lab, pharmacy and imaging, and the outside services a hospital depends on, such as claims clearinghouses and outsourced pathology. It also covers the data itself: whether it is present, current and correct.

It fails in two different ways. Data can be unavailable: a ransomware attack, a network loop or a vendor outage takes systems down, and staff know they are blind. Or data can be wrong: an order silently goes to a queue no one reads, a downtime copy is hours old, or results entered on paper never make it back. Unavailable data is loud and prompts a switch to backup processes; wrong data is quiet and does not.

Unplanned downtime is common. In one survey, 96% of large US health systems had at least one in three years, and 70% had one longer than 8 hours. Ransomware has made multi-week outages routine: about 44% of ransomware attacks on US care delivery organizations from 2016 to 2021 disrupted care, and in-hospital mortality rises among patients already admitted when an attack begins.

FailSystems viewFailSystems' view: in a paper hospital, losing one department's records was a local problem. In an automated hospital, one identity system, one network core or one shared vendor carries every department's data, so failure is correlated and the backup is a mode of work nobody practises. We think the key distinction is 'unavailable' versus 'wrong'. Most planning targets the first: backups, warm sites, paper forms. The second defeats those plans because nothing tells anyone to use them. Defences against wrong data are reconciliation and monitoring (queues with owners, counts that must match, synthetic transactions), not redundancy.

How it fails

Enterprise ransomware and precautionary shutdown

Attackers encrypt servers and endpoints, often after days of undetected access and data theft. The organization then disconnects everything it cannot yet trust, so the EHR, lab, imaging, pharmacy and communications go dark together. Recovery is a rebuild, not a restart, and takes weeks.[1,2,3,4]

Warning signs

Seen inAscension ransomware and multi-week EHR downtime, Universal Health Services enterprise-wide IT shutdown, WannaCry ransomware across the NHS in England

Third-party clearinghouse or lab outage

A vendor that many organizations share (claims clearinghouse, pharmacy switch, outsourced pathology) is attacked or fails. Hospitals whose own systems are intact lose a function they cannot perform themselves, and every customer fails at once.[5,6,7,8]

Warning signs

Seen inChange Healthcare ransomware and national claims/pharmacy clearinghouse outage, Synnovis pathology ransomware, South-East London

Downtime procedures that decay over days and weeks

The Joint Commission advises hospitals to be prepared to run with life- and safety-critical technology offline for four weeks or longer. Over days, order routing between departments, patient identification and result communication break down; lab turnaround slows and medication checks lapse. Back-entry after recovery creates a second risk period.[9,10,11,12,13]

Warning signs

Seen inAscension ransomware and multi-week EHR downtime, Synnovis pathology ransomware, South-East London

Network partition or infrastructure collapse

A loop, misconfiguration, carrier cut or failed core switch makes applications unreachable although servers and data are intact. Intermittent 'flapping' is worse than a clean outage because staff cannot tell whether to switch to paper.[14,15]

Warning signs

Seen inBeth Israel Deaconess network collapse

Silent data loss or misrouting (data wrong, not absent)

Orders, results or messages are accepted by one system and never reach the next, or land in a queue no one watches. The sender sees success, so no one switches to a backup process. Harm emerges as missed follow-up weeks later.[16,15,17]

Warning signs

Seen inVA Oracle Cerner EHR 'unknown queue' silently dropped clinical orders

Stale or incomplete record during and after downtime

Read-only downtime copies are snapshots and age from the moment the outage begins. After restoration, data captured on paper is back-entered late or not at all, and results produced during the outage may be absent from the electronic record. Clinicians decide on data that looks current but is not.[15,10,18]

Warning signs

Seen inAscension ransomware and multi-week EHR downtime

Backups destroyed or unusable when needed

Attackers target backup systems before encrypting, or backups turn out never to have been restored end to end. The organization then has no clean copy to restore from and must rebuild, or pay.[2,15,3]

Warning signs

Seen inChange Healthcare ransomware and national claims/pharmacy clearinghouse outage

Regional spillover to neighbouring hospitals

When a system diverts ambulances and time-critical patients, nearby EDs absorb the load without extra staff. Waits, walk-outs and time-critical cases rise at hospitals that were never attacked; rural patients face much longer travel.[19,20,21]

