Nelson Advisors: When the Hospital Goes Dark: Why Cybersecurity Is Now a Healthcare Security Priority


We tend to think of health security in terms of things we can see under a microscope or feel in a fever. Pandemics, antimicrobial resistance, contaminated water, the next novel virus. These are the threats that governments plan for, that the World Health Organization tracks and that most of us instinctively recognise as matters of life and death.
There is a newer threat on that list, and it does not come from a pathogen. It comes from a laptop, often thousands of miles away, operated by someone who has never set foot in a hospital and never will. On 3rd September 2026, the WHO Regional Office for the Eastern Mediterranean, together with the International Telecommunication Union and the United Nations Office on Drugs and Crime, convened 346 people from health ministries, hospitals, emergency services and cybersecurity agencies for a single purpose: to make the case that cyberattacks on health systems are not an IT problem. They are a health emergency, and they should be planned for like one.
That framing matters, and this article is about why: what actually happens when a hospital is attacked, why digital transformation has made those attacks more likely and more dangerous, what the evidence says about the human cost and what a sensible response looks like.
The quiet dependency
Walk into a modern hospital and almost nothing you see runs without software. The receptionist checks you in on an electronic patient record. The nurse scans your wristband before giving you a drug, and the system checks the dose against your allergies. Your blood sample goes into an analyser that talks to a laboratory information system, which talks back to the ward. The radiologist reads your scan on a workstation that pulled the images from a picture archive. The infusion pump beside your bed may be networked. The ambulance that brought you in was dispatched by a computer-aided system, and the paramedic's tablet sent your vital signs ahead before you arrived.
None of this is a bad thing. Electronic records reduce prescribing errors. Telemedicine reaches people who could never travel to a specialist. Cloud platforms let a small clinic use tools that once required a data centre. Artificial intelligence is starting to spot tumours on scans and sepsis in vital-sign trends earlier than a tired human can. Digital surveillance is what allowed the world to track COVID-19 in something close to real time.
But every one of those systems is also a dependency. The more the care pathway runs through software, the less it can function when the software stops. A hospital's ability to deliver care now rests on the same foundations as a bank's ability to process payments or a utility's ability to keep the lights on. Those foundations can be attacked.
What an attack actually looks like
The word "cyberattack" conjures images of stolen data and data theft is certainly part of the picture. But the attacks that frighten clinicians most are not the ones that copy information. They are the ones that make it disappear.
Ransomware encrypts an organisation's files and systems so they cannot be used, then demands payment for the key. In a hospital, that means the electronic record is gone. The laboratory system is gone. The imaging archive is gone. Staff who have never worked without a screen are suddenly writing on paper, phoning results between departments, and trying to work out which drug a patient was on from a printout that may or may not be current. Operations are cancelled because the anaesthetist cannot see the blood results. Ambulances are diverted to the hospital down the road, which is now dealing with twice its normal emergency load.
Consider what happened in London in June 2024. Synnovis, a pathology provider that runs blood testing for several major NHS hospitals in the south-east of the city, was hit by a ransomware group known as Qilin. The blood-testing infrastructure that Guy's and St Thomas', King's College Hospital and their partner trusts relied on stopped working. According to NHS England figures reported by The Record, 10,152 acute outpatient appointments and 1,710 elective procedures were postponed. Because the laboratories could not do rapid blood matching, hospitals fell back on universal-donor blood, and NHS Blood and Transplant had to issue urgent public appeals as national stocks ran low.
The disruption did not end after a few weeks. By January 2026, more than 161,000 pathology reports still had not been entered into patient records. South London and Maudsley NHS Foundation Trust recorded 122 patient safety incidents linked to incorrect, unavailable or delayed results, and nearly two years on some of its systems remained unrestored. Almost a million patients had data stolen, including the results of tests for cancer and sexually transmitted infections, and many were not told until late 2025.
Then came the finding everyone in health cybersecurity had been dreading. In June 2025, King's College Hospital NHS Foundation Trust confirmed that a patient had died, and that a delayed blood test result caused by the attack was one of "a number of contributing factors" in that death. It was, as far as anyone knows, the first time an NHS patient death had been formally linked to a cyberattack.
This is what the WHO means when it says cyberattacks "can disrupt electronic health records, laboratory and diagnostic systems, emergency services and connected medical devices, potentially delaying care and putting patient safety at risk." The sentence is bureaucratic, but the reality behind it is a person who did not get a blood result in time.
