I see the shift in healthcare cybersecurity this way: stopping attacks is only half the job. You also need to test whether staff can keep care moving during an outage - and return to electronic systems safely.
The stakes are clear. After the 2024 Change Healthcare attack, 75% of hospitals surveyed by the American Hospital Association reported negative effects on patient care.[1]
I’d focus on four checks:
- Prevention: Patch systems, limit access, and contain attacks.
- Care continuity: Identify which care cannot wait, then practice paper workflows and backup communications.
- Safe recovery: Check devices, reconcile records, and get clinical and IT approval before resuming electronic workflows.
- Supplier readiness: Test outage plans, recovery targets, and shared dependencies - not just contract terms.
My bottom line: <u>measure care delivered, not just systems restored</u>. Track treatment delays, downtime, recovery time, patient-safety outcomes, and financial losses alongside security results. Resilience adds to prevention; it does not replace it.
Healthcare Cybersecurity vs. Cyber Resilience
1. Cybersecurity: Prevent and Contain Attacks
Clinical Continuity
Losing access to EHRs, diagnostic tools, or medication histories can interrupt care. Patch connected medical devices and close known vulnerabilities before attackers can reach them. Unsupported operating systems need extra controls; patching alone won't reduce the risk.
Containment can stop an attack from spreading, but isolating systems may force staff back to manual workflows. Recovery needs its own test: can care resume when systems go dark?
Recovery Capability
A security assessment may show strong controls without proving that services needed for patient care can be restored after a shutdown. Control evidence and recovery evidence are separate requirements. Recovery also depends on vendors, not just internal controls.
Third-Party Dependencies
Supplier reviews often focus on direct controls and miss what happens when a critical provider goes down. When hospitals rely on the same provider, one outage can interrupt care across many facilities.
In February 2024, UnitedHealth Group’s Change Healthcare shut down systems to contain a ransomware attack. Insurance reimbursements and prescription processing were disrupted for weeks. An American Hospital Association survey one month later found that 94% of surveyed hospitals reported financial impacts and 75% reported negative impacts on patient care. [1]
Measure readiness by the impact on care - not vendor paperwork alone.
Success Measures
Track how fast teams patch vulnerabilities and isolate systems, plus whether containment stops lateral movement. These measures show whether defenses work. They don't show whether care stays available.
Use the Healthcare and Public Health Cybersecurity Performance Goals as a security baseline, not proof of clinical readiness.
sbb-itb-535baee
Healthcare Cyber Resilience: What Keeps the Doors Open?
2. Cyber Resilience: Maintain Care and Recover Safely
When prevention fails, resilience determines whether teams can keep delivering care.
Clinical Continuity
Define which care must continue during an outage. Train staff to safely handle patient triage, exams, and lab requests using manual workflows when systems are down. [1]
In February 2026, a cyberattack on the University of Mississippi Medical Center forced clinics across the state to close and delayed chemotherapy treatments. Staff used paper documentation to maintain care. [1]
Recovery Capability
Keeping care running is the first test. Recovering safely is the second.
Put safe operation ahead of system availability. As teams restore critical services, check connected medical devices and other critical equipment. Access alone isn't enough: devices must work correctly. [1]
Incorrect device data can drive incorrect treatment, turning a cyber issue into a patient safety issue. [1]
third-party risk dependencies
Recovery also relies on providers outside the hospital. Plan to keep essential care running while critical providers, such as clearinghouses, recover or are replaced. Switching clearinghouses can take weeks or months. [1]
Success Measures
Readiness comes down to performance, not plans.
Measure whether teams can maintain minimum essential operations - the services needed to keep care going during a crisis - and use manual workflows safely. Test staff performance and confirm that critical devices continue to work correctly. [1] Success means showing that teams are ready to deliver care, not simply that controls are in place.
Maintaining Care During Outages and Restoring Services
Resilience takes two kinds of proof: staff can keep care going during outages, and teams can restore services safely. The test is whether those plans work when systems go down.
Clinical Continuity
Map each critical workflow to its backup process, technology dependency, and third-party connection. Use the ONC SAFER Guides to plan for downtime, and practice manual procedures with the staff who will use them.
| Clinical area | Attack prevention | Manual downtime care |
|---|---|---|
| Emergency care | Secure ambulance dispatch and triage systems against access without permission. | Use manual triage and diversion procedures. |
| Medication administration | Protect electronic medication histories and automated dispensing systems. | Verify medication histories manually and place orders on paper. |
| Diagnostics | Patch vulnerabilities in connected imaging and lab systems, including third-party connections. | Use paper lab requests and hand-delivered results. |
| Communications | Protect internal and third-party messaging and VoIP systems from malicious encryption or eavesdropping. | Use radios or runners during outages. |
| Documentation | Protect EHR integrity and keep data confidential. | Document care on paper and reconcile records later. |
Check that each department has practiced its manual workflow and knows which alternate communication channel to use. Then define how the recovery plan will verify when each service can safely return.
Recovery Capability
Downtime care and recovery validation are separate tests. Use the ASPR/NIST Health Care and Public Health Sector Cybersecurity Framework Implementation Guide to guide recovery planning.
| Recovery task | Technical system restoration | Clinically validated service recovery |
|---|---|---|
| Service release | Confirm systems are available. | Get joint clinical-IT approval to resume care. |
| Record reconciliation | Recover stored EHR data. | Reconcile downtime records before reuse. |
| Device validation | Restore connectivity and device function. | Confirm device data are accurate. |
| Backups | Restore from protected, tested backups. | Confirm records support safe decisions. |
| Identity and interfaces | Restore access and system connections. | Confirm access to the right records and services, including third-party lab results. |
After restoration, have emergency, pharmacy, lab, and IT teams reconcile paper records and verify connected data. These teams should jointly decide whether care can safely return to electronic workflows.