Warning signs

Seen inWannaCry ransomware across the NHS in England, Universal Health Services enterprise-wide IT shutdown

Cloud-region or provider control-plane failure

A fault inside the provider (DNS automation, internal network congestion) disables core services across a region while the hospital's own building is fine. Impact depends on how each customer and each supplier built on the region: in October 2025 one Epic-on-AWS system slowed and another saw nothing, while NHS trusts using Oracle services went to paper.[22,23,24,25]

Warning signs

Seen inAWS us-east-1 DynamoDB DNS failure disrupts cloud-hosted clinical systems

Incidents

AWS us-east-1 DynamoDB DNS failure disrupts cloud-hosted clinical systems

A race condition in DynamoDB's DNS automation broke a core AWS region for about 15 hours. Some cloud-hosted EHR users slowed or went to paper; others saw nothing.[22,24,25]

Iberian Peninsula blackout

A grid collapse cut power to continental Spain and Portugal for about ten hours. Hospitals largely held on generators; care outside them did not.[26,27,28,29,30]

Alaris infusion interoperability backlog can load outdated pump orders

A Class I software correction found that backlogged EHR-to-pump automated programming requests could load stale rate, dose or volume parameters.[31,32]

Contec CMS8000 patient monitors: hidden remote-access function disclosed by CISA and FDA

CISA and FDA reported that a low-cost patient monitor's firmware contained hidden functionality that could allow remote access and sent patient data to an external address; independent researchers later judged it an insecure design rather than an intentional backdoor.[33,34,35,36]

CrowdStrike Falcon content update crashes Windows hosts, including hospital systems

A faulty Rapid Response Content update to CrowdStrike's Falcon sensor crashed about 8.5 million Windows devices worldwide. Outside-in measurement found disrupted services at 759 of 2,232 US hospitals studied.[37,38,39,40,41,42,43]

PathDevices → Connectivity & data → Human handoff

Synnovis pathology ransomware, South-East London

Ransomware hit Synnovis, the pathology provider for several south-east London NHS trusts and GP practices. Blood testing and matching collapsed, more than 11,000 appointments and procedures were postponed, O-type blood ran short nationally, and one death was later partly attributed to a delayed result.[8,44,45,46,47,48,49,50]

PathConnectivity & data → Human handoff

Ascension ransomware and multi-week EHR downtime

A ransomware attack took Ascension's electronic records offline for about five weeks. Clinicians told KFF Health News of medication errors and delayed lab results, and one said he had no training for the attack; Ascension said its care teams were trained for such disruptions.[12,18]

Change Healthcare ransomware and national claims/pharmacy clearinghouse outage

Attackers used stolen credentials on a Change Healthcare Citrix remote-access portal that had no multi-factor authentication, then deployed ransomware nine days later. Disconnecting the clearinghouse stalled pharmacy claims, medical claims and payments across the US.[5,51,6,52,53]

PathConnectivity & data → Human handoff

Guy's and St Thomas': heatwave cooling failure takes down both data centres

Air conditioning tripped at both trust data centres on the UK's record-heat day. Clinical IT went down and the trust ran on paper for weeks.[54,55]

Ransomware spillover to adjacent San Diego emergency departments

A month-long ransomware attack on a health system with about 25% of regional inpatient discharges drove patients and ambulances to two unaffected academic EDs, raising their census, waits and stroke activations.[19,13]

PathConnectivity & data → Human handoff

VA Oracle Cerner EHR 'unknown queue' silently dropped clinical orders

After go-live, the new EHR routed more than 11,000 clinical orders to a hidden queue instead of the intended service, without telling the ordering clinician; VHA identified 149 adverse events.[16]

Universal Health Services enterprise-wide IT shutdown

A security incident led UHS to suspend user access to IT applications across its US operations; facilities ran on offline documentation for up to several weeks.[56,57]

WannaCry ransomware across the NHS in England

A self-spreading ransomware worm infected 34 English trusts and 603 primary-care and other NHS organisations, and at least 46 more trusts were disrupted. Thousands of appointments were cancelled and five hospitals diverted ambulances.[58,21,59]

PathConnectivity & data → Devices → Human handoff

Princeton Community Hospital Petya ransomware

Ransomware made the EHR inaccessible; the hospital moved to paper within an hour and restored computers after 36 hours.[13,60,61]

Beth Israel Deaconess network collapse

A network loop took down clinical applications at an academic medical centre for about four days, forcing a return to paper it had abandoned years earlier.[14,62,63,15]

How you'd know

What to do, tier by tier

What should already be in place at each degradation tier for this layer. Tier 0 is normal automated running; tier 3 is paper, batteries and judgement.