The largest attack you have probably never heard of
If the Synnovis attack shows how a single supplier can knock out care across a city, the Change Healthcare attack in the United States shows what happens when the target is a piece of national infrastructure that almost nobody outside the industry knew existed.
Change Healthcare, owned by UnitedHealth Group, is a clearing house. It processes an enormous share of the insurance claims, eligibility checks, prior authorisations and pharmacy transactions that move through the American health system. In February 2024, the ALPHV/BlackCat ransomware group got in and shut it down. UnitedHealth paid a ransom of $22 million in Bitcoin.
The operational fallout was extraordinary. Pharmacies could not verify coverage, so patients were turned away or asked to pay in full. Doctors' practices and small hospitals could not submit claims, so money stopped arriving, and some feared they would close. UnitedHealth and the federal Medicare agency set up emergency funding programmes to keep providers afloat. UnitedHealth's own response costs for the year were around $3.1 billion. And in January 2025 the company confirmed that the data of roughly 190 million people had been exposed, the largest health data breach in American history by a wide margin.
The lesson here is not primarily about the size of the number. It is about concentration. Health systems have outsourced pieces of their operation to specialist providers, and some of those providers have become so central that their failure is, in effect, the failure of the system. Nobody planned for a single company's outage to disrupt pharmacies from Maine to California, because nobody was looking at the health system as a network with single points of failure. Cyber attackers were.
What the evidence says about harm
For years, the health cybersecurity conversation ran on anecdotes. Everyone suspected that attacks hurt patients, but the data were thin. That has changed.
Researchers at the University of Minnesota School of Public Health, led by health economist Hannah Neprash, examined ransomware attacks on American hospitals between 2016 and 2021 using Medicare claims data. In the first week of an attack, patient volume fell by roughly a fifth, emergency department revenue dropped by around 40 percent, and hospitals delivered less imaging and testing. More importantly, in-hospital mortality among Medicare patients rose from about three per hundred admissions to about four. Across the study period, the researchers estimated that between 42 and 67 Medicare patients died who would otherwise have lived. Those figures exclude anyone with private insurance, so the true toll is higher.
A second study, from the University of California San Diego, published in Critical Care Explorations in 2024, looked at something subtler: what happens to the hospitals next door. When a large health system in the region was hit by ransomware, its emergency departments could not take patients, so they went elsewhere. The neighbouring hospitals, which had not been attacked at all, saw a surge in ambulance arrivals, longer waits, more patients leaving without being seen, and an 81 percent increase in cardiac arrests, with worse survival among those patients. An attack on one hospital degrades care across a whole region, in the same way a fire in one building draws every fire engine in the district.
This is why the WHO and its partners insist that these incidents be treated as health emergencies rather than "isolated IT problems." The tools that health systems already have for emergencies, from incident command to mutual aid between hospitals to surge planning, are exactly the tools a cyberattack demands. The problem is that in most countries those tools sit in the emergency preparedness directorate, while cybersecurity sits in the IT department, and the two rarely rehearse together.
Why healthcare is such an attractive target
There are easier targets than hospitals. Why do criminals go after them?
The blunt answer is that hospitals pay, and they pay quickly, because the alternative is that people die. A logistics company hit by ransomware can tolerate a week of disruption. A hospital cannot tolerate an hour. That urgency is precisely what a ransomware operator is monetising. Comparitech's analysis of the first half of 2026 counted 410 ransomware attacks on healthcare organisations worldwide, up 14 percent on the previous six months, with median ransom demands of around $300,000 and attacks on healthcare businesses such as pharmaceutical firms and billing companies up 35 percent. Qilin, the group behind Synnovis, remained among the most active.
The second reason is that health data is unusually valuable and unusually permanent. A stolen credit card can be cancelled. A stolen medical history cannot. This is why IBM's annual Cost of a Data Breach study has found health care to be the most expensive sector to be breached in for 14 consecutive years, with an average cost of $7.42 million per incident in 2025 and an average of 279 days to identify and contain a breach, roughly five weeks longer than the global average. Attackers are inside health systems for the better part of a year before anyone notices.
The third reason is that hospitals are, to put it kindly, easy. Health care is a sector of thin margins, ageing technology and relentless operational pressure. A hospital's IT budget competes directly with nurses and scanners, and it usually loses. The result is a landscape of unpatched systems, shared passwords, remote access tools left over from the pandemic, and thousands of medical devices running operating systems that stopped receiving security updates years ago.
