Ransomware and other cyberattacks against hospitals “should be treated as disasters,” given the increased patient-care disruptions faced by nearby healthcare providers in the aftermath of an attack, according to a new study published in JAMA Network Open.
The findings suggest a need to improve coordinated planning and response efforts between regional care providers.
“Hospitals adjacent to healthcare delivery organizations affected by ransomware attacks may see increases in patient census and may experience resource constraints affecting time-sensitive care for conditions such as acute stroke,” the research showed. The attacks and associated disruptions "should be considered a regional disaster."
The study was led by healthcare subject matter experts from the University of California San Diego Health: Drs. Jeff Tully, Theodore Chan and Christian Dameff. Dameff and Tully are well-known for leading the charge on medical device security, while Dameff has testified to Congress about patient-safety risks posed by hospital cyberattacks on adjacent providers.
UCSD is local to Scripps Health, and when a cyberattack on Scripps brought the health system down for a month in May 2021, area hospitals were left overcrowded and unable to keep pace with the influx of patients diverted from Scripps, Dameff told the House Energy & Commerce Committee in July 2021.
“Our ability to diagnose a patient is tied to the technology that we use every day as clinicians: we are so dependent,” said Dameff, at the time. “You can imagine during a large ransomware attack, wherein these technical systems are no longer available, that we can’t do our jobs as clinicians.”
The new JAMA study examines the fallout from a hospital cyberattack and outages using data gleaned over the course of the month from the nearby hospitals unaffected by the cyberattack, but overwhelmed with the surge in patient care visits.
Scripps is not specifically mentioned in the study’s findings, but referenced in the citations. The dates of the study also align with the Scripps cyberattack.
The researchers compared the four-week period prior to the attack to the four-week period of downtime at two academic urban emergency departments located near the impacted health system and evaluated 19,857 emergency department visits at the unaffected hospital.
Of those visits, 6,114 were before the attack, 7,039 were seen during the attack and recovery phase, and 6,704 occurred in the post-attack phase.
During the examined time period, San Diego County EMS reported ambulance diversion traffic at a median of 27 cumulative hours per day in the 4 weeks prior to the attack compared with 47 cumulative hours per day during the attack, and 31 cumulative hours per day after the attack.
The data showed “significant increases in patient census, ambulance arrivals, waiting room times, patients left without being seen, total patient length of stay, county-wide emergency medical services diversion, and acute stroke care metrics were seen in the unaffected emergency department… during the attack and postattack phases.”
In comparison with the pre-attack phase, there were “significant increases” in overall patient admissions to the emergency departments and individuals who left without being seen during the attack phase. They also found similar increases in median waiting room times during the attack phase than before the attack.
The wait time before the attack was 21 minutes compared with 31 minutes during the attack phase. There was also a rise in length of stay for admitted patients: 614 minutes compared with 822 minutes during the attack. No significant increases were found between the attack and post-attack phases.
Ransomware, Incident Response
Data ties healthcare cyberattacks to greater disruptions at nearby hospitals

Cyberattacks against hospitals should be treated as regional disasters since patients have to be diverted to other hospital to receive care, a new JAMA study concluded. (Getty Images)
An In-Depth Guide to Ransomware
Get essential knowledge and practical strategies to protect your organization from ransomware attacks.
Related Events
Get daily email updates
SC Media's daily must-read of the most current and pressing daily news
You can skip this ad in 5 seconds