These are practices reported or recommended in the cited sources, gathered for reference. They are not a prescription for your organisation; judge what fits your setting, and check the current official text of any standard.

0Full automation

  • Put phishing-resistant MFA on every remote-access portal, VPN and privileged account, starting with vendor access.[3,5,7]
  • Patch known exploited vulnerabilities promptly and retire unsupported operating systems, including those embedded in diagnostic devices.[3,58,21]
  • Keep a daily, encrypted, off-site backup separated from normal storage (air gap); keep several generations; back up system configuration monthly and before every upgrade.[15,2]
  • Build redundant network paths: two internet circuits in different trenches or from different providers, and a routed (not flat Layer-2) core.[15,14]
  • Inventory every third party that performs a clinical or revenue function you cannot do yourself; write incident-notification and recovery terms into the contract.[7,6]
  • Complete all nine SAFER Guides every year as a working review, not a yes/no box; CMS accepts 'no' as an answer, so the attestation alone proves nothing.[65,15]

1Assisted operation

  • Maintain a warm site that can run the whole EHR within 8 hours, more than 50 miles away, and fail over to it at least quarterly.[15]
  • Segment the network so a compromised zone can be isolated without disconnecting everything; plan in advance which segments stay up.[7,2,21]
  • Contract and test an alternate clearinghouse or claims submission route, and an alternate reference lab, before an outage.[6,5]
  • Write and test restoration procedures that bring critical systems and data back within 72 hours, ranked by clinical criticality. The proposed HIPAA Security Rule would require this; do not wait for the final rule.[53,66]
  • Size interface buffers so data queued during an outage is not lost, and alert users in the EHR when a clinical interface is down.[15]

2Manual operation

  • Run a read-only backup EHR refreshed at least hourly, tested weekly, printable, and on UPS or generator power at unit level; make sure staff can log in to it.[15]
  • Keep downtime communication independent of the EHR network (not email, websites or VoIP on the same infrastructure).[15,13]
  • Call downtime early: activate the warm site or downtime procedures before 2 hours of unplanned outage, not after.[15]
  • Double-check high-risk medications manually when barcode scanning is unavailable, and use positive patient identification procedures designed for downtime.[15,9,12]

3Analog fallback

  • Stock current paper forms for orders, medication administration, lab requisitions and results on every unit; keep a paper copy of the downtime policy on units and off-site.[15,67]
  • Run unannounced downtime drills at least yearly, and at least one exercise that assumes weeks, not hours, without the EHR, lab interface or clearinghouse.[15,13,12]
  • Assign a runner or courier system for orders and results between departments; paper without a routing method stalls.[12,10]
  • Agree regional diversion and mutual-aid plans with neighbouring hospitals and EMS for cyber incidents, not only physical disasters.[19,21]
  • Plan recovery as its own phase: assign owners to back-enter and reconcile paper data, restart interfaces in order, and review harm from delays.[15,13,8]

Standards and rules (US)

InstrumentWhat it requires
HIPAA Security Rule, 45 CFR 164.308(a)(7) Contingency planCovered entities must have a data backup plan, a disaster recovery plan and an emergency-mode operation plan; testing/revision and an applications-and-data criticality analysis are 'addressable'. A January 2025 NPRM would add written procedures to restore critical systems and data within 72 hours, but it was not final as of September 2026.[66]
CMS Hospital CoP Emergency preparedness, 42 CFR 482.15Hospitals must maintain a system of medical documentation that preserves patient information and keeps records available in an emergency, with the emergency plan and training/testing program reviewed at least every 2 years.[67]
ONC/ASTP SAFER Guide: Contingency Planning (2025 edition)Self-assessment of 13 practices covering disaster recovery, generators, paper forms, tested backups, downtime training, independent communication, interface restart and downtime monitoring. CMS requires hospitals in the Medicare Promoting Interoperability Program to attest annually (yes or no) to completing all nine SAFER Guides.[15]
HHS 405(d) Health Industry Cybersecurity Practices (HICP), 2023 editionVoluntary, sector-specific: ten practices against five threats including ransomware, scaled for small and large organizations in two technical volumes.[2]
HHS HPH Cybersecurity Performance Goals (CPGs)Voluntary essential goals (e.g., MFA, incident planning, vendor cybersecurity requirements) and enhanced goals (e.g., network segmentation, third-party incident reporting, drilled incident plans).[7]
The Joint Commission Sentinel Event Alert 67 (2023)Not a standard itself; recommends downtime planning committees, response teams, staff training and communication for extended cyber downtime, and points to TJC continuity-of-operations and disaster-recovery requirements.[13]