Assessing Supplier Readiness and Measuring Care Outcomes
Third-Party Dependencies
After mapping internal recovery, check whether suppliers are ready. Assess cloud, software, managed-service, device, and telecom providers based on the clinical workflows they support. Security controls alone cannot tell you how long care can continue when a supplier fails.
| Assessment area | Traditional security check | Resilience readiness check |
|---|---|---|
| Controls | Review access controls, patching, and basic security evidence. | Check that controls support safe work during downtime, including on unsupported devices. |
| Availability | Review uptime commitments. | Identify which functions remain available during a full outage. |
| Recovery objectives | Review backup frequency and recovery policies. | Match recovery time and data-loss targets (RTOs and RPOs) to clinical needs. |
| Notification | Review breach-reporting terms. | Require outage alerts, workflow-impact updates, and escalation contacts. |
| Shared downstream dependencies | Collect subcontractor information. | Identify shared dependencies that could interrupt care at the same time. |
| Workflow impact | Assess sensitive-data exposure. | Identify which care or payment processes stop and how long manual care remains safe. |
| Exit and transition plans | Review termination and data-deletion terms. | Verify usable data return, transition time, and backup ownership. |
| Exercise evidence | Review security testing results. | Request joint outage exercise results, recovery times, and unresolved findings. |
Different suppliers can share the same point of failure. That is concentration risk. Map their underlying dependencies, and document who handles backup creation, retention, restoration, and testing. Confirm who receives escalation alerts and how exported data will remain usable. Test recovery with critical suppliers; contractual exit rights alone do not establish readiness.[1]
Use risk data to assign owners and close gaps - not as proof that care can continue. Feed those findings into the scorecard for care disruption and recovery performance.
Success Measures
Measure whether supplier weaknesses affect patient care, not just whether controls pass review. Use leading indicators to spot gaps, then check what outage outcomes show.
| Category | Leading indicator | Outcome to measure | Strength and limit |
|---|---|---|---|
| Protection | Patching and control coverage | Successful compromises | Shows reduced exposure, but does not prove continuity. |
| Preparedness | Workforce trained in cyber response and completed exercises | Time to trigger emergency manual protocols | Shows readiness, but training completion alone does not prove performance. |
| Continuity | Offline EHR backups and tested contingency plans | Duration of disrupted workflows; delayed or canceled care | Shows care disruption, but results vary by clinical service. |
| Recovery | Attestation to CPG implementation and validated recovery tests | Critical-service restoration time against RTOs | Tests capability, but technical recovery alone does not establish safe care. |
| Learning | Exercise and incident findings resolved and retested | Recurring failures in later exercises or incidents | Shows improvement, but closing a task does not prove that a fix works. |
| Dependency management | Validated exit plans for critical suppliers | Financial loss in U.S. dollars per day of outage | Shows external exposure, but supplier assurances need validation. |
Track patient-safety outcomes, including treatment delays, complications, and, where relevant, mortality. Review them with clinical leaders and by service. A single organization-wide metric can hide delays in pharmacy, lab, or emergency care. An adverse outcome after an outage does not, by itself, establish causation.[1]
Conclusion: Keep Prevention and Measure Care Readiness
That shift changes what leaders measure: not just blocked attacks, but uninterrupted care. Healthcare leaders need answers to both questions: Are systems protected, and can care continue and recover safely?
Keep core security controls. Use the critical-services map to set downtime tests and the restoration order so minimum essential operations can continue. Plan for emergency care availability as part of resilience - not just system restoration.
Test paper-based workflows with frontline staff. For connected clinical devices, prioritize operability and patient safety rather than treating every system equally. [1]
Report continuity outcomes alongside security metrics: care maintained, downtime reduced, recovery time, and financial impact.
FAQs
How do we prioritize care during a cyber outage?
Put patient safety ahead of IT recovery priorities. Use criticality rankings from enterprise risk assessments to restore emergency care, ICU, surgery, pharmacy, laboratory, and imaging first. Also prioritize ambulatory care and telehealth to keep patients connected to their care teams and support disease management.
Keep care running while systems are offline with service-specific recovery plans and unit-level downtime playbooks. Include manual fallback procedures, clearly defined roles for staff, and clear criteria for escalation.
How often should we test downtime workflows?
Healthcare organizations should run downtime workflow drills every quarter and include them in annual competencies to keep staff ready [1]. As technology and workflows change, regularly review and test dependency maps, downtime plans, and vendor concentration risks [2].
After every drill or incident, teams must complete an after-action review. Identify gaps, assign an owner to each corrective action, and retest the fixes to confirm they work [3].
How can we validate a supplier’s recovery claims?
Go beyond static questionnaires with evidence-based verification [1]. Require contracts to spell out recovery time objectives (RTOs), recovery point objectives (RPOs), and incident notification timelines [2]. Suppliers should also provide supporting SOC 2 reports, business continuity plans, and penetration testing summaries [2].
Incident notices alone aren't enough. Require proof of actual restoration testing and check backup integrity logs to confirm the supplier can reliably restore services after a disruption [3].