The medical device problem
That last point deserves its own section, because connected medical devices are the part of the picture that most people, including many clinicians, have never thought about.
An MRI scanner, an infusion pump, a patient monitor or a laboratory analyser is a computer with a medical function bolted on. Many run versions of Windows or embedded Linux that are a decade or more old. They cannot simply be patched the way a laptop can, because any software change may require the manufacturer to revalidate the device's safety, and because a scanner that costs a million pounds is expected to last 15 years, not three. So they sit on the hospital network, often with default passwords and open ports, providing a convenient way in and a convenient thing to hold hostage.
Regulators have started to act. In the United States, the Food and Drug Administration now has statutory authority under Section 524B of the Federal Food, Drug and Cosmetic Act to require that new "cyber devices" come with a software bill of materials, a plan for managing vulnerabilities after sale, and evidence of a secure development process. The agency's guidance, tightened again in 2025, treats cybersecurity as a patient-safety property of the device rather than an optional extra. As Phil Englert of Health-ISAC put it, cybersecurity engineering "is about preventing devices from doing tasks you don't want or expect."
But regulation applies to new devices. The installed base will be there for years. For those, the practical answer is to know what you have, to segment the network so that a compromised infusion pump cannot reach the patient record system, and to monitor for behaviour a device should never exhibit, like a blood-gas analyser trying to connect to a server in another country.

Not just a rich country problem
There is a tempting assumption that cyberattacks on health are a problem for wealthy, heavily digitised systems like the NHS or American hospital chains. The WHO's decision to convene its September 2026 webinar in the Eastern Mediterranean region, and the alarm raised by health officials in Liberia a few days later, should put that assumption to rest.
Low and middle income countries are digitising health care faster than anyone. Electronic immunisation registries, mobile phone based disease surveillance and cloud hosted patient records are leapfrogging the paper systems that never quite worked. But those systems are acquiring the same dependencies, often with fewer resources to protect them and weaker legal frameworks for pursuing criminals. A ransomware attack on a national HIV treatment database or a vaccine cold-chain monitoring system would be a public health event of the first order, and in many countries there is no plan for it.
The WHO's recommendations from the webinar are deliberately practical for that reason. Integrate cybersecurity into national digital health strategies from the outset, rather than bolting it on afterwards. Establish incident response and reporting mechanisms so that an attack on one hospital is known to every other. Run regular simulation exercises, as hospitals do for mass-casualty events. Maintain downtime procedures and paper-based contingencies, so that staff know what to do when the screens go blank. And build partnerships across health, telecommunications, law enforcement and the technology sector, because no ministry of health can fight international organised crime alone.
What resilience actually looks like
Perfect security is not available. Any hospital that connects to the internet can in principle be attacked, and a determined adversary will eventually get in somewhere. The goal is not to be unbreachable. It is to be resilient: to detect an intrusion quickly, to limit how far it spreads, and, above all, to keep caring for patients while the systems are down.
That last point is the one health systems most often neglect. When Synnovis went down, the hospitals that coped best were the ones whose staff had practised working without the lab, knew where the paper request forms were, and had agreed in advance which tests were essential and which could wait. Resilience is a clinical and operational discipline as much as a technical one. It means asking, ward by ward, what happens here if the computers stop for a day, a week, a month, and then rehearsing the answer.
Technically, the basics are well understood and depressingly often absent. Multi-factor authentication on every remote access point, so that a stolen password alone is not enough. Offline, tested backups that ransomware cannot reach, so that recovery does not depend on paying. Network segmentation, so that a compromised device or supplier cannot roam freely. An accurate inventory of every device on the network, because you cannot protect what you do not know you have. And a supplier assurance process that asks the pathology company, the software vendor and the cloud host the same hard questions the hospital asks itself, because, as both Synnovis and Change Healthcare showed, the attack that takes down a hospital is increasingly an attack on someone else.
Governments are beginning to legislate for this. The United Kingdom's Cyber Security and Resilience Bill, introduced in November 2025 and working its way through Parliament during 2026, tightens obligations on health operators and, crucially, brings their critical suppliers and managed service providers into the regulatory net for the first time. It requires an initial incident report within 24 hours and a full report within 72, backed by penalties of up to £17 million or 4 percent of global turnover. The direction of travel is clear: the supply chain is now part of the health system, and it will be regulated as such.