Elsewhere: EU and UK

In the EU the NIS2 Directive (2022/2555) keeps healthcare within its scope and imposes cybersecurity risk-management and incident-notification duties; ENISA's 2023 health threat landscape found ransomware in 54% of 215 reported health-sector incidents and a dedicated ransomware programme in only 27% of surveyed organisations. In England, DHSC's 2023-2030 cyber strategy aims for all health and social care organisations, including critical suppliers, to be cyber resilient by 2030. WannaCry (2017) and Synnovis (2024) are the reference cases: the first showed how unpatched systems and precautionary disconnection spread disruption, the second how a single pathology supplier can halt a region's diagnostics for months.[68,69,70,58,8]

Severity score v0.1 draft

5Likelihood
5Blast radius
3Detectability (5 = hardest)
75of 125

FailSystems judgementJudgement: likelihood is 5 because unplanned EHR downtime is near-universal and ransomware attacks on care delivery roughly doubled between 2016 and 2021. Blast radius is 5 because shared vendors (Change Healthcare, Synnovis) and precautionary shutdowns take down whole regions or national functions at once. Detectability averages two extremes: outright outages are obvious (about 1), but silent misrouting and stale data can go unnoticed for months (about 5).

Each factor is scored 1–5 and multiplied, as in a classic FMEA risk priority number. This is our first-draft judgement, not a measurement; see how scoring works and how it will be revised.

What we don't know yet

These gaps drive what the nightly research pass looks for. If you have evidence, send it.

