When Cyber Risk Becomes Clinical Risk
In April 2026, a cybersecurity incident at Signature Healthcare Brockton Hospital affected information systems across the health system. The hospital activated downtime procedures, diverted ambulances, and temporarily canceled chemotherapy infusion services. Nine days later, it lifted its Code Black status, although some systems and processes still required restoration.
In September, Luminis Health reported a cybersecurity incident that left certain systems unavailable. Patients were asked to call for help with appointments and services, telephone access had to be restored across the organization, and MyChart remained unavailable during the recovery period.
Hospitals use emergency codes differently, but the operational message is clear: when core technology becomes unavailable, normal care processes cannot be assumed. Clinicians may lose immediate access to records. Patients may be unable to schedule care or retrieve test results. Ambulances may be diverted. Pharmacy, laboratory, and revenue-cycle workflows can slow or stop.
These are not simply data-security events. They are continuity-of-care events.
The Cost Goes Beyond Breached Data
Healthcare remains the most expensive industry for data breaches. IBM’s 2025 research placed the average cost of a healthcare breach at $7.42 million and the average time to identify and contain one at 279 days. Those figures capture investigation, notification, recovery, and business disruption, but they cannot fully express the effect of delayed treatment, diverted patients, or clinicians working without the systems they rely on.
The U.S. Department of Health and Human Services describes cyber safety as patient safety. Its hospital resiliency analysis identifies ransomware, phishing, cloud exploitation, software vulnerabilities, and distributed denial-of-service attacks among the threats facing hospitals. The analysis also found substantial variation in hospital preparedness, especially in areas such as vulnerability management, identity and access management, network management, security operations, and incident response.
The implication is direct: hospitals cannot treat resilience as a recovery project that begins after an incident. It must be designed into the environment before disruption occurs.
Build Resilience Before Care Is Interrupted
Cyber resilience is the ability to anticipate, withstand, respond to, and recover from an incident while maintaining the critical functions that patient care depends on. For hospitals, that requires security and clinical continuity planning to work together.
-
Know What Is Exposed
An organization cannot protect assets it does not know are visible. Hospitals should maintain a current view of public-facing systems, applications, devices, remote-access points, and third-party connections. External exposure should be reviewed continuously, with findings prioritized according to exploitability and potential impact on care delivery.
-
Map Critical Clinical Dependencies
Traditional asset inventory is not enough. Hospitals also need to understand which clinical and operational workflows depend on each system. What happens if the electronic health record, imaging platform, voice network, pharmacy system, patient portal, or a mission-critical third party becomes unavailable? Mapping these dependencies helps leaders focus investments where disruption would create the greatest risk to patients and operations.
-
Reduce the Blast Radius
Strong identity controls, phishing-resistant multifactor authentication, network segmentation, disciplined vulnerability management, and protected backups can limit an attacker’s ability to move through the environment. Monitoring across communications, infrastructure, and security systems can also help teams detect abnormal activity sooner and respond before an isolated compromise becomes an enterprise-wide outage.
-
Prepare for Extended Downtime
Downtime plans should be designed as clinical continuity plans, not IT documents. The American Hospital Association recommends preparing to maintain critical functions without network- or internet-dependent services, technologies, or supply chains for 30 days or longer. Hospitals should define decision rights, communication channels, manual workflows, and recovery priorities, then test them through realistic exercises that involve clinical, operational, executive and technology leaders.
-
Turn Findings into a Prioritized Roadmap
Most hospitals already have a long list of security initiatives. The challenge is knowing what to address first. A resilience roadmap should connect technical exposure to operational consequences, sequence improvements by risk and feasibility, and define clear measures of progress. That gives leaders a practical path forward without waiting for a major incident to reveal the most urgent gaps.
Keep Care Online
Hospitals will never eliminate every cyber threat. They can, however, reduce the likelihood that an attack becomes a clinical crisis and improve their ability to restore operations safely when disruption occurs.
C1 helps healthcare organizations connect communications, infrastructure, and security into a coordinated resilience strategy. By identifying external exposure, protecting critical operations, and strengthening response and recovery readiness, hospitals can reduce risk while keeping the focus where it belongs: on patients.
Do not wait for Code Black to expose the gaps.
Robert Redd
Portfolio and Offer Management Executive Lead