What this means for you
If you are a patient, there is little you can do to protect your hospital, and quite a lot you can do to protect yourself. Keep your own record of your medications, allergies and key diagnoses, on paper or on your phone, so that you can tell a clinician what they need to know if their system is down. Be alert to phishing that uses stolen health data as bait, since the criminals who took your details from a breached lab will happily use them to impersonate your GP. And when you are asked to donate blood after an attack, as Londoners were in 2024, understand that the request is not a formality.
If you are a clinician, your role is to insist that downtime procedures are real and rehearsed, not a binder on a shelf. You are also the last line of defence against the most common way attackers get in, which remains a convincing email and a hurried click. Be as suspicious of an unexpected attachment as you are of an unexpected drug interaction.
If you run a hospital or a health system, the question to ask your board is not "are we secure?" but "what happens to our patients on day three of an outage, and have we tested it?" Cybersecurity belongs on the risk register next to infection control and fire safety, funded accordingly.
And if you make policy, the WHO has given you the framing. Treat cyber incidents as health emergencies. Bring the emergency planners and the technologists into the same room. Regulate the supply chain. Fund the basics. And recognise that in a world where health care runs on software, a health system's cyber defences are part of its capacity to keep people alive.
The pathogen that isn't one
Public health has a long history of learning to see new threats. Cholera was a miasma until John Snow mapped a water pump. Each time, the discipline had to expand its definition of what counts as a threat to health, and each time the expansion felt strange at first.
Cybersecurity is the latest such expansion. There is no organism, no vector, no vaccine. But the effect is the same as any other health emergency: care delayed, results lost, patients diverted, and, at the far end of the chain, people dying who did not need to. The evidence for that is no longer anecdotal. It is in the mortality data from Minnesota, the cardiac arrest data from San Diego and a patient safety investigation in south London.
The digital transformation of health care will continue, and it should. The question is whether the security of that transformation keeps pace with its ambition. The WHO's September webinar was a statement that it must. The next few years will show whether health systems, and the governments that fund them, were listening.
Nelson Advisors > European HealthTech, MedTech, Digital Health Investment Banking
Nelson Advisors specialise in Mergers and Acquisitions, Partnerships and Investments for Digital Health, HealthTech, MedTech, Health IT, Consumer HealthTech, Healthcare Cybersecurity, Healthcare AI companies.www.nelsonadvisors.co.uk
Nelson Advisors regularly publish Thought Leadership articles covering market insights, industry trends, deal commentary, market analysis & predictions @ https://www.healthcare.digital
Nelson Advisors publish Europe's Leading Healthcare Technology Investment Banking Newsletter every week, join 5000+ HealthTech and MedTech subscribers today! https://lnkd.in/e5hTp_xb
Nelson Advisors pride ourselves on our DNA as ‘Founders advising Founders.’ We partner with entrepreneurs, boards, corporates, venture capital and private investors to maximise shareholder value and investment returns.www.nelsonadvisors.co.uk
#NelsonAdvisors #HealthTech#MedTech#DigitalHealth #HealthIT #Cybersecurity #HealthcareAI #FemTech#ConsumerHealth #Mergers #Acquisitions #Partnerships #Growth #Strategy #NHS #UK #Europe #USA#Canada#Commonwealth#CorporateDivestitures #VentureCapital #PrivateEquity #Founders #SeriesA #SeriesB #Founders #SellSide #TechAssets #Fundraising #BuildBuyPartner #GoToMarket #PharmaTech #BioTech #Genomics
Nelson Advisors LLP
Hale House, 76-78 Portland Place, Marylebone, London, W1B 1NT
Meet Nelson Advisors @ 2026 Events
Digital Health Rewired > March 2026 > Birmingham, UK
NHS ConfedExpo > June 2026 > Manchester, UK
HLTH Europe > June 2026, Amsterdam, Netherlands
HIMSS AI in Healthcare > July 2026, New York, USA
Bits & Pretzels > September 2026, Munich, Germany
World Health Summit 2026 > October 2026, Berlin, Germany
HealthInvestor Healthcare Summit > October 2026, London, UK
HLTH USA 2026 > October 2026, USA
Barclays Health Elevate > October 2026, London, UK
Web Summit 2026 > November 2026, Lisbon, Portugal
MEDICA 2026 > November 2026, Düsseldorf, Germany
Venture Capital World Summit > December 2026 Toronto, Canada




































Comments