Sources cited on this page

  1. Health Industry Cybersecurity Practices: Managing Threats and Protecting Patients (HICP), 2023 Edition. HHS 405(d) Program / Health Sector Coordinating Council, 2023. Primary Guidance · link checked 2026-09-26
  2. #StopRansomware: Black Basta (AA24-131A). CISA, FBI, HHS, MS-ISAC, 10 May 2024. Primary Guidance · link checked 2026-09-26
  3. Hacked to Pieces? The Effects of Ransomware Attacks on Hospitals and Patients. American Economic Journal: Economic Policy 18(1):256-81 (Neprash H, McGlave C, Nikpay S), February 2026. Primary Peer-reviewed · link checked 2026-09-26
  4. Testimony of Andrew Witty, CEO, UnitedHealth Group, before the Senate Finance Committee: 'Hacking America's Health Care: Assessing the Change Healthcare Cyber Attack and What's Next'. US Senate Committee on Finance, 1 May 2024. Primary Testimony / filing · link checked 2026-09-26
  5. Change Healthcare Cyberattack Underscores Urgent Need to Strengthen Cyber Preparedness for Individual Health Care Organizations and as a Field. American Hospital Association, 2025. Secondary Official report · link checked 2026-09-26
  6. Healthcare and Public Health (HPH) Sector Cybersecurity Performance Goals. HHS (with CISA), 2024. Primary Guidance · link checked 2026-09-26
  7. Synnovis cyber incident (update of 10 November 2025). NHS England, 10 November 2025. Primary Official report · link checked 2026-09-26
  8. Implications of electronic health record downtime: an analysis of patient safety event reports. Journal of the American Medical Informatics Association 25(2):187 (Larsen E, Fong A, Wernz C, Ratwani RM), February 2018. Primary Peer-reviewed · link checked 2026-09-26
  9. Continuing Patient Care during Electronic Health Record Downtime. Applied Clinical Informatics (Larsen E, Hoffman D, Rivera C, Kleiner BM, Wernz C, Ratwani RM), May 2019. Primary Peer-reviewed · link checked 2026-09-26
  10. Contingency planning for electronic health record-based care continuity: a survey of recommended practices. International Journal of Medical Informatics 83(11):797-804 (Sittig DF, Gonzalez D, Singh H), 2014. Primary Peer-reviewed · link checked 2026-09-26
  11. Cyberattack led to harrowing lapses at Ascension hospitals, clinicians say. KFF Health News (Rachana Pradhan) and Michigan Public (Kate Wells); co-published by NPR, 20 June 2024. Secondary Journalism · link checked 2026-09-26
  12. Sentinel Event Alert Issue 67: Preserving patient safety after a cyberattack. The Joint Commission, 15 August 2023. Primary Guidance · link checked 2026-09-26
  13. Halamka on Beth Israel's Health-Care IT Disaster. CIO Magazine (Scott Berinato), 15 February 2003. Secondary Journalism · link checked 2026-09-26
  14. SAFER Guide: Contingency Planning (2025 edition). ASTP/ONC, US Department of Health and Human Services, 2025. Primary Guidance · link checked 2026-09-26
  15. The New Electronic Health Record's Unknown Queue Caused Multiple Events of Patient Harm (Report 22-01137-204). VA Office of Inspector General, 14 July 2022. Primary Official report · link checked 2026-09-26
  16. Problems with health information technology and their effects on care delivery and patient outcomes: a systematic review. Journal of the American Medical Informatics Association 24(2):246-250 (Kim MO, Coiera E, Magrabi F), March 2017. Primary Peer-reviewed · link checked 2026-09-26
  17. The state-by-state impact of Ascension's cyberattack. Healthcare Dive, 2024. Secondary Journalism · link checked 2026-09-26
  18. Ransomware Attack Associated With Disruptions at Adjacent Emergency Departments in the US. JAMA Network Open (Dameff C, Tully J, Chan TC, et al.), 8 May 2023. Primary Peer-reviewed · link checked 2026-09-26
  19. What happens to rural hospitals during a ransomware attack? Evidence from Medicare data. Journal of Rural Health (Neprash HT, McGlave CC, Rydberg K, Henning-Smith C), 17 March 2024. Primary Peer-reviewed · link checked 2026-09-26
  20. Lessons learned review of the WannaCry Ransomware Cyber Attack. Department of Health and Social Care / NHS England (William Smart, CIO for Health and Social Care), 1 February 2018. Primary Official report · link checked 2026-09-26
  21. Summary of the Amazon DynamoDB Service Disruption in the Northern Virginia (US-EAST-1) Region. Amazon Web Services, October 2025. Primary Official report · link checked 2026-09-26
  22. Summary of the AWS Service Event in the Northern Virginia (US-EAST-1) Region. Amazon Web Services, December 2021. Primary Official report · link checked 2026-09-26
  23. AWS outage disrupts Tufts Medicine; other health systems unaffected. Becker's Hospital Review (Naomi Diaz), 21 October 2025. Secondary Journalism · link checked 2026-09-26
  24. AWS outage causes disruption to patient care across NHS sites. Digital Health News (Jordan Sollof), 21 October 2025. Secondary Journalism · link checked 2026-09-26
  25. Final Report on the Grid Incident in Spain and Portugal on 28 April 2025. ENTSO-E Expert Panel, 20 March 2026. Primary Official report · link checked 2026-09-26
  26. La resaca en los hospitales tras salvar el apagón: 'Más allá de cierto caos, hemos sobrevivido bastante bien'. elDiario.es (Sofía Pérez Mendoza), 29 April 2025. Secondary Journalism · link checked 2026-09-26
  27. When the lights went out: impacts of the April 2025 Iberian blackout on the Portuguese National Health Service sovereignty. Frontiers in Public Health, 2025. Primary Peer-reviewed · link checked 2026-09-26
  28. Blackout in Spain: Urgent Analysis of Impact on Emergency Medical Services. Prehospital and Disaster Medicine, December 2025. Primary Peer-reviewed · link checked 2026-09-26
  29. Excess mortality attributable to the 2025 Iberian Peninsula blackout. Nature Communications, July 2026. Primary Peer-reviewed · link checked 2026-09-26
  30. Infusion Pump Software Correction: BD Issues Correction for BD Alaris Systems Manager and Care Coordination Engine Infusion Adapter Software Due to Risk for Outdated Automated Programming Requests to Load. U.S. Food and Drug Administration, 18 February 2025. Primary Official report · link checked 2026-09-26
  31. BD Provides Update on Feb. 4, 2020 Voluntary Recall of the BD Alaris System PC Units and Modules. U.S. Food and Drug Administration (company announcement), 9 March 2020. Primary Official report · link checked 2026-09-26
  32. Cybersecurity Vulnerabilities with Certain Patient Monitors from Contec and Epsimed: FDA Safety Communication. U.S. Food and Drug Administration, 30 January 2025. Primary Official report · link checked 2026-09-26
  33. ICS Medical Advisory ICSMA-25-030-01: Contec Health CMS8000 Patient Monitor (Update A). Cybersecurity and Infrastructure Security Agency, 30 January 2025. Primary Official report · link checked 2026-09-26
  34. Do the CONTEC CMS8000 Patient Monitors Contain a Chinese Backdoor? The Reality is More Complicated…. Claroty Team82, 2 February 2025. Supporting Vendor research · link checked 2026-09-27
  35. Contec Patient Vital Signs Monitor: Chinese Backdoor or Bad Design?. Cylera (Chad Waters, Apostolos Bakoyiannis), 4 February 2025. Supporting Vendor research · link checked 2026-09-27
  36. External Technical Root Cause Analysis - Channel File 291. CrowdStrike, 6 August 2024. Supporting Official report · link checked 2026-09-26
  37. Testimony of Adam Meyers, CrowdStrike, before the House Homeland Security Subcommittee on Cybersecurity and Infrastructure Protection: 'An Outage Strikes'. U.S. House Committee on Homeland Security, 24 September 2024. Primary Testimony / filing · link checked 2026-09-26
  38. Microsoft global outage forces hospitals to cancel appointments. STAT (Palmer K, Trang B, Ross C), 19 July 2024. Secondary Journalism · link checked 2026-09-26
  39. Patient Care Technology Disruptions Associated With the CrowdStrike Outage. JAMA Network Open (Tully JL, ... Dameff CJ), 1 July 2025. Primary Peer-reviewed · link checked 2026-09-26
  40. Helping our customers through the CrowdStrike outage. Microsoft (David Weston), 20 July 2024. Supporting Official report · link checked 2026-09-26
  41. Widespread IT Outage Due to CrowdStrike Update. CISA, 19 July 2024. Primary Guidance · link checked 2026-09-26
  42. A look at how Mass General Brigham recovered from the CrowdStrike outage. Healthcare Brew (Cassie McGrath), 11 September 2024. Secondary Journalism · link checked 2026-09-27
  43. NHS Ransomware Hack Caused Patient Harm in UK, Data Shows. Bloomberg News (Ryan Gallagher), 14 January 2025. Secondary Journalism · link checked 2026-09-26
  44. Ransomware attack contributed to patient's death, says Britain's NHS. The Record by Recorded Future News (Alexander Martin), 25 June 2025. Secondary Journalism · link checked 2026-09-26
  45. Synnovis cyber update. Synnovis, 2025. Supporting Official report · link checked 2026-09-26
  46. O Positive and O Negative donors asked to urgently book appointments to give blood following London hospitals IT incident. NHS Blood and Transplant, 10 June 2024. Primary Official report · link checked 2026-09-26
  47. Qilin ransomware attack on NHS supplier contributed to patient fatality. The Register, 26 June 2025. Secondary Journalism · link checked 2026-09-26
  48. Ransomware attack continues to disrupt healthcare in London nearly two years later. The Record (Recorded Future News), 2026. Secondary Journalism · link checked 2026-09-26
  49. Cyber Security and Resilience (Network and Information Systems) Bill factsheet: Designating critical suppliers. UK Government (GOV.UK), 30 June 2026. Primary Guidance · link checked 2026-09-26
  50. AHA Survey: Change Healthcare Cyberattack Significantly Disrupts Patient Care, Hospitals' Finances. American Hospital Association, 15 March 2024. Secondary Journalism · link checked 2026-09-26
  51. UnitedHealth hikes number of Change cyberattack breach victims to 190 million. Healthcare Dive (Emily Olsen), 27 January 2025. Secondary Journalism · link checked 2026-09-26
  52. HIPAA Security Rule To Strengthen the Cybersecurity of Electronic Protected Health Information (NPRM, FR Doc 2024-30983). HHS Office for Civil Rights, Federal Register 90(3):898-1022, 6 January 2025. Primary Regulation · link checked 2026-09-26
  53. Review of the Guy's and St Thomas' IT Critical Incident — Final report from the Deputy Chief Executive Officer. Guy's and St Thomas' NHS Foundation Trust, January 2023. Primary Official report · link checked 2026-09-26
  54. Incident: cooling related failure in one of our buildings that hosts zone europe-west2-a. Google Cloud Service Health, 19 July 2022. Primary Official report · link checked 2026-09-26
  55. Universal Health Services Form 8-K (information technology security incident). Universal Health Services, Inc. / SEC EDGAR, 29 September 2020. Primary Official report · link checked 2026-09-26
  56. Universal Health Services Form 10-K for fiscal year 2020. Universal Health Services, Inc. / SEC EDGAR, 2021. Primary Official report · link checked 2026-09-26
  57. Investigation: WannaCry cyber attack and the NHS. National Audit Office (UK), 27 October 2017. Primary Official report · link checked 2026-09-26
  58. A retrospective impact analysis of the WannaCry cyberattack on the NHS. npj Digital Medicine, 2 October 2019. Primary Peer-reviewed · link checked 2026-09-26
  59. Princeton hospital to replace 12-hundred computer hard drives after cyber attack. WV MetroNews (Carrie Hodousek), 30 June 2017. Secondary Journalism · link checked 2026-09-27
  60. Cyber attack prompts Princeton Community Hospital to rebuild network. Bluefield Daily Telegraph (Blake Stowers), 29 June 2017. Secondary Journalism · link checked 2026-09-27
  61. All Systems Down. CIO / Computerworld (Scott Berinato), 25 February 2003. Secondary Journalism · link checked 2026-09-26
  62. Computer crash - lessons from a system failure. New England Journal of Medicine 348(10):881-882, 6 March 2003. Primary Peer-reviewed · link checked 2026-09-26
  63. Breach Portal: Notice to the Secretary of HHS Breach of Unsecured Protected Health Information. HHS Office for Civil Rights. Primary Dataset · link checked 2026-09-26
  64. SAFER Guides requirements: Medicare Promoting Interoperability Program and MIPS Promoting Interoperability (infographic). Centers for Medicare & Medicaid Services, 2023. Primary Regulation · link checked 2026-09-26
  65. 45 CFR 164.308(a)(7) Contingency plan (HIPAA Security Rule, administrative safeguards). eCFR / US Government. Primary Regulation · link checked 2026-09-26
  66. 42 CFR 482.15 Condition of participation: Emergency preparedness (hospitals). eCFR / CMS. Primary Regulation · link checked 2026-09-26
  67. Directive (EU) 2022/2555 on measures for a high common level of cybersecurity across the Union (NIS 2 Directive). European Parliament and Council / EUR-Lex; summary by European Commission, 14 December 2022. Primary Regulation · link checked 2026-09-26
  68. ENISA Threat Landscape: Health Sector (press release 'Checking-up on Health: Ransomware Accounts for 54% of Cybersecurity Threats'). European Union Agency for Cybersecurity (ENISA), 5 July 2023. Primary Official report · link checked 2026-09-26
  69. Cyber security strategy for health and social care: 2023 to 2030. Department of Health and Social Care (UK), 22 March 2023. Primary Guidance · link checked 2026-09-26

Cite this pageFailSystems. “Connectivity & data.” https://failsystems.health201.com/layers/connectivity/ (reviewed 2026-09-26). Health 201 / AstroNexus LLC. CC BY 4.0.

Information only, not advice. FailSystems is an aggregation and synthesis of published sources. It is not consulting, engineering, legal, regulatory or medical advice, and using it creates no professional relationship. Health systems are complex and no approach fits every organisation: anything you adopt is your own decision, at your own risk, and should be checked against the current official sources and by qualified people who know your setting. Full disclaimer.

Dealing with an incident right now? This site is a reference, not an incident-response service. Activate your organisation's emergency operations plan and incident command, and: